📁 Android VPN Tutorial

Clash for Android: A Complete Beginner’s Guide to VPN Setup

234 views 17 min read
Clash for Android: A Complete Beginner’s Guide to VPN Setup

Table of Contents

  1. What Is Clash for Android?
  2. Before You Start: Requirements
  3. Step 1: Download and Install Clash for Android APK
  4. Step 2: Import Your Subscription Link
  5. Step 3: Grant VPN Permission and Start
  6. Step 4: Choose the Right Proxy Mode
  7. Step 5: Select a Node and Verify the Connection
  8. Step 6: TUN Mode vs. System Proxy
  9. Step 7: Set Up Per-App Proxy
  10. Troubleshooting Common Clash for Android Issues
  11. Is Clash for Android Still Maintained in 2026?
  12. FAQ
  13. Where to Go Next

What Is Clash for Android?

Clash for Android (CFA) is a rule-based proxy client that runs a local VPN service on your phone. Unlike basic VPN apps that push all traffic through a single server, Clash reads a YAML configuration file and decides connection by connection whether traffic should go direct, through a proxy, or be rejected.

That rule-based approach is what makes Clash VPN Android setups so flexible. You can keep banking apps, delivery services, and local video platforms on a direct connection while routing only the traffic that needs a proxy through your selected nodes. It supports multiple protocols, proxy groups, latency testing, and per-app routing—features that most consumer VPN apps do not offer.

Quick answer: Clash for Android is a rule-based proxy client for Android that imports a subscription link, runs as a local VPN, and routes traffic by rules rather than sending everything through one server.

If you are still picking a provider, the VPN plans page compares every tier, from a light browsing plan for casual use up to unlimited high-speed for heavy streaming and downloads.


Before You Start: Requirements

You need three things before you open the app:

  1. An Android device running Android 8 or newer. Modern phones are almost all arm64-v8a. Emulators and older 32-bit devices may need armeabi-v7a. Installing the wrong architecture usually fails immediately or crashes on launch.
  2. A subscription link from a provider. This is an HTTPS URL that returns a Clash-compatible YAML configuration containing nodes, proxy groups, and routing rules in one file. Do not confuse it with a single-node link meant for V2RayNG or Shadowrocket—those use different formats and will not import correctly into Clash.
  3. A stable network for the first import. The subscription endpoint itself must be reachable from your current Wi-Fi or mobile data. If the provider's subscription server is blocked on your network, the app cannot download the profile even if the nodes inside it would work later.

Keep the subscription URL in a password manager. Treat it like a password: anyone who has it can download your profile and consume your traffic. If you accidentally post it in a chat or screenshot, reset it from your provider dashboard. If billing or account questions come up, the FAQ covers most of the common ones.


Step 1: Download and Install Clash for Android APK

Google Play distribution for open proxy clients is inconsistent by region, so most users install the Clash APK directly. This is a security decision, not a convenience one. Prefer the publisher you already trust—either the official GitHub Releases page or your provider's download mirror. Avoid APKs with names like "cracked," "modded," or "free nodes included." Those bundles are a common delivery method for malware and certificate replacement attacks.

Download the file that matches your phone's CPU architecture. On modern phones, this is almost always arm64-v8a. If you are unsure, check under Settings → About Phone → Processor, or simply try the ARM64 build first—most devices from the last six years use it.

Once the download finishes, open the APK from your browser or file manager. Android will warn you about installing unknown apps. This is normal. Grant the Install unknown apps permission to the browser or file manager you used, then return to the installer and confirm. Some Chinese OEM ROMs split this permission per source app, so if the install button is greyed out, check that you gave the permission to the app that is actually launching the installer.

After installation, open the app. It will ask for notification permission. Allow it. On many ROMs, the persistent notification is part of what keeps the VPN service alive in the background—without it, the system may quietly kill the tunnel after a few minutes.


Step 2: Import Your Subscription Link

The wording varies slightly between Clash for Android builds, but the workflow is the same: open the profile area, create a remote profile, paste the URL, download it, and activate the result. Do not paste the subscription link into a node editor—that field is for individual server entries, and the app will either reject it or create a broken profile.

Here is the path on a typical CFA build:

  1. Open the app. On the bottom bar or side menu, tap Profiles (sometimes labeled Configuration or Configs).
  2. Tap the + button in the corner. Choose Import from URL (or URL). Do not choose "Local file" or "Manual edit."
  3. Paste the full subscription URL into the URL field. Long-press to paste, then check the beginning and end of the link. Android clipboard managers sometimes insert a line break or trailing space when copying from formatted messages.
  4. Give the profile a name you will recognize later. "ProviderName_2026_June" is better than "Config 1," especially if you manage more than one account.
  5. Tap Save or the checkmark. The app will download the profile. If the download fails, you will see an error message. A 403 usually means the token expired or the provider rate-limited your IP. A TLS error often points to captive-portal Wi-Fi or a system clock that is far off. Fix those before assuming the nodes are dead.
  6. Once the download completes, tap the profile card to select it. A selected profile shows a checkmark or highlighted border.

Step 3: Grant VPN Permission and Start

Go back to the home screen. You will see a large circular button in the center, usually labeled Tap to Start or just a power icon. Tap it.

Android will immediately show a system dialog: "Clash for Android wants to set up a VPN connection and allow it to monitor network traffic." This is the standard Android VPN permission prompt. Tap OK or Allow. If you tap Cancel, the tunnel will not establish and the app will sit idle even though the profile is loaded.

One thing that trips people up: this system dialog sometimes cannot be tapped if another app is using a screen overlay or if your phone has an eye-comfort mode active. If the OK button does not respond, close other apps, turn off any blue-light filter, and try again. The dialog is a system component, not part of Clash—the app cannot fix a blocked overlay for you.

Once you allow the connection, the status bar will show a small VPN key icon. The circular button in the app will change color or display Running. That means the tunnel is up.


Step 4: Choose the Right Proxy Mode

The mode selector is usually on the main screen or in a side panel. You will see three options: Rule, Global, and Direct. Understanding what each one does prevents most "why is my bank app broken" moments.

ModeWhat It DoesWhen to Use It
RuleRoutes each connection according to the rules in your profile. Domestic traffic goes direct; matched overseas traffic goes through the proxy.Daily use. This is the correct default for almost everyone.
GlobalForces all proxyable traffic through the currently selected outbound, ignoring rules.Quick debugging. If a site works in Global but fails in Rule, the problem is your rules or DNS, not the node.
DirectBypasses the proxy entirely. Traffic exits over your normal connection.Speed comparisons or temporarily disabling the proxy without closing the app.

Rule mode is what you want for daily use. The app reads the rules inside your profile and routes each connection accordingly. Domestic domains and IPs go direct. Overseas services that match a proxy rule go through your selected node. Everything else falls through to a default policy defined in the configuration. This keeps WeChat, Alipay, and local delivery apps working normally while your browser and YouTube go through the proxy.

Global mode forces all proxyable traffic through your currently selected outbound. It ignores the rule engine's direct-vs-proxy decisions. Useful for a quick test, but not for daily use—Global mode will route local traffic through your proxy as well, which often breaks domestic apps that detect foreign IPs and refuse to work.

Direct mode bypasses the proxy entirely. This is equivalent to turning the VPN off without closing the app.


Step 5: Select a Node and Verify the Connection

Tap the Proxy tab (usually the second icon on the bottom bar). You will see your proxy groups. The exact layout depends on your provider's configuration, but common groups include Auto Select, Fallback, and a manual list of node names.

Tap a node name to select it. The selected node gets a checkmark or highlight. If you are not sure which one to use, start with a node in a region you expect to be fast from your location—Japan, Singapore, or the US West Coast for users in Asia.

Do not pick based on latency alone. Clash's latency test measures the time to establish a connection to the node, not the throughput you will actually get. A node can show 50 ms and still deliver terrible speed if the server is overloaded. The better test is to open a video on YouTube or run a speed test after connecting.

To verify the tunnel is working:

  1. Open a browser and visit a site that is blocked on your normal connection. If it loads, you are through.
  2. Check your public IP on a site like ip.sb or whatismyipaddress.com. If it shows the same IP as your regular connection, the proxy is not active—check that the profile is selected, the mode is not Direct, and the tunnel is actually running.

If you regularly stream, a plan built for that—like HD streaming or high-speed download—will matter more than the raw node count. For low-latency games, the gaming boost tier is the one to look at.


Step 6: TUN Mode vs. System Proxy

Clash for Android can route traffic in two ways. Understanding the difference prevents a lot of "why is this one app not working" confusion.

System proxy mode (default). The app tells Android's network stack to send HTTP and HTTPS traffic through the local Clash listener. This works for browsers and most apps, but some apps bypass the system proxy entirely—games with their own networking code, certain email clients, and apps that use raw TCP or UDP.

TUN mode. Creates a virtual network interface. All IP traffic from the device, including UDP, enters that interface and is handed to Clash. This captures games, email clients, and anything else that ignores system proxy settings. To enable it, go to Settings → Network (or Settings → TUN) and toggle TUN mode on. The app will ask for VPN permission again if it is not already running.

Caveats to know before enabling TUN:

  • TUN mode requires the VPN permission, so it cannot run alongside another VPN app.
  • On some ROMs, you may need to turn off Private DNS or a system-level "secure DNS" feature, because those can interfere with Clash's DNS handling.
  • If a specific app stops working after you enable TUN, check the TUN settings for an exclude app list and add that app. Some apps deliberately detect VPN interfaces and refuse to send traffic through them—TUN mode makes that detection easier for them.

For most users, system proxy mode is enough. Turn on TUN if you need to proxy a game, a mail client, or an app that is clearly ignoring the proxy in system mode.


Step 7: Set Up Per-App Proxy

Clash for Android can route traffic per app. This is useful when you want only certain apps to use the proxy while everything else stays on the normal connection. The setting lives under Settings → Network → Access Control (the exact label varies by build).

You will see two modes:

  • Blacklist mode: Every app is proxied except the ones you select.
  • Whitelist mode: Only the apps you select are proxied.

The correct choice depends on your goal. If you want most things proxied and only a few apps to stay local, use Blacklist and add those few apps. If you want almost everything local and only a browser or a specific chat app to go through the proxy, use Whitelist and add just those.

Tap Access Control App List to open the app picker. Check the boxes for the apps you want to include. The change takes effect immediately—no need to restart the tunnel.

One limitation: per-app proxy works at the application level, not the connection level. If an app talks to both domestic and overseas servers (a common pattern in banking apps and delivery apps), you cannot route only the overseas connections through the proxy while keeping the domestic ones direct. For that level of control, you need TUN mode combined with rule-based routing, and even then the app's behavior may not cooperate.


Troubleshooting Common Clash for Android Issues

The VPN icon is there but nothing loads

This is the most common symptom. Work through these in order:

  • Check the mode. If you are in Direct mode, nothing will be proxied. Switch to Rule.
  • Check the profile. Make sure the subscription profile is selected, not just downloaded. A downloaded-but-unselected profile does nothing.
  • Check the node. In the Proxy tab, make sure a real node is selected, not "DIRECT" or "REJECT." Some proxy groups default to DIRECT when no node has been chosen yet.
  • Check the subscription freshness. Tap the profile and trigger a manual update. Providers rotate nodes; a profile from two weeks ago may point to dead servers.
  • Check system time. Android refuses TLS connections when the clock is off by more than a small margin. If your system time is not set to automatic, enable that and retry.

It works on Wi-Fi but not on mobile data, or vice versa

This usually points to a DNS issue specific to one network, or a captive portal on the Wi-Fi. If the Wi-Fi requires a login page, the subscription cannot download until you authenticate. On mobile data, some carriers interfere with DNS in ways that Wi-Fi does not. Try switching the DNS settings in Clash to a well-known resolver, or enable Fake IP if your profile supports it. If the problem follows the network, not the app, the fix is almost never inside Clash.

It dies after a few minutes in the background

This is an Android battery optimization problem, not a Clash problem. OEM ROMs—Xiaomi, Huawei, Oppo, Vivo, and others—aggressively kill background services. You need to do three things:

  1. Disable battery optimization for Clash. Go to Settings → Apps → Clash → Battery, and set it to "Unrestricted" or "Don't optimize."
  2. Allow autostart. In the same app settings page, find an "Autostart" or "Startup manager" option and enable it.
  3. Lock the app in the recent tasks view. Open the recent apps screen, find the Clash card, and tap the lock icon. This prevents the system from swiping it away during a memory cleanup.

On MIUI and HyperOS specifically, also enable Show pop-up windows and Display in status bar for Clash. The notification icon is not cosmetic—it is one of the signals Android uses to decide whether the app is "foreground enough" to keep its VPN service alive.


Is Clash for Android Still Maintained in 2026?

The original Clash for Android by Kr328 is no longer actively maintained. It still works on many devices, but newer Android versions have introduced background restrictions and permission changes that the old code does not handle well.

If you are starting from scratch in 2026, consider a maintained Mihomo-compatible client instead. These use the same configuration format, the same subscription links, and largely the same interface logic. The setup steps in this guide apply to them as well—the menus may be arranged slightly differently, but the concepts of profiles, VPN permission, proxy modes, and per-app routing are identical.

If you already have CFA working on your device and it does what you need, there is no urgent reason to switch. If you are installing fresh and running into crashes on Android 14 or 15, the maintained alternatives will save you time.


FAQ

What is Clash for Android used for?

Clash for Android is used as a rule-based proxy client on Android. It reads a subscription configuration and routes traffic either direct or through a proxy based on rules, rather than sending everything through a single server like a traditional VPN app.

Is Clash for Android free?

The Clash for Android app itself is free and open source. You still need a subscription from a provider to get working nodes. The app does not include free servers, and any APK claiming to bundle "free nodes" should be treated as suspicious.

Can I use Clash for Android without a subscription?

No. Clash for Android needs a configuration file or a subscription link to know which nodes to connect to. Without one, the app has no servers to route through and will not proxy anything.

Does Clash for Android work on Android 14 and 15?

The original CFA build still runs on many Android 14 and 15 devices, but background restrictions and permission changes on newer Android versions can cause crashes or premature disconnections. Maintained Mihomo-compatible clients handle these versions more reliably.

Why does Clash for Android disconnect in the background?

Android's battery optimization kills background services on many OEM ROMs. Disable battery optimization for the app, allow autostart, and lock the app in the recent tasks view to keep the VPN service alive.

What is the difference between Rule, Global, and Direct mode?

Rule routes traffic according to your profile's rules and is the correct daily setting. Global forces all proxyable traffic through the selected node and is useful only for debugging. Direct bypasses the proxy entirely.

Do I need TUN mode on Clash for Android?

Only if you need to proxy apps that ignore the system proxy—games, some email clients, and apps using raw TCP or UDP. For browsers and most apps, the default system proxy mode is enough.


Where to Go Next

Once your Android setup is stable, the same subscription link usually works on every other device you own.

If you are setting up a household or a small office, the family share, professional office, and all-in-one plans are built for multiple devices under one account. Heavy users should look at the 2TB flagship and 1TB capacity tiers.

Business users can compare business starter, business standard, and business ultimate, or step up to enterprise starter, enterprise standard, and enterprise ultimate for larger teams.

Casual users will find daily use, basic starter, basic unlimited, standard plus, and ultimate unlimited cover most day-to-day needs.


That covers the full setup. The key habits are: keep the subscription URL private, use Rule mode for daily use, check the profile is selected before blaming the nodes, and fix the OEM battery settings early rather than fighting mysterious disconnections later.

Recommended High-Speed VPN

Standard Plus Package

Traffic: 200G · Devices: 10 · 365 days

HD Streaming Package

Traffic: 300G · Devices: 10 · 365 days

Basic Unlimited Traffic

Traffic: 99,999G · Devices: 10 · 365 days

All-in-One Package

Traffic: 500G · Devices: 10 · 365 days

About This Article

This article is part of our Android VPN Tutorial series — covering VPN setup, configuration, privacy, and network optimization for Wraith VPN users.

Wraith VPN provides global high-speed nodes, multi-device support, stable access to streaming media, anonymous USDT payment, and a strict no-logs policy.

Looking for a plan? Visit our VPN Packages page. For common questions, see FAQ.

Last updated: September 28, 2026