Setting up a VPN on an iPhone is usually straightforward once the roles of the account, subscription URL, Shadowrocket, and selected server are clear. The difficult part is not tapping the connection switch; it is making sure that the correct subscription is copied, imported into the right place, updated when necessary, and tested without confusing a routing problem with an account or network problem. This iPhone VPN setup guide walks through the complete Shadowrocket workflow: prepare the account, obtain the subscription URL, add it to Shadowrocket, update the available nodes, choose a server, approve the iOS VPN profile, verify the result, and troubleshoot the most common beginner errors.

Before You Start: Account, App, and Network

Begin on a network that can currently open ordinary websites. You need a working connection to sign in, open the user panel, retrieve the subscription URL, and complete the first configuration update. If the underlying Wi-Fi or mobile network cannot load websites at all, an import failure may be incorrectly blamed on Shadowrocket. Test the network with a few normal pages before changing any proxy settings.

NrVPN does not require an email address for registration. An account can be created with a username and password, and the user panel is the place to check the plan, subscription, and client-related information. Keep the username and password in a private password manager or another secure location. The subscription URL should be protected in the same way. Anyone who obtains the full URL may be able to retrieve the configuration associated with it, so do not paste it into a public chat, a forum post, a screenshot, or an untrusted online conversion tool.

On the iPhone, make sure Safari or another browser can copy the entire URL without truncation. A subscription URL can be long, and copying only part of it may produce an error that looks like an invalid server response. It is also useful to keep the account panel open in one tab and Shadowrocket available on the device, so you can return to the source and copy the link again if necessary.

Preparation check

You are ready to continue when the account panel opens normally, the subscription URL can be copied in full, and Shadowrocket is installed. There is no need to manually edit iPhone DNS or system proxy settings before importing the subscription.

What a Subscription URL Does in Shadowrocket

A subscription URL is a remote configuration entry point. When Shadowrocket accesses it, the app may receive server addresses, ports, protocol information, encryption or authentication parameters, node names, and groups used for selection. The exact content depends on the service and the format supplied by the provider. The URL itself does not establish a connection. Shadowrocket must first retrieve and parse the data, then use a compatible node to create the connection.

This distinction explains several common situations. A URL can be valid but still produce no usable nodes if the client does not understand the returned format. An import can appear to succeed while the list remains outdated if the subscription has not been updated. A node can be visible but fail to connect if the protocol, transport, credentials, or current network conditions are incompatible. These are different stages and should be checked separately instead of repeatedly tapping the connect button.

100+

Countries covered

250+

Available routes

5

Supported platforms

Unlimited

Device count

Shadowrocket is a client, not a universal decoder for every configuration format. Subscription data may refer to protocols such as Shadowsocks, VMess, Trojan, VLESS, Hysteria2, TUIC, or WireGuard, but support depends on the version and core used by the client. A provider may also deliver different formats for different clients. If the user panel offers a client-specific subscription or an import option intended for Shadowrocket, use that option instead of copying a generic URL at random.

Object What it does What it does not do Typical beginner mistake
Account Authenticates access to the user panel and service Does not automatically configure Shadowrocket Assuming the app can connect with only the account password
Subscription URL Delivers remote configuration data to a compatible client Does not function as a VPN app by itself Sharing the URL or copying it incompletely
Shadowrocket Imports configurations, applies rules, and starts the connection Does not repair an invalid or expired subscription Reinstalling the app instead of updating the subscription
Selected node Provides the route used for the active connection Does not guarantee that every website or app will use it Testing a website while the request is routed directly

Import the Subscription URL into Shadowrocket

The exact button labels can vary slightly between Shadowrocket versions, but the workflow is consistent: copy the URL, add it as a remote subscription, save it, and run an update. Do not paste the link into the manual node form unless the provider specifically gives you a single node URI. A subscription URL belongs in the subscription or remote-resource area because it may contain a list of nodes and update metadata.

  1. Open the NrVPN user panel. Sign in with your username and password, then open the section containing the subscription information. If you have more than one link, choose the one marked for a compatible client or subscription import.
  2. Copy the complete URL. Use the panel’s copy control when available. Avoid selecting only the visible first line of a wrapped URL. Do not modify punctuation, capitalization, query parameters, or the beginning protocol such as https://.
  3. Open Shadowrocket. Go to the section for subscriptions, remote files, or configuration resources. The wording may differ by app version, but the function is to add a remotely updated configuration.
  4. Add a new subscription. Paste the URL into the URL field. Give it a short local name such as NrVPN so it is easy to identify later. A local name is only a label; it does not change the remote configuration.
  5. Save the entry. Return to the subscription list and confirm that the new item is visible. At this stage, seeing the subscription entry does not necessarily mean that its nodes have already been downloaded.
  6. Run an update. Use the update or refresh action for that subscription. Wait for the operation to complete, then open the node list and check whether configurations have appeared.

If Shadowrocket asks for permission to access the clipboard, review the prompt carefully and allow the action only when you intentionally copied the subscription URL. If the URL does not appear after pasting, return to the browser and copy it again. iOS clipboard behavior, an interrupted copy action, or a line break inserted by another app can make a valid URL look empty or incomplete.

Update the List and Select a Server

After the subscription update finishes, open the list of available nodes. Names often include a country, city, region, or route description, but a name is only a label. It does not by itself prove that the route is currently suitable for a particular website, application, or time of day. Start with a geographically reasonable location and then compare alternatives based on the actual task you need to complete.

Shadowrocket may also show groups, policies, or rule-related selections. A group can decide which node is used, while a rule set can decide whether a request goes through the proxy or connects directly. These are separate decisions. Selecting a node does not necessarily mean every request will use that node if the active routing mode sends some domains directly.

For a first test, keep the configuration simple. Select one clearly named node, choose the ordinary rule or global behavior that matches your intended test, and avoid changing several advanced options at once. Once the connection is confirmed, you can return to split routing and application-specific behavior. Changing multiple variables simultaneously makes it difficult to identify which setting caused a problem.

What you see Likely meaning Next action
Subscription entry is visible, but no nodes appear The update did not complete, the format is incompatible, or the URL is incomplete Copy the URL again, update once more, and verify the client-specific format
Nodes appear with readable names Shadowrocket parsed at least part of the returned configuration Select one node and proceed to the connection test
A node is selected, but traffic remains direct The active rule or routing mode may bypass the proxy Check the mode and test with a request that should use the selected route
The node is visible but connection fails The node may be unavailable, incompatible, or blocked by the current network Try another compatible node and review the connection log

Connect, Approve iOS Access, and Verify the Result

Once a node is selected, tap the main connection switch in Shadowrocket. iOS may display a system permission prompt explaining that the app wants to add a VPN configuration. Read the prompt and approve it if you intend to use Shadowrocket. This permission is a normal part of allowing a VPN client to create its local tunnel; it is separate from importing the subscription.

After approval, wait for the app and the iOS status area to show an active connection. Then verify the result in layers. First, confirm that Shadowrocket reports an active connection rather than merely showing a selected node. Second, open an IP-check page to see whether the visible exit IP and approximate location have changed as expected. Third, test the specific website or application that you actually need. A successful tunnel does not guarantee that every service will respond in the same way, because websites may use their own account region, DNS behavior, device settings, or application-level policies.

Test both a normal browser page and the target application when possible. If the browser works but the application does not, inspect the application’s own account, region, cache, and network settings before changing the entire subscription. If some domains work and others do not, check whether the active rules send those domains directly. A connection icon alone is not a complete diagnosis.

Verification result

A reliable setup has three matching signals: the subscription is imported, the client reports an active connection, and an external IP check or target application shows the expected routing result. If only one signal is present, continue diagnosing instead of assuming the setup is complete.

Fix the Most Common Shadowrocket Problems

The URL is rejected or cannot be added

First check whether the entire URL was copied. Long links can be truncated when copied from a formatted message, and punctuation can be lost when a URL passes through a note-taking app. Copy it directly from the user panel again. If the panel provides more than one format, use the option intended for Shadowrocket or a compatible remote subscription. Do not add spaces before or after the URL, and do not replace characters that look unusual.

Also confirm that the current network can reach the subscription address. A client cannot retrieve remote data if the domain is unavailable on the underlying network. Try again from a normal connection, then check whether the subscription entry has an update timestamp or error detail. Reinstalling Shadowrocket will not repair an incomplete URL.

The subscription is saved, but no nodes are listed

A saved subscription entry is only a local record of the URL. Run the update action and wait for a result. If the list remains empty, inspect the update log if Shadowrocket provides one. Common causes include an expired or revoked link, a service-side format change, a response that the client cannot parse, or a subscription designed for a different client core. Contact support with the error wording and the client version, but never send the full private URL in a public ticket or discussion.

A node appears but will not connect

Try another node from the same subscription rather than editing protocol fields immediately. A single route can be temporarily unavailable while the subscription itself remains valid. If every node fails, compare the result on Wi-Fi and mobile data, check the device date and time, and review the log for handshake, DNS, timeout, or authentication messages. These clues point to different layers of the connection.

The browser works, but an app does not

Review Shadowrocket’s routing mode and rules. Some requests may be configured as direct traffic, so the app can bypass the selected node even while the tunnel is active. Also check whether the application has cached a previous result, uses its own account region, or restricts connections based on device settings. Test one change at a time and restore the previous working configuration if the result becomes less clear.

Old routes remain after an update

Confirm that you updated the existing subscription instead of creating a second entry with a similar name. Duplicate entries can make it unclear which list is active. Remove or disable obsolete local profiles only after confirming that the current subscription has been saved successfully. Keep the remote subscription as the source of truth instead of manually editing every node, because manual changes may be overwritten during the next update.

Maintain the Setup Without Making It Fragile

Once Shadowrocket is working, avoid unnecessary changes. Keep one clearly named subscription entry, update it when the provider publishes new configurations, and record which routing mode was working during your initial test. If you use the iPhone on several networks, remember that Wi-Fi restrictions, mobile carrier behavior, captive portals, and local DNS responses can differ. A configuration that worked on one network may require a different route on another, but that does not automatically mean the account or subscription is broken.

Protect the subscription URL whenever you copy it between devices. Do not include it in screenshots, public troubleshooting posts, or a shared note. If you believe it has been exposed, return to the user panel and look for a way to refresh or replace the subscription credential, or contact support for the correct recovery procedure. When moving to another compatible client, import the subscription through that client’s supported method rather than converting it through an unknown website.

For multi-device use, remember that NrVPN supports Windows, macOS, iOS, Android, and Linux, and the number of simultaneously online devices is unlimited. The subscription format still matters: a URL that works in one client may need a different client-specific format or core in another. On iPhone, keep Shadowrocket updated through the official distribution channel available to you, but do not assume an app update can fix a server-side subscription issue.

NrVPN offers monthly plans of ¥9.9 per month with 60GB, ¥18 per month with 250GB, and ¥28 per month with 500GB. Monthly traffic resets on the activation date, and an upgrade during the cycle uses a remaining-days difference calculation. Traffic packages are available at ¥158 for 300GB, ¥358 for 1000GB, and ¥658 for 3000GB; they remain available until used and do not expire. Before selecting an option, compare your actual usage pattern with the traffic rules shown in the user panel rather than choosing only by the displayed amount.

Stage Successful result If it fails
Account The user panel opens and the subscription section is available Check credentials and the underlying network before touching Shadowrocket
Copy The complete private subscription URL is in the clipboard Copy directly from the panel and avoid formatted intermediaries
Import The remote subscription entry is saved in Shadowrocket Use the remote subscription field, not a single-node field
Update Nodes and groups appear after the refresh action Check the response, format compatibility, and link status
Connect iOS approves the profile and Shadowrocket reports an active tunnel Review permission, selected node, routing mode, and logs
Verify An IP check and the target application show the expected result Test direct versus proxied routing and compare another compatible node
Final takeaway

The dependable iPhone workflow is simple: copy the current subscription URL privately, add it as a remote subscription in Shadowrocket, update the list, select a compatible node, approve the iOS VPN profile, and verify actual traffic. When something fails, identify the stage first—copying, importing, parsing, connecting, routing, or application behavior—before changing settings.