FAQ

Shadowrocket FAQ: Genuine App Checks, Install and Subscription Import Troubleshooting

20 Q&As across four themes: storefront verification and purchase facts, installing and authorizing on iPhone and iPad, subscriptions and node import, and Global Routing plus connection troubleshooting. Each answer gives an actionable sequence of steps, with interface terms kept in their original English so you can match them against your device.

  • DeveloperShadow Launch Technology Limited
  • App ID932747118
  • PriceOne-time purchase
  • PlatformUniversal for iPhone and iPad

QUESTIONS

Four FAQ categories to work through in order

Every answer is a sequence of steps, not just a conclusion. Find the category that matches the symptom, then verify each item in the steps listed.

01

Genuine App Checks & Purchase

Developer name · App ID · One-time purchase

Can't find Shadowrocket in the App Store - what now?

First, make sure you are searching the full English name Shadowrocket, not a Chinese nickname. App Store search ranking depends on the storefront your signed-in account belongs to, and the same app may be listed in some storefronts and not others.

If it still does not appear, open the product page directly: the store URL ends with id932747118. Once it opens, check the developer name and the app icon to confirm it is the same app. If the page says the app is unavailable in your region, that storefront does not carry it, and you will need to review your account region settings using Apple's official support documentation.

How do I confirm I bought the genuine app?

Check three things on the store page: the developer name Shadow Launch Technology Limited, the app icon (a rocket with a blue-purple gradient outline on a white background, matching the icon in this site's header), and the app ID 932747118 (the id932747118 at the end of the store page URL). Only when all three match is it the same app.

Search results include many apps with the same or similar names, so judging by name alone can lead to a wrong purchase - go by the developer name and app ID. For the full verification steps, see the App Store verification page.

How much does Shadowrocket cost? Is it a subscription?

It is a paid app sold as a one-time purchase: about USD 2.99 in the US storefront, shown in local currency elsewhere, with the exact amount as listed on the App Store page.

The purchase covers the client only and does not include any servers, nodes or subscriptions - buying the client is not the same as buying a service plan; nodes and subscriptions must come from your own provider.

I got a new iPhone - do I have to buy it again?

No. Sign in to the App Store with the same Apple ID you used for the purchase, find Shadowrocket under Purchased and download it again - you will not be charged twice.

Whether Family Sharing is supported, and whether Mac and Apple TV are covered by the same purchase, depends on what the App Store page states.

The app isn't available in my account's storefront - can I change regions?

The App Store storefront is determined by the region of the Apple ID you are signed in with. If you need to change it, follow the path in Apple's official support documentation to update your account region and handle the payment method required for that region.

This site takes no part in any account-level operations and does not provide accounts. Before buying, check three things: storefront, price and compatibility.

02

Install & First Launch

VPN configuration authorization · iPhone · iPad

How do I install it on iPhone? What are the system requirements?

Tap Get on the App Store page and confirm with Face ID, Touch ID or your password to start the download; the icon appears on the Home Screen when installation finishes.

The required system version is whatever the App Store page states - the Compatibility section lists the supported devices and OS versions. Before installing, check that your device has enough free space.

What is the "Add VPN Configuration" prompt on first launch?

It is a system-level authorization dialog in iOS. For the client to take over network requests at the system level, it must register a VPN configuration through this dialog; after you allow it, you will be asked to verify your device passcode or Face ID.

If you decline, the client cannot establish a connection - open the app again to trigger the prompt once more. Authorized configurations can be viewed under Settings → General → VPN & Device Management, and removed there when you no longer need them.

Can I install it on iPad? How is it different from iPhone?

The same App Store page lists both iPhone and iPad, so if you already bought it with the same Apple ID you can download it directly on iPad.

The interface is wider on iPadOS, but the settings are the same as on iPhone: Home, Config, Global Routing, On Demand and Data all sit in the same places. The VPN configuration authorization flow on iPad is identical to iPhone.

The interface is in English - is there a Chinese version?

The settings in the client interface appear in their original English wording, for example Home, Config, Global Routing, On Demand, Add Server, Subscribe. Our guides keep those terms as-is and explain them, so you can find each item by matching the word.

Displays may differ slightly between system versions; go by what you actually see on your device.

Does it work on Mac and Apple TV?

The Compatibility section of the same App Store page lists Mac, Apple TV and Apple Vision, and the system requirements and whether it is a universal purchase are as stated on the store page.

Getting it on Mac works the same way as on iPhone - everything happens inside the App Store.

03

Subscriptions & Node Import

Subscribe · Scan QR Code · Add Server

Where do subscription links come from?

Subscription links come from your own provider. This site does not provide, sell or recommend any subscription, node or plan. Before importing, confirm with your provider whether the link is valid, whether it is tied to a device limit, and whether it needs to be reset periodically.

The one-time client purchase covers the app only; the service is a separate matter.

How do I import a subscription into Shadowrocket?

Open the Home page, tap + in the top-right corner, choose Subscribe, paste the full link from your provider into the URL field, put a label in Remark, and save - the app then fetches the node list once automatically.

You can also use Scan QR Code to scan your provider's QR code, or Import from Cloud JSON to import a configuration file. A sample link looks like https://example.com/sub?token=xxxx; use whatever link your provider gives you. For step-by-step instructions, see the tutorial.

Subscription update failed with an error - what should I do?

Work through these in order:

  1. Open the subscription link in a browser and see whether it returns content. If it does not open, the link has expired or been reset by your provider - confirm with them.
  2. Check that the link was copied in full; the token parameter after ? is often truncated by chat apps.
  3. Make sure your current network can reach the provider's domain directly; if needed, switch to Direct mode first and then update.
  4. Open Config, find the subscription entry and trigger an update manually.
  5. If it was just an occasional timeout, simply retry later.

A subscription update rebuilds the node list from the configuration your provider delivers, so earlier manual changes are not kept.

Which fields do I fill in when adding a server manually?

On the Add Server page: pick the protocol in Type (Shadowsocks, VMess, VLESS, Trojan, Hysteria2, WireGuard), enter the server address in Address, the port in Port, fill in Password or UUID with the details your provider gives you, and put a recognizable name in Remark.

The example values are for format reference only: Address as example.com, Password as your-password — enter the real parameters supplied by your provider.

My subscription has too many nodes - can I keep just a few?

You can view subscription entries in Config and control whether they are enabled, but a subscription update rebuilds the node list from the configuration your provider delivers, and entries you deleted manually usually do not survive.

A more reliable approach is to keep Global Routing in Config mode and let rules decide which traffic goes through the proxy, rather than controlling things by deleting nodes.

04

Rules & Troubleshooting

Global Routing · On Demand · REJECT

How do I choose between the three Global Routing modes?

Global Routing has three modes: Config (rule-based routing, the default), Proxy (all traffic through the proxy) and Direct (all traffic direct).

For everyday use, stay on Config and let rules decide between direct and proxy. If you suspect a domain is being matched incorrectly, switch to Proxy temporarily to test - if it works there, the problem is in your rules. Switch to Direct when you need to restore your local network temporarily. For the differences between the three modes, see Features & Settings.

The connection switch won't turn on, or it turns off right after I enable it?

Check in order:

  1. Whether you have added at least one server or subscription - with no usable nodes, no connection can be established.
  2. Whether the first-time VPN configuration authorization was declined; check under Settings → General → VPN & Device Management.
  3. Whether other VPN configurations exist on the device - remove the ones you no longer use.
  4. Whether a restriction is enabled under Screen Time.
  5. Restart the device and try again.
It says connected, but web pages won't load?

Narrow it down in this order:

  1. Switch to Direct mode and confirm the local network itself has internet access. If Direct also fails, the problem is not the proxy.
  2. Switch to Proxy mode. If Proxy works but Config does not, your rules are sending that domain to DIRECT; check the rule order.
  3. Go back to Config and run a latency test on the server list to see whether the node is usable.
  4. Confirm whether the subscription has expired or its data allowance is used up.
  5. Check whether On Demand is dropping the connection when the network changes.
Does leaving it on all the time drain the battery or use a lot of data?

While the client is running, it keeps a system network extension active. Battery use depends on how heavily you use it, node latency and the number of rules - there is no single fixed figure.

The Data page gives you two sets of readings, by server and by app, so you can see how much traffic actually went through and which app is responsible; On Demand can cut down idle work on networks where you don't need it. Actual results depend on your device and network environment.

I added a REJECT rule - why do ads still appear?

REJECT can only block domains or IPs that a rule matches, and only while traffic passes through the client: under HTTPS the request path is not visible, and in-app requests, requests using their own DNS, and domain fronting can all bypass rules.

So how well rule-based blocking works varies by app, and no ad-blocking result is promised. To check whether a rule matched, review the matching order of DOMAIN-SUFFIX, GEOIP and FINAL. For details, see REJECT rules: how blocking works and where it stops.

Need more detailed steps?

For step-by-step instructions see the tutorial; for the full flow from getting the app to day-to-day upkeep see the complete guide; for how rules are written see what DOMAIN, GEOIP, IP-CIDR and FINAL each match.

Always get subscription links and node details from your own provider; a one-time client purchase is not a service plan.