Identify the operating system first, then choose between a graphical client and the standalone core. A graphical client manages subscriptions, proxy modes, the system proxy, and TUN; Mihomo is better suited to servers, routers, and environments where service configuration is maintained manually.
The platform tab is reflected in the page URL. Share an anchored link and the recipient can open the matching system directly. Switching tabs only changes the displayed platform; it does not start a download.
Clash for Windows
Most desktop users should start with the installer. Before downloading, check Settings → System → About in Windows; the Windows graphical client downloads here target common x64 systems.
WINDOWS / X64
Clash Plus
Top pick
For Windows users who want one graphical interface for subscriptions, proxy modes, policy groups, and traffic interception. After installation, import a configuration and confirm it is selected. The system proxy and TUN are different interception methods, so choose according to the apps you need to cover.
Installation type
x64 installer
Configuration entry
Import a subscription or local configuration in the graphical interface
Best for
Everyday desktop use, rule-based routing, and configuration maintenance
Provides graphical controls for switching configurations, the system proxy, TUN, and rules. Suited to users familiar with Clash basics who want more granular configuration management. If service mode or TUN is required on first launch, follow the client’s prompts to grant system permissions.
Installation type
x64 installer
Configuration methods
Subscription import, local configuration, and override settings
Important
After switching configurations, recheck the policy group and interception status
A cross-platform interface for users who want similar workflows across desktop and mobile devices. On Windows, choose either the installer or an archive for a self-contained directory; both use the same configuration content, differing mainly in installation and update workflows.
Primary option
x64 installer
Alternative format
x64 archive
Before use
Confirm that the configuration parses correctly and define the scope of the system proxy or TUN
For users who want to maintain multiple configurations, review logs, and control proxy switches from a desktop interface. After installation, do more than confirm that the window opens: check listening ports, the active proxy mode, and the route used by the target application.
Installation type
Windows x64 installer
Managed items
Configuration files, proxy policies, and system interception settings
Verification
Check client logs and test browser and terminal paths separately
Reserved for users managing existing installations and legacy configurations. It is not recommended as the starting point for a new environment. Archived packages can help read old configurations before migration, but first separate client settings, subscription content, and local overrides to avoid overwriting files that must be preserved.
Maintenance status
Archived client, no longer maintained
Use cases
Legacy environment recovery, configuration migration, and compatibility checks
Migration focus
Record ports, DNS, rule providers, and policy group names
The installer may not start when the architecture does not match.
Installation permissions
Grant permissions when prompted by the installer
Service mode or TUN may need system-level components.
Legacy clients
Record the configuration directory and listening ports
Running multiple clients can cause port conflicts or overwrite each other’s system proxy settings.
Startup verification
Check logs first, then enable traffic interception
This separates configuration parsing issues from system proxy issues.
Clash clients for macOS
Open About This Mac to identify the chip. Choose ARM64 or Apple Silicon for Apple M-series chips and x64 for Intel processors. After downloading, follow the client’s process for security prompts, VPN configuration, or network extension permissions.
MACOS / ARM64 / X64
Clash Plus
Top pick
Separate downloads are provided for Apple Silicon and Intel Macs. These clients suit users who want to import configurations, choose proxy modes, and manage system interception from a graphical interface. Read each macOS permission prompt carefully; the required scope depends on the features enabled.
Apple Silicon
For Apple M-series chips
Intel
For Intel-based Macs
After installation
Import a configuration, choose policies, then enable the required proxy interception
For macOS users who need configuration overrides, rule management, the system proxy, and TUN controls. The two architecture downloads in this list are maintained separately by the release service; after downloading, verify the package against the chip shown in About This Mac.
Configuration management
Subscriptions, local configurations, and override rules
System integration
System proxy, service mode, and TUN settings
Permissions
Approve only the system permissions requested for the features you use
Offers a configuration and policy workflow similar to other platforms, making it suitable for users who switch between desktop and mobile devices. Use the chip information to choose a package; after importing a subscription, check rule mode, the default policy group, and traffic interception.
Installation format
DMG disk image
Available options
Separate Apple Silicon and Intel builds
What to verify
The app’s proxy route, DNS behavior, and policy selection
The archived download is for recovery and migration checks on existing ClashX Meta installations. Before installing, record menu bar settings, the configuration directory, the external control port, and local overrides. When migrating, do not assume options with matching names work the same way.
Maintenance status
Archived client, no longer maintained
Best for
Legacy configuration access, environment recovery, and migration preparation
Migration checks
DNS, rule providers, policy groups, and system proxy settings
Apple M-series chips use ARM64; Intel processors use x64.
App installation
Open the DMG and move the app to Applications
Do not run the client directly from the disk image long term.
Network permissions
Handle VPN or network extension permissions as requested by the features
Traffic interception works differently across clients.
Keychain prompts
Confirm which client is requesting access and why
Saving system-level network settings may trigger credential authorization.
Clash clients for Android
Most recent phones and tablets use ARM64. Older 32-bit devices can use ARM32; when the architecture is unknown, start with the available universal package. After installation, Android must approve the VPN connection before app traffic can enter the client.
ANDROID / ARM64 / ARM32
Clash Plus
Top pick
For common ARM64 Android devices. Import a subscription, choose policies, and establish a system VPN connection from the mobile interface. A successful import only means the configuration can be read; select it, confirm the policy group, and approve the connection request in Android.
Installation architecture
ARM64
Interception method
Android system VPN interface
First connection
Approve the VPN request and review battery and background-running policies
Offers ARM64, ARM32, and universal builds for Android users who need to match a package to their device architecture. Most recent devices use ARM64; the universal package supports more architectures and suits cases where the processor architecture cannot be confirmed from device information.
ARM64
Most recent Android phones and tablets
ARM32
Older 32-bit ARM devices
Universal build
Use when the architecture is unknown; the file is usually larger
A cross-platform interface for similar configuration workflows on Android and desktop systems. ARM64 covers most newer devices, ARM32 older devices, and x86_64 some emulators and specialized hardware.
Common choice
Android ARM64
Older devices
Android ARM32
Specialized environments
x86_64 emulators or devices using that architecture
Provides a universal Android package for users who want a mobile rule-based proxy interface without having to identify the device architecture. Client support for configuration fields varies, so review parsing notices after import and confirm that rules and policy groups are complete.
Installation type
Universal Android package
Configuration check
After import, verify field compatibility and policy group contents
Connection method
Use the system VPN interface to intercept selected traffic
Older devices may need ARM32; emulators may use x86_64.
Unknown architecture
Choose the universal package
Universal packages support more devices but are usually larger.
VPN permission
Approve the system request on first connection
Without approval, the client cannot create a system traffic path.
Background operation
Check battery saver and background restrictions
System process cleanup can interrupt the connection.
Clash clients for iOS
Install Clash Plus on iPhone or iPad through the App Store. Import a subscription or local configuration, choose a policy group, and add the VPN configuration when prompted by iOS. Importing a configuration and establishing the system connection are separate steps.
IOS / APP STORE
Clash Plus
App Store · Top pick
A graphical client for iPhone and iPad with configuration import, proxy policy selection, and system VPN controls. On the first connection, iOS displays a system dialog to add the VPN configuration; after approving it, return to the client and confirm the active configuration and policy.
Open the product page in the App Store and install it
The app icon appears on the device Home Screen or in the App Library.
Configuration
Import a subscription or local configuration
The client displays the configuration and policy group contents.
Authorization
Add the VPN configuration when prompted by iOS
The client receives permission to create a system network tunnel.
Verification
After connecting, check the policy and target app
Confirm that traffic follows the active rules and policy group.
Clash clients for Linux
On desktop Linux, choose Clash Verge Rev or FlClash. First check the distribution package format and CPU architecture: Debian and Ubuntu commonly use DEB, while Fedora and RHEL-based systems commonly use RPM. The client packages here target AMD64 desktop environments.
LINUX / AMD64
Clash Verge Rev
Recommended
For Linux users with a desktop environment who need graphical configuration management. DEB targets Debian, Ubuntu, and compatible distributions; RPM targets Fedora, RHEL-based, and compatible distributions. If TUN is needed, also check permissions, service status, and route changes after installation.
For Linux desktop users who want a cross-platform graphical interface. The primary download here is AMD64 DEB, with RPM and AppImage for other distributions. AppImage usually needs executable permission before launch, and you manage its file location yourself.
Primary option
Linux AMD64 DEB
Other formats
AMD64 RPM and AppImage
Configuration workflow
Import a configuration graphically, then check the system proxy or TUN
Use DEB for Debian-based systems and RPM for RHEL-based systems
The native format simplifies dependency and uninstall management.
Processor architecture
Confirm the system is AMD64 / x86_64
The graphical client files in this section are not for ARM64 Linux.
Desktop environment
Confirm a graphical session and tray support
Headless servers are better suited to the Mihomo core below.
Terminal proxy
Set the required environment variables separately
A desktop system proxy does not necessarily affect shell and command-line programs.
MIHOMO CORE Server and router downloads
Standalone Mihomo Core
Mihomo handles proxy protocols, DNS, rule evaluation, and policy group execution; it is not a desktop graphical client. Most Windows, macOS, Android, iOS, and Linux desktop users should choose the GUI clients above.
A configuration file is not a client settings page
The standalone core typically reads listening ports, DNS, proxies, policy groups, and rules from a YAML configuration. Before starting, use the command line to check that it parses correctly, then connect it to systemd, a container, or router service management. This prevents syntax errors from being hidden by an automatic restart loop.
The architecture name must match the device
AMD64 is often written as x86_64, while ARM64 is often written as aarch64. ARMv7 and MIPS softfloat target specific embedded devices. The operating system name alone is not enough; also verify the processor architecture and the system ABI.
AFTER DOWNLOAD Installation and connection sequence
From installation to connection testing
Downloading the file is only the first step. If the client is running but an app still cannot connect, check configuration, policy, interception, and the app’s route layer by layer instead of repeatedly switching clients.
01
Finish installation and run only one client
Close older clients that may use the same listening ports. After starting the new client, check the logs first. If no configuration has been imported, do not enable TUN or the system proxy yet; otherwise configuration and interception issues become difficult to separate.
02
Import a subscription or local configuration
The subscription URL comes from a separate subscription service; the client does not generate one automatically. After importing, confirm that the configuration parses correctly and distinguish remote subscription content from local overrides. When updating, fields changed locally may be replaced by the new content.
03
Choose a proxy mode and policy group
Rule mode determines the route according to the order of rules in the configuration. Global mode usually sends most traffic to a selected policy, while direct mode bypasses the proxy. After choosing a mode, check the actual option in each policy group; a group name does not guarantee that a usable choice exists.
04
Enable the required traffic interception method
The system proxy suits apps that follow the operating system proxy settings. TUN can cover a broader network path but requires appropriate permissions and routes. Do not enable the system proxy or TUN in multiple clients at once, as this can create port, route, and DNS conflicts.
05
Test the browser and terminal separately
A working browser does not mean that the shell, package manager, or developer tools use the same proxy route. First check whether the client log shows the target request, then review the app’s own proxy settings, terminal environment variables, and DNS resolution path.
These answers cover file selection, system architecture, and the connection steps after installation. For specific configuration fields, rule routing, and TUN behavior, continue to the user guide.
What do I need after downloading a Clash client?
A client handles configuration, traffic interception, and core control. Before use, you typically need an active subscription or local configuration file. Import it, select the active profile, check the proxy mode and policy group, then enable the system proxy or TUN for the apps you need to cover. Subscription services, graphical clients, and the core that executes rules are separate layers; installing one does not provide the others.
Should I choose the Windows installer or archive?
The installer suits most desktop users because it places program files and creates system shortcuts through a guided setup. Choose an archive when you need a portable directory or prefer to manage program files manually; after extraction, you maintain the runtime directory, shortcuts, and replacement updates yourself. Both formats use subscriptions and rules in the same basic way.
How can I tell Apple Silicon from Intel on a Mac?
Open About This Mac from the Apple menu and check the chip or processor field. Choose Apple Silicon or ARM64 for Apple M-series chips and Intel or x64 for Intel processors. If a filename does not clearly identify the architecture, rely on the download entry and your device information.
Should I download ARM64, ARM32, or the universal Android build?
Most recent Android phones and tablets use ARM64. Older 32-bit devices may need ARM32; choose the universal build when the architecture is unknown. Universal packages cover more architectures but are usually larger, while x86_64 is mainly for some emulators and specialized devices.
What is the difference between a graphical client and the Mihomo core?
A graphical client provides interfaces for importing subscriptions, choosing policies, configuring the system proxy and TUN, viewing logs, and updating. Mihomo executes proxy protocols, DNS, and rule evaluation. Most desktop and mobile users should choose a graphical client; servers, routers, and users managing their own processes should deploy the core directly and maintain its YAML configuration and service.
Why can’t I access sites through the proxy after importing a subscription?
Importing a subscription only means the client received the configuration; it does not mean traffic is using the proxy. Confirm in order that the profile is selected, the policy group has a current choice, and the system proxy or TUN is enabled as needed. Then check whether the target app uses the system proxy. Terminal programs, package managers, and developer tools may require separate proxy environment variables.