Profile: the configuration source
FlClash can add Profiles from a URL, local file or QR code. Remote Profiles are convenient for updates, while local files are better when you maintain the Mihomo configuration yourself.
FlClash Guide · Profile / Override / Proxy / VPN / TUN
Start with the first launch, add a Profile from a URL, file or QR code, choose a proxy group and Rule / Global / Direct mode, then enable the network entry method for your platform. Use Override / Override Script for persistent local changes, and check DNS, Connections and Logs when validating the final setup.
Core concepts
FlClash is the client, Profile and platform-integration layer; Mihomo Core executes proxy groups, Rules, DNS and TUN. The Profile supplies the base configuration, Override keeps local changes separate, and System Proxy, Android VPN or TUN determines how traffic enters the Core.
FlClash can add Profiles from a URL, local file or QR code. Remote Profiles are convenient for updates, while local files are better when you maintain the Mihomo configuration yourself.
Proxy nodes, groups, Rules, DNS, Providers and TUN are ultimately executed by Mihomo Core. The UI manages these settings, but troubleshooting should focus on the effective runtime config.
Standard Override changes base settings and supports added Rules. Override Script uses an external extension script for more flexible transformations without repeatedly editing a remote Profile.
Desktop can use System Proxy or TUN, while Android primarily uses the operating system VpnService. These paths only determine how traffic reaches Mihomo; Rules and proxy groups still decide where it goes.
First setup
The configuration model is shared across Android and desktop, but the final traffic-entry method is platform-specific: desktop can use System Proxy or TUN, while Android uses the system VPN interface.
Choose the Android, Windows, macOS or Linux package that matches your device and CPU architecture, then confirm the client and Mihomo Core start normally.
Open Profiles and import from URL, file or QR code. For remote Profiles, configure auto update if needed and confirm the intended Profile actually loads.
Open Proxies, inspect the available groups and members, and select the policy required by the active configuration. Automated groups continue to follow their Mihomo group type.
Use Rule for normal policy-based routing. Global is useful for testing a single proxy policy, while Direct helps isolate whether a problem comes from the proxy path or configuration rules.
Use System Proxy on desktop for proxy-aware apps, Android VPN on mobile, or desktop TUN when broader traffic capture is required. Confirm permissions, DNS and routing after enabling it.
A Profile defines the base configuration source. Override is where FlClash keeps persistent local changes. Multi-Profile Merge should not be treated as the core setup model for current FlClash.
Add a Profile from a URL or QR code when the configuration should refresh from a maintained source. Changes to proxies, groups and Rules depend on what that source returns.
Remote updatesImport a local file when you want to maintain Mihomo fields yourself, including proxy groups, Rules, DNS, Providers and other advanced options.
Local controlUse standard Override for structured settings and added Rules. Use Script mode when an external extension script is needed for more flexible transformations.
Persistent local changesOutbound modes
Outbound mode controls how Mihomo chooses the route after traffic reaches the Core. System Proxy, Android VPN and TUN are separate network-entry mechanisms and do not replace correct Rules or proxy-group selection.
| Mode | Best for | Notes |
|---|---|---|
| Rule | Normal daily routing | Mihomo evaluates the active Rules in order and sends each connection to the matching proxy group, DIRECT, REJECT or another configured action. |
| Global | Testing one global policy | Traffic is handed to the selected global policy, which helps test the proxy path without depending on the normal rule set. |
| Direct | Isolating proxy effects | Traffic bypasses proxy routing as much as possible, helping determine whether a problem comes from the proxy node, Rules, DNS or the network-entry layer. |
Use the platform-native path first: desktop apps that follow OS proxy settings usually work with System Proxy, Android uses VpnService, and desktop TUN is most useful when broader traffic capture is required.
System Proxy points the desktop operating system proxy settings at Mihomo's local listener. Browsers and many conventional desktop apps can use this path without virtual-network routing.
Android uses VpnService to send device traffic into FlClash / Mihomo. App Access Control can decide which applications enter the VPN or which selected apps are excluded.
Configuration FAQ
These answers focus on the configuration workflow. Use the download page for package selection and the FAQ page for deeper port, DNS, Core and runtime troubleshooting.
No. A Profile is a configuration source managed by FlClash. It can be added from a URL, file or QR code; a subscription URL is simply one common source for a remote Profile.
Use a remote Profile when configuration should refresh from a maintained source. Use a local file when you want to maintain Mihomo fields yourself. Either source can still receive local Override changes.
Refreshing replaces the remote source content. Put persistent local changes in Override, added Rules or Override Script instead of repeatedly editing content that will be downloaded again.
Standard Override changes structured settings and supports simple added Rules. Script mode runs an external extension script for more flexible configuration transformations. The final Mihomo config is the result that matters.
Do not treat multi-Profile Merge as a stable core workflow. Current FlClash setup should be described around one Profile plus Override, Override Script and added Rules for persistent local customization.
Some applications ignore operating system proxy settings or use their own network stack. Check app-specific proxy settings first, then use TUN if broader traffic capture is truly required.
FlClash primarily uses Android VpnService to route device traffic into Mihomo. Android and desktop platforms expose different network APIs, so their controls and permission prompts are not identical.
No. TUN captures more desktop traffic but adds virtual-interface, routing, DNS and permission complexity. System Proxy is usually simpler when the target apps already follow OS proxy settings.
Check DNS when domains fail to resolve, Fake-IP behaves unexpectedly, proxy node hostnames fail, or DNS results and Rules appear inconsistent. Useful FlClash options include Override DNS, nameserver roles and respect rules.
Use Connections, Requests, Logs, Traffic Usage and Network Speed. If there are no connection records, check System Proxy, Android VPN or TUN first; if traffic is visible, continue with Rules, proxy groups and node state.
Next step
Use the download page for Android, Windows, macOS and Linux packages. After installation, follow this workflow to add a Profile, choose a proxy group and mode, then enable System Proxy, Android VPN or TUN.