Clash Verge Rev is an open-source (GPL-3.0) desktop app for Windows, macOS and Linux, built on the Mihomo core, the project once called Clash.Meta. It routes; it does not sell. You give it proxies, which it calls nodes, plus rules, and for every connection it decides whether a node carries it or it goes out over your own line. It comes with no proxies of its own. This guide adds the HTTP or SOCKS5 proxy you already bought as a node, puts it in a group, and writes rules so only the sites you name use it. Everything else leaves from your own connection and never touches the meter.
We ran every config on this page through the Mihomo core, v1.19.32, with a proxy we started ourselves on the same machine standing in for ours. We did not click through the app itself: button names come from Clash Verge Rev’s English interface text and its documentation, so if a label has moved in your version, the app wins.
How to add your own proxy to Clash Verge
Short answer: write a small profile file with your proxy under proxies, a select group under proxy-groups, and rules that end in MATCH,DIRECT. Load it from Profiles → New with Type set to Local, select it, and switch to Rule mode. Would rather click than type? Right-click a profile, Edit Proxies, and paste http://USER:PASS@HOST:PORT. The long version:
Step 1: write the profile
Save this as a file, say monkey.yaml:
proxies:
- name: monkey-http
type: http
server: gate.example.com
port: 8000
username: USER
password: PASS
- name: monkey-socks
type: socks5
server: gate.example.com
port: 1080
username: USER
password: PASS
proxy-groups:
- name: PROXY
type: select
proxies: [monkey-http, monkey-socks]
rules:
- DOMAIN-SUFFIX,target-site.com,PROXY
- DOMAIN,httpbin.org,PROXY
- MATCH,DIRECTproxiesholds two nodes, one per protocol, with the same login. Swapgate.example.com, both ports,USERandPASSfor the host, ports and credentials in your dashboard. The ports here are placeholders; use the ones your dashboard lists for HTTP and SOCKS5 rather than guessing. Only use one protocol? Delete the other node and its name from the group.- Passwords with odd characters go in double quotes, because YAML reads a
#, a:followed by a space, or a leading@as syntax.password: "p@ss:w#rd"logged in fine on both node types in our test. proxy-groupswraps the nodes in a group calledPROXY. Aselectgroup uses whichever node you click on the Proxies page, and does nothing behind your back. More on why that matters on a per-GB line in the bandwidth post.rulesare read top to bottom and the first match wins.DOMAIN-SUFFIX,target-site.comcovers the domain and every subdomain under it (www.and deeper, in our run) but not lookalikes such asnot-target-site.com.DOMAINmatches one exact name; thehttpbin.orgline is only there for the check below.MATCH,DIRECTsends everything no rule named straight out over your own connection.- No ports and no mode in the file. Clash Verge manages the local port, the mode and a few other fields from its Settings, and in its own words those fields “always use those settings in the final config”.
Step 2: load it into Clash Verge
- Open Profiles and click New. In Create Profile, set Type to Local, give it a name, click Choose File, pick
monkey.yamland save. Dragging the file into the app works too, from v1.6.2 on. - Right-click the new profile and choose Select to make it the active one.
Clash Verge copies the file into its own profiles folder, so editing your original later changes nothing. Edit its copy instead: right-click the profile, Edit File. Save a typo there and Clash Verge throws the edit out with “YAML syntax error, changes reverted”.
Or click it together: Edit Proxies, Edit Proxy Groups, Edit Rules
Clash Verge can build the same thing without a file. It works best on an empty profile: New, Local, and save without choosing a file, which the docs say creates a blank one. Then right-click that profile:
- Edit Proxies. Paste one URI per line and click Prepend Proxy:
Here, unlike in the YAML file, special characters in the username or password must be URL-encoded:http://USER:PASS@HOST:PORT socks5://USER:PASS@HOST:PORT@becomes%40,:becomes%3A,#becomes%23. - Edit Proxy Groups. Set Group Type to
select(“Select proxy manually”), give it a Group Name, tick your nodes under Use Proxies, and click Prepend Group. - Edit Rules. For each site: Rule Type
DOMAIN-SUFFIX, Rule Content the domain, Proxy Policy your group, then Prepend Rule. Finish with one rule of typeMATCHand policyDIRECT, added with Append Rule.
The docs say prepended rules outrank the profile’s own and survive profile updates. That is also the catch on a profile that is not empty: an appended MATCH,DIRECT only applies after the profile’s own rules, so if those already end in a catch-all of their own, yours never fires. Read the last rule on the Rules page before you trust it.
Step 3: Rule mode, and pick the node
Clash Verge has three modes, on the Proxies page and on the Home page’s Proxy Mode card. Rule reads your rules. Global, in the app’s words, forwards “all network requests through the selected proxy”. Direct uses no proxy at all. Choose Rule. Then, in the PROXY group on the Proxies page, click the node you want it to use.
Step 4: send traffic to Clash
Rules only sort what reaches Clash, and there are three ways in:
- Settings → System Proxy. Apps that follow the operating system’s proxy setting, which includes most browsers, now go through Clash. Apps are free to ignore it.
- One app only. Point it at
127.0.0.1and the Mixed Port, which you will find under Settings → Port Config. That one port speaks both HTTP and SOCKS5, so either proxy type works in the app’s settings. - Tun Mode, for apps that ignore proxy settings altogether. It needs the Clash Verge service or administrator rights before it will switch on. Our guide to forcing any app through a proxy covers that problem and the other tools for it.
Check the route
Replace MIXED_PORT with your Mixed Port and run both:
curl -x http://127.0.0.1:MIXED_PORT https://httpbin.org/ip
curl -x http://127.0.0.1:MIXED_PORT https://api.ipify.orgThe first should print the proxy’s IP, because httpbin.org has a rule. The second should print your own, because api.ipify.org has none and falls through to MATCH,DIRECT. Same port, two different exits: that is the rules working. The Logs page shows why. These two lines are from our run:
[TCP] 127.0.0.1:49598 --> httpbin.org:443 match Domain(httpbin.org) using PROXY[monkey-http]
[TCP] 127.0.0.1:49614 --> api.ipify.org:443 match Match using DIRECTPROXY[monkey-http] is the group and the node inside it. If the Logs page stays quiet, set Log Level to info in Settings. The Connections page tells the same story per connection, with Host, Rule and Chains columns. On our side, your usage log should now show httpbin.org and nothing for api.ipify.org. Once you are satisfied, delete the httpbin.org rule, or keep it for next time.
What a wrong username or password looks like
Clash does not pop up an error. The listed sites just stop loading while everything else carries on, because unlisted traffic never touches the node. The Logs page has the reason. From our run with a wrong password, first on the HTTP node, then on the SOCKS5 one:
[TCP] dial PROXY (match Domain/httpbin.org) 127.0.0.1:37500 --> httpbin.org:443 error: can not connect remote err code: 403
[TCP] dial PROXY (match Domain/httpbin.org) 127.0.0.1:37892 --> httpbin.org:443 error: rejected username/password- The HTTP node reports whatever status the proxy sent back. Our stand-in answered
403; a proxy provider normally answers 407 Proxy Authentication Required. Either way, the proxy turned the login down. - The SOCKS5 node says it outright:
rejected username/password. - Clash retries before giving up. One request gave us ten of those lines in about two seconds.
- The app sees something vaguer. A plain-HTTP request gets
502 Bad Gatewayfrom Clash. An HTTPS one has already been told the tunnel is open, so the connection simply drops: curl saysSSL_ERROR_SYSCALL, a browser shows a connection error. - A wrong host or port looks different again:
connect: connection refused, ori/o timeoutwhen nothing answers at all; see connection timeouts.
To rule Clash out, try the proxy on its own. If this gets a 407, retype the credentials, mind the quotes in YAML and the URL-encoding in a URI, and try again:
curl -x http://USER:PASS@HOST:PORT https://httpbin.org/ipWhich proxy to use as the node
Scraping traffic you route through Clash suits our residential line: a new home address per request, billed by the gigabyte, with no country pinning. That billing is why the MATCH,DIRECT line matters; the bandwidth post covers the settings that quietly put your whole machine on the meter instead. A browser session you log in to wants an address that stays put: a static ISP proxy in the country you pick at checkout, or datacenter where the site does not mind hosting ranges.
All three lines speak HTTP and SOCKS5. Treat our SOCKS5 as TCP only: UDP relay is not verified on our gateways, so do not add udp: true to the node expecting it to work. When we sent UDP at an HTTP node in our test, Clash refused it with no support. Stuck? Bring the log lines, credentials blurred, to Discord.
Top-ups start at $5.
One shared datacenter IP for 30 days is $1.25. A single gigabyte of residential is $5.50. The balance never expires.