Guide · 7 min read

Clash Verge proxy setup: your own proxy as a node, and rules that decide what uses it

Add your own HTTP or SOCKS5 proxy to Clash Verge Rev as a node, group it, write rules so only chosen sites use it, check the route and spot a failed login.

Clash Verge Rev is an open-source (GPL-3.0) desktop app for Windows, macOS and Linux, built on the Mihomo core, the project once called Clash.Meta. It routes; it does not sell. You give it proxies, which it calls nodes, plus rules, and for every connection it decides whether a node carries it or it goes out over your own line. It comes with no proxies of its own. This guide adds the HTTP or SOCKS5 proxy you already bought as a node, puts it in a group, and writes rules so only the sites you name use it. Everything else leaves from your own connection and never touches the meter.

We ran every config on this page through the Mihomo core, v1.19.32, with a proxy we started ourselves on the same machine standing in for ours. We did not click through the app itself: button names come from Clash Verge Rev’s English interface text and its documentation, so if a label has moved in your version, the app wins.

How to add your own proxy to Clash Verge

Short answer: write a small profile file with your proxy under proxies, a select group under proxy-groups, and rules that end in MATCH,DIRECT. Load it from Profiles → New with Type set to Local, select it, and switch to Rule mode. Would rather click than type? Right-click a profile, Edit Proxies, and paste http://USER:PASS@HOST:PORT. The long version:

Step 1: write the profile

Save this as a file, say monkey.yaml:

proxies:
  - name: monkey-http
    type: http
    server: gate.example.com
    port: 8000
    username: USER
    password: PASS
  - name: monkey-socks
    type: socks5
    server: gate.example.com
    port: 1080
    username: USER
    password: PASS
proxy-groups:
  - name: PROXY
    type: select
    proxies: [monkey-http, monkey-socks]
rules:
  - DOMAIN-SUFFIX,target-site.com,PROXY
  - DOMAIN,httpbin.org,PROXY
  - MATCH,DIRECT
  • proxies holds two nodes, one per protocol, with the same login. Swap gate.example.com, both ports, USER and PASS for the host, ports and credentials in your dashboard. The ports here are placeholders; use the ones your dashboard lists for HTTP and SOCKS5 rather than guessing. Only use one protocol? Delete the other node and its name from the group.
  • Passwords with odd characters go in double quotes, because YAML reads a #, a : followed by a space, or a leading @ as syntax. password: "p@ss:w#rd" logged in fine on both node types in our test.
  • proxy-groups wraps the nodes in a group called PROXY. A select group uses whichever node you click on the Proxies page, and does nothing behind your back. More on why that matters on a per-GB line in the bandwidth post.
  • rules are read top to bottom and the first match wins. DOMAIN-SUFFIX,target-site.com covers the domain and every subdomain under it (www. and deeper, in our run) but not lookalikes such as not-target-site.com. DOMAIN matches one exact name; the httpbin.org line is only there for the check below. MATCH,DIRECT sends everything no rule named straight out over your own connection.
  • No ports and no mode in the file. Clash Verge manages the local port, the mode and a few other fields from its Settings, and in its own words those fields “always use those settings in the final config”.

Step 2: load it into Clash Verge

  1. Open Profiles and click New. In Create Profile, set Type to Local, give it a name, click Choose File, pick monkey.yaml and save. Dragging the file into the app works too, from v1.6.2 on.
  2. Right-click the new profile and choose Select to make it the active one.

Clash Verge copies the file into its own profiles folder, so editing your original later changes nothing. Edit its copy instead: right-click the profile, Edit File. Save a typo there and Clash Verge throws the edit out with “YAML syntax error, changes reverted”.

Or click it together: Edit Proxies, Edit Proxy Groups, Edit Rules

Clash Verge can build the same thing without a file. It works best on an empty profile: New, Local, and save without choosing a file, which the docs say creates a blank one. Then right-click that profile:

  1. Edit Proxies. Paste one URI per line and click Prepend Proxy:
    http://USER:PASS@HOST:PORT
    socks5://USER:PASS@HOST:PORT
    Here, unlike in the YAML file, special characters in the username or password must be URL-encoded: @ becomes %40, : becomes %3A, # becomes %23.
  2. Edit Proxy Groups. Set Group Type to select (“Select proxy manually”), give it a Group Name, tick your nodes under Use Proxies, and click Prepend Group.
  3. Edit Rules. For each site: Rule Type DOMAIN-SUFFIX, Rule Content the domain, Proxy Policy your group, then Prepend Rule. Finish with one rule of type MATCH and policy DIRECT, added with Append Rule.

The docs say prepended rules outrank the profile’s own and survive profile updates. That is also the catch on a profile that is not empty: an appended MATCH,DIRECT only applies after the profile’s own rules, so if those already end in a catch-all of their own, yours never fires. Read the last rule on the Rules page before you trust it.

Step 3: Rule mode, and pick the node

Clash Verge has three modes, on the Proxies page and on the Home page’s Proxy Mode card. Rule reads your rules. Global, in the app’s words, forwards “all network requests through the selected proxy”. Direct uses no proxy at all. Choose Rule. Then, in the PROXY group on the Proxies page, click the node you want it to use.

Step 4: send traffic to Clash

Rules only sort what reaches Clash, and there are three ways in:

  • Settings → System Proxy. Apps that follow the operating system’s proxy setting, which includes most browsers, now go through Clash. Apps are free to ignore it.
  • One app only. Point it at 127.0.0.1 and the Mixed Port, which you will find under Settings → Port Config. That one port speaks both HTTP and SOCKS5, so either proxy type works in the app’s settings.
  • Tun Mode, for apps that ignore proxy settings altogether. It needs the Clash Verge service or administrator rights before it will switch on. Our guide to forcing any app through a proxy covers that problem and the other tools for it.

Check the route

Replace MIXED_PORT with your Mixed Port and run both:

curl -x http://127.0.0.1:MIXED_PORT https://httpbin.org/ip
curl -x http://127.0.0.1:MIXED_PORT https://api.ipify.org

The first should print the proxy’s IP, because httpbin.org has a rule. The second should print your own, because api.ipify.org has none and falls through to MATCH,DIRECT. Same port, two different exits: that is the rules working. The Logs page shows why. These two lines are from our run:

[TCP] 127.0.0.1:49598 --> httpbin.org:443 match Domain(httpbin.org) using PROXY[monkey-http]
[TCP] 127.0.0.1:49614 --> api.ipify.org:443 match Match using DIRECT

PROXY[monkey-http] is the group and the node inside it. If the Logs page stays quiet, set Log Level to info in Settings. The Connections page tells the same story per connection, with Host, Rule and Chains columns. On our side, your usage log should now show httpbin.org and nothing for api.ipify.org. Once you are satisfied, delete the httpbin.org rule, or keep it for next time.

What a wrong username or password looks like

Clash does not pop up an error. The listed sites just stop loading while everything else carries on, because unlisted traffic never touches the node. The Logs page has the reason. From our run with a wrong password, first on the HTTP node, then on the SOCKS5 one:

[TCP] dial PROXY (match Domain/httpbin.org) 127.0.0.1:37500 --> httpbin.org:443 error: can not connect remote err code: 403
[TCP] dial PROXY (match Domain/httpbin.org) 127.0.0.1:37892 --> httpbin.org:443 error: rejected username/password
  • The HTTP node reports whatever status the proxy sent back. Our stand-in answered 403; a proxy provider normally answers 407 Proxy Authentication Required. Either way, the proxy turned the login down.
  • The SOCKS5 node says it outright: rejected username/password.
  • Clash retries before giving up. One request gave us ten of those lines in about two seconds.
  • The app sees something vaguer. A plain-HTTP request gets 502 Bad Gateway from Clash. An HTTPS one has already been told the tunnel is open, so the connection simply drops: curl says SSL_ERROR_SYSCALL, a browser shows a connection error.
  • A wrong host or port looks different again: connect: connection refused, or i/o timeout when nothing answers at all; see connection timeouts.

To rule Clash out, try the proxy on its own. If this gets a 407, retype the credentials, mind the quotes in YAML and the URL-encoding in a URI, and try again:

curl -x http://USER:PASS@HOST:PORT https://httpbin.org/ip

Which proxy to use as the node

Scraping traffic you route through Clash suits our residential line: a new home address per request, billed by the gigabyte, with no country pinning. That billing is why the MATCH,DIRECT line matters; the bandwidth post covers the settings that quietly put your whole machine on the meter instead. A browser session you log in to wants an address that stays put: a static ISP proxy in the country you pick at checkout, or datacenter where the site does not mind hosting ranges.

All three lines speak HTTP and SOCKS5. Treat our SOCKS5 as TCP only: UDP relay is not verified on our gateways, so do not add udp: true to the node expecting it to work. When we sent UDP at an HTTP node in our test, Clash refused it with no support. Stuck? Bring the log lines, credentials blurred, to Discord.

Try it while you read

Top-ups start at $5.

One shared datacenter IP for 30 days is $1.25. A single gigabyte of residential is $5.50. The balance never expires.

Published

Filed under

Found a mistake? Tell us in Discord and we will fix the post.

The community layer

Stuck halfway through?

Paste the error in Discord. Someone has hit it before and the answer is usually one message long.

Join the Discord

4,200+monkeys in the Discord

  • Help from humans

    Post your error, get an answer. Usually in minutes, usually from someone who has hit the same wall.

  • A status bot that tells on us

    Pool health, incidents and maintenance posted automatically. Including the bad days.

  • Deals and free traffic

    Bonus GB drops, early access to new pools, and the occasional giveaway for a good bug report.

Join the Discord4,200+ monkeys, free to lurk