This article is the first run of Shadowrocket. It assumes the official app is already on your Home Screen from the App Store. If it is not, verify the developer and app ID on the download page first. Have your materials ready: a subscription URL from your provider, a QR code, or a set of fields that name the protocol. Without that, the app stays on Not Connected. This site does not provide subscriptions.
On first launch, iOS asks to add a VPN configuration. Tap Allow, then confirm with Face ID, Touch ID, or a passcode. iOS is protecting a system slot. This is not an app login, and there is no account to fill in. After you allow it, Settings → General → VPN & Device Management (the label can vary by iOS version) should list Shadowrocket. Seeing that row only means the app may build a tunnel. It does not mean you are connected. Home should still say Not Connected. If you tapped Don't Allow, background the app and open it again—iOS usually asks once more. If it still does not, delete the leftover VPN in Settings, then open the app again.
Do not flip the toggle yet. Learn Home first. The title bar has scan on the left and plus on the right. The first row is Not Connected and the toggle—it only controls the tunnel. The second row is Global Routing, usually followed by Config. The third row is Connectivity Test; you can skip it the first time. Below that is SERVER. With no configuration it only shows Add Server. You can ignore the other three tabs until you are connected.
Tap plus in the top right, or tap Add Server. The first field is Type. Change Type before you fill the rest. If your provider gave a long URL that starts with http or https, set Type to Subscribe and paste the whole URL. Do not split it into Host. If they gave a QR code, scan it, then check Type and Host before you save. If they gave a set of fields, set Type to the protocol they named. Host, port, password or UUID, and the cipher must match. Leave Plugin on none unless they asked for one.
After you save, Home should list one or more rows under SERVER. Select one; a dot appears on the left. If you still see only Add Server, the save failed, Type is wrong, or the subscription is dead. Do not flip the toggle, and do not run a test yet. Once the list is there, tap the second row and confirm Global Routing is Config. That is everyday rule-based routing. Skip Proxy and Direct for now.
Confirm a server is selected, then flip the first-row toggle. A VPN icon only means the local tunnel is up. Open Safari and visit a site you already use. When that page loads, you are connected. Do not treat Connectivity Test as the answer: a healthy test with a blank page still needs a comparison; a very high number or a timeout means try another server, then Safari again.
If the site will not load, do not reinstall. Set Global Routing to Direct and open the same site. If Direct also fails, the phone Wi-Fi or cellular is the problem—turn the toggle off and check the network. If Direct works, the phone network is fine. The problem is the server or subscription: select another server, or ask your provider to refresh the subscription. After the comparison, switch back to Config.
Keep Config for everyday use. To change servers, tap another row in the list. When you are done, turn the toggle off. With On Demand off, it will not connect by itself. Servers in a subscription can expire or slow down—update that subscription row. Do not reinstall the client. Day to day, Home is the only tab you need.
The three first-run stalls, in this order: iOS never asks for VPN—delete the leftover profile in Settings, open the app again, and confirm the install is official. SERVER is empty—check that Subscribe was not pasted into Host, and that the subscription still works. The toggle is on but sites fail—run the Direct comparison, then decide whether to check the network or change servers. Those three steps clear most "did I break the install" doubts.
Two easy misses when you add a configuration. Remark is only a display name. Call it whatever you recognize; it is not used to connect. If a scan or save produces many rows, pick one that does not look extreme. You do not need to test every server. After a subscription update, old names can vanish or change. That is the provider, not the app eating your config. Before you delete a row, know whether it is a hand-entered server or a member of a subscription. Delete a hand-entered row by mistake, and you must ask your provider for the fields again.
Make browser confirmation a habit. In Safari, open a stable site you already use—not an address you just heard about. Then you can tell "that site is down" from "my tunnel is wrong." In-app previews and third-party browsers sometimes take another network path and add noise the first time. After Safari works, use other apps as you normally would.
If your provider gave both a subscription and a QR code, use one path first. Do not add both and then flip the toggle. Get a selectable row in the list, confirm Safari loads, then decide whether you need the other path. One kind of material at a time tells you whether the URL is dead or the code is incomplete. Same rule as comparing modes: change one thing. If both fail, ask whether the materials are still valid before you assume you pasted into the wrong field.
After the first successful run, leave Settings alone. You can switch the language; that only changes menus. Leave the test method on the default. Scripts, decryption, and On Demand can wait until you need them. Most first failures are not a missing advanced option. They are a missing working configuration, or a toggle flipped too early. Touch fewer options. Get the order right. Success goes up.
Get Started writes the same order as steps you can follow while you work. Fields and the comparison table live in the tutorial. This article only asks you to finish the first run. Done looks specific: the VPN is in Settings, SERVER lists a selected server, the toggle is on, and that site opens in Safari. When all four are true, stop. If you still lack the official client, finish the download-page checks, then come back here.