Clash Verge vs SwitchyOmega: a browser extension or a system-level router?
Clash Verge vs SwitchyOmega: when a browser extension is enough for your proxy, when bots and command-line tools need a system-level router, and what to check.
If only your browser needs the proxy, SwitchyOmega is enough. Its maintained fork, SwitchyOmega 3, sends the sites you list through the proxy, switches from the toolbar and installs nothing outside the browser. If anything else has to use the proxy, such as a bot, a script, a command-line tool or a desktop program, you need something that sits below the browser, and Clash Verge Rev is one such tool. Neither one supplies proxies. Both take the HTTP or SOCKS5 proxy you already bought and decide which traffic goes through it.
This post compares the two for that one job: your own proxy, with rules deciding what uses it. For the Clash Verge side we ran its core, Mihomo 1.19.32, against a local test proxy that asks for a login, and the log lines below come from those runs. The SwitchyOmega side comes from our SwitchyOmega guide.
Side by side
| SwitchyOmega 3 | Clash Verge Rev | |
|---|---|---|
| What it is | A browser extension for Chrome, Edge and Firefox | A desktop app for Windows, macOS and Linux, built on the Mihomo core |
| What it can route | That browser's requests | Programs that use the system proxy or are pointed at its local port; in TUN mode, the whole machine |
| Rules match on | Host and URL patterns | Domain, domain suffix, keyword, IP range, port, process name and more |
| Where the proxy login lives | In the extension, one login per host and port | In each node, so several nodes can share one host and port |
| SOCKS5 with a login | Not in Chrome or Edge | Yes, for everything it routes |
| What it installs | Nothing outside the browser | A desktop app; TUN mode also needs a service or administrator rights, and a firewall rule |
| Comes with proxies | No | No |
When the extension is enough
- Only the browser needs the proxy. A few sites you sign in to, a dashboard, research in a handful of tabs. Nothing else on the computer has to change.
- Per-site rules are all you need. A Switch Profile sends the hosts you list through the proxy and everything else direct, and the toolbar turns it off in one click.
- You cannot install a desktop program, or would rather not, on a work laptop or a shared computer.
The limits are the ones our SwitchyOmega guide covers. Chrome and Edge cannot send a SOCKS5 username and password at all, so use HTTP, or SOCKS5 with your IP on the allowlist. Chrome sometimes asks for the proxy password even though the extension holds it. Only one extension can control the browser's proxy at a time. And an extension that answers proxy logins sees everything you browse, which is why are proxy browser extensions safe? is worth five minutes before you install one.
When you need a system-level router
- Something other than a browser needs the proxy. A bot, a scraper, curl, a desktop app with no proxy field: none of them can see a browser extension.
- Several programs should follow one set of rules. Clash Verge applies the same rules to every connection that reaches it, whichever program opened it.
- You want SOCKS5 with a login. Programs talk to Clash Verge's local port without a login, and the node signs in to your proxy, over SOCKS5 as easily as HTTP.
- You want different logins on the same port. Each node keeps its own username and password. On residential, where the session choice travels in the password, a Sticky IP node and a Randomize IP node can share one port, and rules decide which sites use which. An extension that keeps one login per host and port cannot hold both.
- You want rules by program.
PROCESS-NAMEmatches the program that opened the connection.
We tried it on Linux with this pair of rules:
rules:
- PROCESS-NAME,curl,PROXY
- MATCH,DIRECT
Then we sent one request from curl and one from a Python script:
127.0.0.1:36486(curl, uid=1000) --> api.ipify.org:443 match ProcessName(curl) using PROXY[pool-http]
127.0.0.1:36500(python3.12, uid=1000) --> api.ipify.org:443 match Match using DIRECT
The name has to be the program's exact name. The script ran as python3.12, so a rule for python would not have caught it, and Clash Verge's own documentation writes Windows names with .exe. Finding the process relies on what the operating system provides, so do not assume a rule that works on one system behaves the same on another. The Connections page has a Process column that shows what the core saw. The lookup can also miss: in 80 curl connections fired back to back, 12 failed it and fell through to MATCH,DIRECT. Treat a process rule as a convenience, and give the target a domain rule as well.
How programs reach Clash Verge matters as much as the rules. With System Proxy switched on, programs that read the system setting follow it, but that setting is a convention rather than a requirement. Many command-line tools ignore it, and it cannot carry UDP. Point those at the Mixed Port shown in Clash Verge's settings yourself:
curl -x 127.0.0.1:MIXED_PORT https://api.ipify.org
The other way in is TUN mode, which creates a virtual network adapter and takes TCP and UDP from every program, whether it cooperates or not. TUN needs the core allowed through your firewall, and Clash Verge running in service mode or as administrator.
What going system-level costs
More to install, and more to get wrong. A mistake in an extension stays inside one browser. A mistake in Clash Verge can send programs you forgot about through the proxy, or keep the one you meant off it. End the rules with MATCH,DIRECT, so anything you did not list goes direct, and read the Connections page after every change: it lists each connection with the rule it matched and the node it used. To see what the traffic that did go through weighs on your meter, count your own bytes walks through measuring it.
Trust works the same way as for an extension. Clash Verge Rev is open source under GPL-3.0, publishes its releases only on GitHub, and says it collects no user data. It still sees every connection you send through it, so install it from the project's own releases page and keep it updated.
Check it yourself: an IP rule can take a domain off the proxy
Clash rules can match on IP ranges as well as names, and that is where a quiet mistake lives. When a connection arrives with a domain name and the core reaches an IP-CIDR rule, it looks the name up locally to test the rule, unless the rule ends in no-resolve. If the address falls inside the range, that rule wins, and the domain rule below it never runs.
We tested it with an IP-CIDR rule for a range that holds some of api.ipify.org's addresses, placed above a rule meant to send that name through the proxy:
rules:
- IP-CIDR,104.26.0.0/16,DIRECT
- DOMAIN,api.ipify.org,PROXY
- MATCH,DIRECT
Across ten runs of the same file, seven connections went direct, and the test proxy's log never showed them:
127.0.0.1:58434 --> api.ipify.org:443 match IPCIDR(104.26.0.0/16) using DIRECT
The other three used the proxy, because the lookup returned one of the name's addresses outside the range. A rule that misfires only some of the time is the hardest kind to notice. With ,no-resolve added to the IP-CIDR line, the core skipped it for connections that arrive by name, and six runs out of six matched the domain rule:
127.0.0.1:58442 --> api.ipify.org:443 match Domain(api.ipify.org) using PROXY[pool-http]
There is a second difference. A connection that reaches the node by name is looked up by the proxy: our test proxy's log showed api.ipify.org:443, not an address. One that trips an IP rule without no-resolve has already been looked up on your side, by the core, before the proxy is involved at all.
Two habits avoid both problems: put domain rules above IP rules, and add no-resolve to IP rules meant for addresses you connect to directly, such as your home network. Then check rather than trust. Open the Connections page, or Clash Verge's Logs, and read which rule each connection matched.
Quick answers
Does Clash Verge come with proxies? No. It is a client that routes the proxies you give it. Ours work in it as HTTP or SOCKS5 nodes.
Can SwitchyOmega route my bot or script? No. It only sees requests from the browser it is installed in. Give the script the proxy in its own code, as our setup guides do, or route it through Clash Verge.
Is one safer than the other? Both see everything they route, and both are open source. Install either from the link its project publishes, and keep it updated.
Where ProxyPanda fits
Our proxies speak HTTP and SOCKS5. Residential ports answer both, and ISP and datacenter proxies switch protocol in the dashboard. In SwitchyOmega, use HTTP with a login, or SOCKS5 with your IP on the allowlist; the SwitchyOmega guide covers both. In Clash Verge, either protocol works with its login, and the Clash Verge guide adds your proxy as a node and writes the rules. If you are unsure which protocol your tool wants, HTTP vs SOCKS5 explains the difference.