Setup guide
Clash Verge: add an HTTP or SOCKS5 proxy
Clash Verge Rev is a free, open-source (GPL-3.0) desktop client for Windows, macOS and Linux, built on the Mihomo core, also known as Clash.Meta. It does not sell or include proxies. You give it nodes and rules, and for every connection it decides which node carries it, if any. This guide adds your own ProxyPanda proxy as a node and sends only the sites you list through it. Labels follow Clash Verge Rev 2.5.8, and the configuration was run on Mihomo 1.19.32.
Before you start
- Clash Verge Rev installed on Windows, macOS or Linux.
- HOST, PORT, USERNAME and PASSWORD from the service page.
- The domains that should go through the proxy. Everything else will stay direct.
Your connection details
Sign in to the dashboard and open the service you bought. Its page shows the host, port, username and password for that service. There is no single ProxyPanda address to remember, so copy them from there each time. The code in these guides uses the placeholders below; replace each one with your own value.
- HOST
- The proxy address for this service, exactly as the service page shows it.
- PORT
- The port to connect to. Copy it with the host, since it can differ from one service to the next.
- USERNAME
- Your proxy login. It is separate from the email you use for the dashboard.
- PASSWORD
- Copy it in full. On residential, the options you choose in the dashboard are added to the end of the password, so a password typed from memory loses them.
You can skip the username and password by adding the IP address you connect from to the service’s allowlist. Then only HOST and PORT go into your code.
Need help? Letting the proxy recognise your IP address
The examples use HTTP, which reaches https sites through an encrypted tunnel. SOCKS5 works too: residential ports accept both, and ISP and datacenter proxies switch protocol in the dashboard.
Steps
Install it from the project’s releases page
Download Clash Verge Rev from the Releases page of the clash-verge-rev repository on GitHub, which its documentation names as the only place it is published, and pick the build for your system and processor. It is a client and nothing more: it comes with no proxies, and everything below uses the one you bought.
Create a local profile
Open the Profiles page, click New, set Type to Local, give it a name and Save without choosing a file. Clash Verge writes a template profile. Right-click its card and choose Edit File. The file holds three empty lists, proxies: [], proxy-groups: [] and rules: [], and the next three steps replace each one with the block shown.
Add your proxy as a node
Each entry under proxies is one node. Copy HOST, PORT, USERNAME and PASSWORD from the service page. A residential port answers both protocols, so both nodes work there; on ISP and datacenter the dashboard sets one, so keep only the node whose type matches it. The names are yours to choose, and groups and rules refer to them. Edit Proxies, in the same menu, also takes a node as a URI such as socks5://USERNAME:PASSWORD@HOST:PORT; in that form, URL-encode any special characters in the login.
proxies proxies: - name: pool-http type: http server: HOST port: PORT username: USERNAME password: PASSWORD - name: pool-socks type: socks5 server: HOST port: PORT username: USERNAME password: PASSWORDPut the nodes in a group
A select group lets you switch nodes on the Proxies page without touching the file. Rules point at the group, so changing node never means rewriting rules.
proxy-groups proxy-groups: - name: PROXY type: select proxies: [pool-http, pool-socks]Write the rules
Rules are read from the top, and the first one that matches decides. DOMAIN matches one exact name. DOMAIN-SUFFIX matches a domain and every subdomain under it; put the site you need in place of the second rule’s domain. The IP-CIDR line keeps your home network direct, and no-resolve stops the core looking up names just to test it. MATCH,DIRECT comes last: anything you did not list goes direct and never touches the proxy.
rules rules: - DOMAIN,api.ipify.org,PROXY - DOMAIN-SUFFIX,example.com,PROXY - IP-CIDR,192.168.0.0/16,DIRECT,no-resolve - MATCH,DIRECTUse the profile in Rule mode
Save the file. If Clash Verge reports that validation failed, the core refused the file and kept the old one, so check the indentation first. Right-click the card and choose Select. On the Proxies page, set the mode to Rule. Global would send everything through the chosen node, and Direct would send nothing. Then click pool-http or pool-socks in the PROXY group.
Check where traffic goes
Programs that read the system proxy follow Clash Verge once System Proxy is switched on in Settings. Command-line tools often do not, so point them at the Mixed Port under Settings › Clash Setting › Port Config, written MIXED_PORT below. The first command should print the proxy’s address and the second your own, because only api.ipify.org is listed. The Connections page shows the rule each connection matched and the group and node it went through.
terminal curl -x 127.0.0.1:MIXED_PORT https://api.ipify.org curl -x 127.0.0.1:MIXED_PORT https://httpbin.org/ip
Rotating and sticky IPs
Clash Verge opens a separate connection to the node for every connection a program makes, and each one signs in on its own. On residential with Randomize IP, one page can therefore arrive from several addresses. Use Sticky IP for anything that signs in.
Each node carries its own login, so two nodes on the same residential port can hold different passwords, one copied with Sticky IP and one with Randomize IP. A rule can also name a node instead of the group: send the site you sign in to to the sticky node and the rest of your list to the random one. Browser extensions that keep one login per host and port cannot do this.
An ISP or datacenter IP keeps its address for the rental term. Every program and site your rules send to that node shares it, so give jobs that must not be linked an IP each.
Common errors and fixes
Logs show “rejected username/password”
A SOCKS5 node’s login was refused. Copy USERNAME and PASSWORD from the service page again; on residential, the session options sit at the end of the password and are easy to lose. For a node added as a URI in Edit Proxies, check that special characters are URL-encoded.
Logs show “can not connect remote err code” and a number
The proxy behind an HTTP node turned the request down, and the number is the status it sent back. 407, Proxy Authentication Required, means the login was not accepted; fix it as above. Clash Verge accepts the program’s connection before it reaches the node, so the program never sees a login prompt: an https site fails with a dropped or reset connection, and a plain http page returns 502.
The Connections page shows Match and DIRECT for a site you listed
The site’s connections did not meet your rule. Check the spelling of the domain, that the rule sits above MATCH, that the mode is Rule, and that the profile you edited is the selected one. An IP-CIDR rule without no-resolve above your domain rules can also claim the site first.
A program ignores the proxy entirely
It does not read the system proxy, so nothing reaches Clash Verge and no rule can catch it. Give the program 127.0.0.1 and the Mixed Port in its own proxy setting or environment variables. TUN mode captures programs without their cooperation, but needs the core allowed through the firewall and Clash Verge running in service mode or as administrator.
One node works and the other never connects
On ISP and datacenter the dashboard sets a single protocol. A socks5 node pointed at a proxy set to HTTP, or the reverse, cannot connect. Delete the node that does not match, or switch the protocol in the dashboard.
Need help? What a 407 or 403 message means
Which line to pick
For a bot or script that signs in to one account every day, point its node at an ISP IP. Residential with Sticky IP covers targets that turn away server addresses, and your rules keep those gigabytes to the domains you list. Datacenter is the cheapest node for tools and checks that accept any address.
Other setup guides
Not sure what a word means? The glossary explains it in plain English.
Stuck on a step?
Paste the command and the error into Discord, with your password taken out. People there have met most of these errors before.