Before you start

  • Clash Verge Rev installed on Windows, macOS or Linux.
  • HOST, PORT, USERNAME and PASSWORD from the service page.
  • The domains that should go through the proxy. Everything else will stay direct.

Your connection details

Sign in to the dashboard and open the service you bought. Its page shows the host, port, username and password for that service. There is no single ProxyPanda address to remember, so copy them from there each time. The code in these guides uses the placeholders below; replace each one with your own value.

HOST
The proxy address for this service, exactly as the service page shows it.
PORT
The port to connect to. Copy it with the host, since it can differ from one service to the next.
USERNAME
Your proxy login. It is separate from the email you use for the dashboard.
PASSWORD
Copy it in full. On residential, the options you choose in the dashboard are added to the end of the password, so a password typed from memory loses them.

You can skip the username and password by adding the IP address you connect from to the service’s allowlist. Then only HOST and PORT go into your code.

Need help? Letting the proxy recognise your IP address

The examples use HTTP, which reaches https sites through an encrypted tunnel. SOCKS5 works too: residential ports accept both, and ISP and datacenter proxies switch protocol in the dashboard.

Steps

  1. Install it from the project’s releases page

    Download Clash Verge Rev from the Releases page of the clash-verge-rev repository on GitHub, which its documentation names as the only place it is published, and pick the build for your system and processor. It is a client and nothing more: it comes with no proxies, and everything below uses the one you bought.

  2. Create a local profile

    Open the Profiles page, click New, set Type to Local, give it a name and Save without choosing a file. Clash Verge writes a template profile. Right-click its card and choose Edit File. The file holds three empty lists, proxies: [], proxy-groups: [] and rules: [], and the next three steps replace each one with the block shown.

  3. Add your proxy as a node

    Each entry under proxies is one node. Copy HOST, PORT, USERNAME and PASSWORD from the service page. A residential port answers both protocols, so both nodes work there; on ISP and datacenter the dashboard sets one, so keep only the node whose type matches it. The names are yours to choose, and groups and rules refer to them. Edit Proxies, in the same menu, also takes a node as a URI such as socks5://USERNAME:PASSWORD@HOST:PORT; in that form, URL-encode any special characters in the login.

    proxies
    proxies:
      - name: pool-http
        type: http
        server: HOST
        port: PORT
        username: USERNAME
        password: PASSWORD
      - name: pool-socks
        type: socks5
        server: HOST
        port: PORT
        username: USERNAME
        password: PASSWORD
  4. Put the nodes in a group

    A select group lets you switch nodes on the Proxies page without touching the file. Rules point at the group, so changing node never means rewriting rules.

    proxy-groups
    proxy-groups:
      - name: PROXY
        type: select
        proxies: [pool-http, pool-socks]
  5. Write the rules

    Rules are read from the top, and the first one that matches decides. DOMAIN matches one exact name. DOMAIN-SUFFIX matches a domain and every subdomain under it; put the site you need in place of the second rule’s domain. The IP-CIDR line keeps your home network direct, and no-resolve stops the core looking up names just to test it. MATCH,DIRECT comes last: anything you did not list goes direct and never touches the proxy.

    rules
    rules:
      - DOMAIN,api.ipify.org,PROXY
      - DOMAIN-SUFFIX,example.com,PROXY
      - IP-CIDR,192.168.0.0/16,DIRECT,no-resolve
      - MATCH,DIRECT
  6. Use the profile in Rule mode

    Save the file. If Clash Verge reports that validation failed, the core refused the file and kept the old one, so check the indentation first. Right-click the card and choose Select. On the Proxies page, set the mode to Rule. Global would send everything through the chosen node, and Direct would send nothing. Then click pool-http or pool-socks in the PROXY group.

  7. Check where traffic goes

    Programs that read the system proxy follow Clash Verge once System Proxy is switched on in Settings. Command-line tools often do not, so point them at the Mixed Port under Settings › Clash Setting › Port Config, written MIXED_PORT below. The first command should print the proxy’s address and the second your own, because only api.ipify.org is listed. The Connections page shows the rule each connection matched and the group and node it went through.

    terminal
    curl -x 127.0.0.1:MIXED_PORT https://api.ipify.org
    curl -x 127.0.0.1:MIXED_PORT https://httpbin.org/ip

Rotating and sticky IPs

Clash Verge opens a separate connection to the node for every connection a program makes, and each one signs in on its own. On residential with Randomize IP, one page can therefore arrive from several addresses. Use Sticky IP for anything that signs in.

Each node carries its own login, so two nodes on the same residential port can hold different passwords, one copied with Sticky IP and one with Randomize IP. A rule can also name a node instead of the group: send the site you sign in to to the sticky node and the rest of your list to the random one. Browser extensions that keep one login per host and port cannot do this.

An ISP or datacenter IP keeps its address for the rental term. Every program and site your rules send to that node shares it, so give jobs that must not be linked an IP each.

Common errors and fixes

Logs show “rejected username/password”

A SOCKS5 node’s login was refused. Copy USERNAME and PASSWORD from the service page again; on residential, the session options sit at the end of the password and are easy to lose. For a node added as a URI in Edit Proxies, check that special characters are URL-encoded.

Logs show “can not connect remote err code” and a number

The proxy behind an HTTP node turned the request down, and the number is the status it sent back. 407, Proxy Authentication Required, means the login was not accepted; fix it as above. Clash Verge accepts the program’s connection before it reaches the node, so the program never sees a login prompt: an https site fails with a dropped or reset connection, and a plain http page returns 502.

The Connections page shows Match and DIRECT for a site you listed

The site’s connections did not meet your rule. Check the spelling of the domain, that the rule sits above MATCH, that the mode is Rule, and that the profile you edited is the selected one. An IP-CIDR rule without no-resolve above your domain rules can also claim the site first.

A program ignores the proxy entirely

It does not read the system proxy, so nothing reaches Clash Verge and no rule can catch it. Give the program 127.0.0.1 and the Mixed Port in its own proxy setting or environment variables. TUN mode captures programs without their cooperation, but needs the core allowed through the firewall and Clash Verge running in service mode or as administrator.

One node works and the other never connects

On ISP and datacenter the dashboard sets a single protocol. A socks5 node pointed at a proxy set to HTTP, or the reverse, cannot connect. Delete the node that does not match, or switch the protocol in the dashboard.

Need help? What a 407 or 403 message means

Which line to pick

For a bot or script that signs in to one account every day, point its node at an ISP IP. Residential with Sticky IP covers targets that turn away server addresses, and your rules keep those gigabytes to the domains you list. Datacenter is the cheapest node for tools and checks that accept any address.

Stuck on a step?

Paste the command and the error into Discord, with your password taken out. People there have met most of these errors before.

Join the Discorddiscord.gg/proxypanda
Start with $5Ask in Discord