Clash Verge Rev is a desktop client for Windows, macOS and Linux built around the Mihomo core. It sells and supplies no proxies: you give it nodes, here the HTTP or SOCKS5 proxy from your own order, and rules that decide, connection by connection, which traffic uses a node and which goes direct. Clash Verge proxy setup comes down to three blocks of YAML: proxies with your host, port, username and password, a proxy-groups entry to switch between them, and rules that end in MATCH,DIRECT so only what you name touches the proxy.

We ran every config on this page with Mihomo v1.19.32 against local HTTP and SOCKS5 proxies that require a username and password, and quote the core's own log lines. We did not run the Clash Verge app itself: its menu names, TUN mode and service mode come from the project's documentation at clashverge.dev, and we say so where it matters. Clash Verge Rev is GPL-3.0 licensed and released on GitHub.

Before you start

  1. Open your order in the dashboard at https://app.proxyhive.io.
  2. Copy HOST, USERNAME and PASSWORD, plus both the HTTP port and the SOCKS5 port. Each ISP or datacenter IP is its own endpoint, with its HTTP, HTTPS and SOCKS5 ports listed separately on the order.
  3. Decide what should use the proxy: a handful of domains, a few programs, or everything. That decision becomes your rules.

Both protocols carry TCP and neither encrypts anything itself; HTTP vs SOCKS5 proxies covers the choice, and the protocol comparison shows on the wire what a plain SOCKS5 connection exposes.

The profile: nodes, a group and rules

Save this as hive.yaml, with HOST, USERNAME and PASSWORD replaced by the values from your order, and 8000 and 1080 by its HTTP and SOCKS5 ports:

proxies:
  - name: hive-http
    type: http
    server: HOST
    port: 8000
    username: USERNAME
    password: "PASSWORD"
  - name: hive-socks
    type: socks5
    server: HOST
    port: 1080
    username: USERNAME
    password: "PASSWORD"
proxy-groups:
  - name: PROXY
    type: select
    proxies: [hive-http, hive-socks]
rules:
  - DOMAIN,api.ipify.org,PROXY
  - DOMAIN-SUFFIX,target-site.com,PROXY
  - IP-CIDR,10.0.0.0/8,DIRECT,no-resolve
  - MATCH,DIRECT
  • proxies are the nodes. type: http uses your HTTP proxy port, type: socks5 the SOCKS5 port. Write the password as it is, in quotes. We tested a password containing @, : and / this way and it worked on both node types; the same password percent-encoded in YAML was refused, because the core sends it literally.
  • proxy-groups gives the rules one name, PROXY, to point at. A select group is switched by hand, so you can move every rule from the HTTP node to the SOCKS5 node in one click. In our test the core remembered the choice across restarts.
  • rules are read top to bottom and the first match wins. MATCH,DIRECT at the end means anything you did not name leaves from your own connection and never touches the node.

Matched domains are handed to the node by name, so the proxy resolves them. The core logged match DomainSuffix(target-site.com) using PROXY[hive-http], our test proxy logged a request for target-site.com, and our local resolver received no query for it.

Import it into Clash Verge

Clash Verge's documentation describes two ways in for a local profile: create a new profile and choose the file, or drag the YAML file onto the window (version 1.6.2 or later). Either way the file is copied into Clash Verge's profiles directory, so later edits to your original hive.yaml do not reach it. Make that profile the active one and set the mode to Rule; Global sends everything through the node you pick and Direct sends nothing.

If you would rather extend a profile you already use, the documentation lists two visual editors on the profile's right-click menu:

  • Edit Nodes accepts a node as a URI, such as socks5://USERNAME:PASSWORD@HOST:PORT or http://USERNAME:PASSWORD@HOST:PORT. In this form, URL-encode any special characters in the username and password, the opposite of the YAML advice above.
  • Edit Rules has prepend rules, which take priority over the profile's own, and append rules, which apply after them. The project says rules added there survive profile updates.

Rules worth knowing

The rule types Clash Verge documents include DOMAIN, DOMAIN-SUFFIX, DOMAIN-KEYWORD, GEOSITE, IP-CIDR, GEOIP, DST-PORT, PROCESS-NAME, AND and OR, and MATCH. Three behave in ways that catch people out:

  • PROCESS-NAME matches the name the operating system reports. On Linux, PROCESS-NAME,curl,PROXY sent curl through the node and left everything else alone; the log showed 127.0.0.1:57824(curl, uid=1000). Python showed up as python3.12, not python3, so copy the name from the log. The project's examples use names such as Telegram.exe on Windows. Process lookup depends on what each operating system exposes, so test it on yours. Back-to-back curl runs in our test missed the lookup on some connections, which fell through to the next rule, so give a target that must use the proxy a domain rule as well.
  • IP-CIDR and GEOIP without no-resolve make the core look the domain up locally to compare the address. If the answer lands in the range, the connection goes wherever that rule says, before your domain rule is ever read. Add ,no-resolve to IP rules unless you mean them to catch domains. The system proxy vs TUN mode comparison walks through our test.
  • UDP skips a rule whose node cannot carry it. An HTTP node, or a SOCKS5 node without udp: true, cannot relay UDP, so UDP matching that rule fell through to MATCH,DIRECT in our test. Add AND,((NETWORK,UDP),(DOMAIN-SUFFIX,target-site.com)),REJECT above the proxy rule if that traffic must never leave directly.

Rule-based routing covers the idea behind all of this.

System proxy or TUN mode

Rules decide where traffic goes; the capture mode decides what reaches the rules. From the project's documentation:

System proxyTUN mode
How traffic arrivesApps that read the operating system's proxy setting send it to Clash's local mixed portA virtual network adapter takes traffic from every app
Apps that ignore proxy settingsNot capturedCaptured
UDPNot carriedCaptured, then routed by your rules
SetupTurn it on in Clash VergeAllow the cores verge-mihomo and verge-mihomo-alpha through your firewall; service mode lets TUN start without an administrator prompt

Start with system proxy. Move to TUN mode when a program ignores proxy settings, the job ProxyChains and Redsocks do on a Linux box. The mixed port, the mode, IPv6 and the TUN switch are Clash Verge settings, and they override anything an extension writes for them. You can also skip both modes: point one program's own proxy setting at the mixed port, which accepts HTTP and SOCKS5 on the same port. System proxy vs TUN mode vs per-app rules compares the three.

Extension config and extension script

Each profile can carry an extension config, YAML merged over it, and an extension script, JavaScript run after the extension config. The documentation is precise about the merge, and one rule matters most: a list such as rules or proxies in the extension config replaces the profile's list whole. Put rules: there and the profile's own rules are gone. Use Edit Rules to prepend instead, or a script that adds to the list:

function main(config) {
  var ips = [
    { name: "isp-1", server: "203.0.113.10" },
    { name: "isp-2", server: "203.0.113.11" }
  ];
  var nodes = ips.map(function (ip) {
    return {
      name: ip.name,
      type: "socks5",
      server: ip.server,
      port: 1080,
      username: "USERNAME",
      password: "PASSWORD"
    };
  });
  config.proxies = (config.proxies || []).concat(nodes);
  config["proxy-groups"] = (config["proxy-groups"] || []).concat([
    { name: "ISP", type: "select", proxies: nodes.map(function (n) { return n.name; }) }
  ]);
  config.rules = ["DOMAIN-SUFFIX,target-site.com,ISP"].concat(config.rules || []);
  return config;
}

It turns a list of IPs into one node each, groups them, and puts one rule in front of whatever the profile already has. Replace the documentation addresses 203.0.113.x, the port and the credentials with your own. We ran this function in Node against a profile ending in MATCH,DIRECT and loaded the result into Mihomo, which routed target-site.com through ISP[isp-1] and the rest direct; Clash Verge's own script runtime was not part of that test.

Chain through an office proxy with dialer-proxy

Some networks only let traffic out through a company proxy. dialer-proxy makes one node connect through another:

proxies:
  - name: office-gateway
    type: http
    server: proxy.office.example
    port: 3128
  - name: hive-socks
    type: socks5
    server: HOST
    port: 1080
    username: USERNAME
    password: "PASSWORD"
    dialer-proxy: office-gateway
rules:
  - DOMAIN-SUFFIX,target-site.com,hive-socks
  - MATCH,DIRECT

In our run the office proxy logged a single tunnel to the SOCKS5 node's address and port, and only the SOCKS5 node saw target-site.com. SOCKS5 is not encrypted, so an office proxy that inspects tunnels could still read that handshake. Clash Verge Rev 2.4.5 and later builds the same thing in Edit Nodes, with an entry node, an optional middle node and an exit node, on top of dialer-proxy. Every hop adds latency and any hop failing breaks the route; the proxy chain entry covers when a chain earns its place.

Check the route

The first rule in the profile exists for this test. With Clash Verge running, send a request through the mixed port, the port number shown in Clash Verge's settings:

curl -s -x http://127.0.0.1:MIXED_PORT "https://api.ipify.org?format=json"

The ip should be your proxy's. Remove the DOMAIN,api.ipify.org,PROXY rule and run it again: now it falls through to MATCH,DIRECT and shows your own address. One request each way proves the node works and that the rules, not luck, decide.

The core's log names the rule and the node for every connection. These lines are from our run of the profile above, where the test site listened on port 28100:

[TCP] 127.0.0.1:56822 --> api.ipify.org:443 match Domain(api.ipify.org) using PROXY[hive-http]
[TCP] 127.0.0.1:56814 --> target-site.com:28100 match DomainSuffix(target-site.com) using PROXY[hive-http]
[TCP] 127.0.0.1:60314 --> other-site.com:28100 match Match using DIRECT

Troubleshooting

  • SOCKS5 node, wrong username or password. The log repeats error: rejected username/password as the core retries. A plain-HTTP request through the mixed port gets a 502.
  • HTTP node, refused login. The log reads can not connect remote err code: followed by the status the proxy sent; 407 is the standard one for a refused login. The 407 never reaches your app.
  • A TLS error in the browser instead of a status code. Clash answers the browser's CONNECT with 200 Connection established before dialing the node. When the node then refuses, the tunnel closes and curl reports SSL_ERROR_SYSCALL. Read the core's log, not the browser.
  • Traffic goes direct although a rule names the proxy. An earlier rule matched: check IP rules without no-resolve first, then UDP that fell through.
  • A program ignores the proxy. It does not read the system proxy setting. Use TUN mode or point the program at the mixed port.

With ProxyHive

A static ISP proxy suits a desktop routing client: the address stays yours for the term, the order lists HTTP, HTTPS and SOCKS5 ports with username and password authentication, and each IP is its own endpoint, so each one becomes its own node. Add several to a select group and the rules decide which work uses which IP. The specs say nothing about UDP relay, so plan on TCP and keep the UDP REJECT rule above. ISP IPs start at $3.20/IP (dedicated) on ISP pricing; check the allowed-use policy before you route a new job through them.