Clash Verge Rev is a desktop client for Windows, macOS and Linux built around the Mihomo core. It sells and supplies no proxies: you give it nodes, here the HTTP or SOCKS5 proxy from your own order, and rules that decide, connection by connection, which traffic uses a node and which goes direct. Clash Verge proxy setup comes down to three blocks of YAML: proxies with your host, port, username and password, a proxy-groups entry to switch between them, and rules that end in MATCH,DIRECT so only what you name touches the proxy.
We ran every config on this page with Mihomo v1.19.32 against local HTTP and SOCKS5 proxies that require a username and password, and quote the core's own log lines. We did not run the Clash Verge app itself: its menu names, TUN mode and service mode come from the project's documentation at clashverge.dev, and we say so where it matters. Clash Verge Rev is GPL-3.0 licensed and released on GitHub.
Before you start
- Open your order in the dashboard at https://app.proxyhive.io.
- Copy HOST, USERNAME and PASSWORD, plus both the HTTP port and the SOCKS5 port. Each ISP or datacenter IP is its own endpoint, with its HTTP, HTTPS and SOCKS5 ports listed separately on the order.
- Decide what should use the proxy: a handful of domains, a few programs, or everything. That decision becomes your rules.
Both protocols carry TCP and neither encrypts anything itself; HTTP vs SOCKS5 proxies covers the choice, and the protocol comparison shows on the wire what a plain SOCKS5 connection exposes.
The profile: nodes, a group and rules
Save this as hive.yaml, with HOST, USERNAME and PASSWORD replaced by the values from your order, and 8000 and 1080 by its HTTP and SOCKS5 ports:
proxies:
- name: hive-http
type: http
server: HOST
port: 8000
username: USERNAME
password: "PASSWORD"
- name: hive-socks
type: socks5
server: HOST
port: 1080
username: USERNAME
password: "PASSWORD"
proxy-groups:
- name: PROXY
type: select
proxies: [hive-http, hive-socks]
rules:
- DOMAIN,api.ipify.org,PROXY
- DOMAIN-SUFFIX,target-site.com,PROXY
- IP-CIDR,10.0.0.0/8,DIRECT,no-resolve
- MATCH,DIRECT
proxiesare the nodes.type: httpuses your HTTP proxy port,type: socks5the SOCKS5 port. Write the password as it is, in quotes. We tested a password containing@,:and/this way and it worked on both node types; the same password percent-encoded in YAML was refused, because the core sends it literally.proxy-groupsgives the rules one name,PROXY, to point at. Aselectgroup is switched by hand, so you can move every rule from the HTTP node to the SOCKS5 node in one click. In our test the core remembered the choice across restarts.rulesare read top to bottom and the first match wins.MATCH,DIRECTat the end means anything you did not name leaves from your own connection and never touches the node.
Matched domains are handed to the node by name, so the proxy resolves them. The core logged match DomainSuffix(target-site.com) using PROXY[hive-http], our test proxy logged a request for target-site.com, and our local resolver received no query for it.
Import it into Clash Verge
Clash Verge's documentation describes two ways in for a local profile: create a new profile and choose the file, or drag the YAML file onto the window (version 1.6.2 or later). Either way the file is copied into Clash Verge's profiles directory, so later edits to your original hive.yaml do not reach it. Make that profile the active one and set the mode to Rule; Global sends everything through the node you pick and Direct sends nothing.
If you would rather extend a profile you already use, the documentation lists two visual editors on the profile's right-click menu:
- Edit Nodes accepts a node as a URI, such as
socks5://USERNAME:PASSWORD@HOST:PORTorhttp://USERNAME:PASSWORD@HOST:PORT. In this form, URL-encode any special characters in the username and password, the opposite of the YAML advice above. - Edit Rules has prepend rules, which take priority over the profile's own, and append rules, which apply after them. The project says rules added there survive profile updates.
Rules worth knowing
The rule types Clash Verge documents include DOMAIN, DOMAIN-SUFFIX, DOMAIN-KEYWORD, GEOSITE, IP-CIDR, GEOIP, DST-PORT, PROCESS-NAME, AND and OR, and MATCH. Three behave in ways that catch people out:
PROCESS-NAMEmatches the name the operating system reports. On Linux,PROCESS-NAME,curl,PROXYsent curl through the node and left everything else alone; the log showed127.0.0.1:57824(curl, uid=1000). Python showed up aspython3.12, notpython3, so copy the name from the log. The project's examples use names such asTelegram.exeon Windows. Process lookup depends on what each operating system exposes, so test it on yours. Back-to-back curl runs in our test missed the lookup on some connections, which fell through to the next rule, so give a target that must use the proxy a domain rule as well.IP-CIDRandGEOIPwithoutno-resolvemake the core look the domain up locally to compare the address. If the answer lands in the range, the connection goes wherever that rule says, before your domain rule is ever read. Add,no-resolveto IP rules unless you mean them to catch domains. The system proxy vs TUN mode comparison walks through our test.- UDP skips a rule whose node cannot carry it. An HTTP node, or a SOCKS5 node without
udp: true, cannot relay UDP, so UDP matching that rule fell through toMATCH,DIRECTin our test. AddAND,((NETWORK,UDP),(DOMAIN-SUFFIX,target-site.com)),REJECTabove the proxy rule if that traffic must never leave directly.
Rule-based routing covers the idea behind all of this.
System proxy or TUN mode
Rules decide where traffic goes; the capture mode decides what reaches the rules. From the project's documentation:
| System proxy | TUN mode | |
|---|---|---|
| How traffic arrives | Apps that read the operating system's proxy setting send it to Clash's local mixed port | A virtual network adapter takes traffic from every app |
| Apps that ignore proxy settings | Not captured | Captured |
| UDP | Not carried | Captured, then routed by your rules |
| Setup | Turn it on in Clash Verge | Allow the cores verge-mihomo and verge-mihomo-alpha through your firewall; service mode lets TUN start without an administrator prompt |
Start with system proxy. Move to TUN mode when a program ignores proxy settings, the job ProxyChains and Redsocks do on a Linux box. The mixed port, the mode, IPv6 and the TUN switch are Clash Verge settings, and they override anything an extension writes for them. You can also skip both modes: point one program's own proxy setting at the mixed port, which accepts HTTP and SOCKS5 on the same port. System proxy vs TUN mode vs per-app rules compares the three.
Extension config and extension script
Each profile can carry an extension config, YAML merged over it, and an extension script, JavaScript run after the extension config. The documentation is precise about the merge, and one rule matters most: a list such as rules or proxies in the extension config replaces the profile's list whole. Put rules: there and the profile's own rules are gone. Use Edit Rules to prepend instead, or a script that adds to the list:
function main(config) {
var ips = [
{ name: "isp-1", server: "203.0.113.10" },
{ name: "isp-2", server: "203.0.113.11" }
];
var nodes = ips.map(function (ip) {
return {
name: ip.name,
type: "socks5",
server: ip.server,
port: 1080,
username: "USERNAME",
password: "PASSWORD"
};
});
config.proxies = (config.proxies || []).concat(nodes);
config["proxy-groups"] = (config["proxy-groups"] || []).concat([
{ name: "ISP", type: "select", proxies: nodes.map(function (n) { return n.name; }) }
]);
config.rules = ["DOMAIN-SUFFIX,target-site.com,ISP"].concat(config.rules || []);
return config;
}
It turns a list of IPs into one node each, groups them, and puts one rule in front of whatever the profile already has. Replace the documentation addresses 203.0.113.x, the port and the credentials with your own. We ran this function in Node against a profile ending in MATCH,DIRECT and loaded the result into Mihomo, which routed target-site.com through ISP[isp-1] and the rest direct; Clash Verge's own script runtime was not part of that test.
Chain through an office proxy with dialer-proxy
Some networks only let traffic out through a company proxy. dialer-proxy makes one node connect through another:
proxies:
- name: office-gateway
type: http
server: proxy.office.example
port: 3128
- name: hive-socks
type: socks5
server: HOST
port: 1080
username: USERNAME
password: "PASSWORD"
dialer-proxy: office-gateway
rules:
- DOMAIN-SUFFIX,target-site.com,hive-socks
- MATCH,DIRECT
In our run the office proxy logged a single tunnel to the SOCKS5 node's address and port, and only the SOCKS5 node saw target-site.com. SOCKS5 is not encrypted, so an office proxy that inspects tunnels could still read that handshake. Clash Verge Rev 2.4.5 and later builds the same thing in Edit Nodes, with an entry node, an optional middle node and an exit node, on top of dialer-proxy. Every hop adds latency and any hop failing breaks the route; the proxy chain entry covers when a chain earns its place.
Check the route
The first rule in the profile exists for this test. With Clash Verge running, send a request through the mixed port, the port number shown in Clash Verge's settings:
curl -s -x http://127.0.0.1:MIXED_PORT "https://api.ipify.org?format=json"
The ip should be your proxy's. Remove the DOMAIN,api.ipify.org,PROXY rule and run it again: now it falls through to MATCH,DIRECT and shows your own address. One request each way proves the node works and that the rules, not luck, decide.
The core's log names the rule and the node for every connection. These lines are from our run of the profile above, where the test site listened on port 28100:
[TCP] 127.0.0.1:56822 --> api.ipify.org:443 match Domain(api.ipify.org) using PROXY[hive-http]
[TCP] 127.0.0.1:56814 --> target-site.com:28100 match DomainSuffix(target-site.com) using PROXY[hive-http]
[TCP] 127.0.0.1:60314 --> other-site.com:28100 match Match using DIRECT
Troubleshooting
- SOCKS5 node, wrong username or password. The log repeats
error: rejected username/passwordas the core retries. A plain-HTTP request through the mixed port gets a 502. - HTTP node, refused login. The log reads
can not connect remote err code:followed by the status the proxy sent; 407 is the standard one for a refused login. The 407 never reaches your app. - A TLS error in the browser instead of a status code. Clash answers the browser's
CONNECTwith200 Connection establishedbefore dialing the node. When the node then refuses, the tunnel closes and curl reportsSSL_ERROR_SYSCALL. Read the core's log, not the browser. - Traffic goes direct although a rule names the proxy. An earlier rule matched: check IP rules without
no-resolvefirst, then UDP that fell through. - A program ignores the proxy. It does not read the system proxy setting. Use TUN mode or point the program at the mixed port.
With ProxyHive
A static ISP proxy suits a desktop routing client: the address stays yours for the term, the order lists HTTP, HTTPS and SOCKS5 ports with username and password authentication, and each IP is its own endpoint, so each one becomes its own node. Add several to a select group and the rules decide which work uses which IP. The specs say nothing about UDP relay, so plan on TCP and keep the UDP REJECT rule above. ISP IPs start at $3.20/IP (dedicated) on ISP pricing; check the allowed-use policy before you route a new job through them.