Android, connected step by step.
Connect HKUVPN on Android with FlClash: choose the APK, add and update a remote Clash profile, select a node and approve the VPN connection.
7 chapters · 5 device types · Official client downloads
01 · Check that your connection is ready.
Creating an account, activating a plan and importing into a client are separate steps.
- Register with Google or your usual email—no invitation or school address needed. Open My connection after signing in.
- Check that the connection is active, unexpired and has data remaining. Registration alone does not include a paid connection.
- In Your subscription, copy the format for your client: the general subscription for Shadowrocket, or the Clash subscription for Clash Verge Rev and FlClash.
The full link contains connection credentials. Do not post it in public groups, online converters or screenshots.
02 · Download and install
FlClash
Open-source client
- Download an Android APK from the official FlClash Releases page. Most recent phones use arm64-v8a; check device information and release notes for other architectures.
- Android may ask you to allow installations from the downloading app. Grant this only after confirming the official source; do not disable all device protections.
- HarmonyOS NEXT cannot run Android APKs directly. On older HarmonyOS devices with Android compatibility, check client and system compatibility first.
Menu labels may vary by version, language and system. Refer to the client and its official documentation.
03 · Import your subscription, then connect.
- 01
Copy the Clash subscription
In Harbor, copy the Clash subscription under My connection. FlClash and Clash Verge use the same profile format; the general subscription is not interchangeable.
- 02
Add a remote profile
Open Profiles in FlClash. Add a profile from a URL, paste the full link, name it Harbor and save. Menu labels can vary with version and language.
Harbor appears in the profile list. Check for missing characters or extra spaces.
- 03
Update and select it
Update Harbor and make it the current profile. Open the proxy list and select an HY2 or Trojan node in the Harbor group.
- 04
Start the connection
Start the client from its home screen. On Android, approve the first VPN prompt. On desktop, enable System Proxy or configure TUN only if needed.
The client is running. Android normally shows the system VPN indicator.
- 05
Verify access
Open your target page and check exit information. If the browser works but another app does not, check per-app exclusions and whether that app follows the selected proxy mode.
HY2 · UDP
Try HY2 if your network allows UDP. Keep the subscription's certificate and obfuscation settings.
Trojan · TCP
Try Trojan if HY2 times out. Keep TLS verification on; do not disable it to hide errors.
04 · Verify with real access.
- Check VPN status on mobile, or System Proxy / TUN and the current profile and node on desktop.
- Open an ordinary HTTPS page, then test your target app. Restrictions on one third-party service do not mean every connection failed.
- Check your exit country and address with IPinfo and compare with My connection. Usage records may update after a short delay. IPinfo
A US datacenter exit is not a residential IP. Risk scores or the length of AI responses are not connection tests.
05 · Start with the specific error.
Import fails or the format is invalid
Copy the complete link again. Use the general subscription for Shadowrocket, and the Clash subscription for Clash Verge Rev or FlClash. Check for a disabled account, expired plan, exhausted data or replaced URL.
The profile imports but no nodes appear
Update the subscription and select it as the current profile. An unknown proxy type error may require an update from the client's official source. Older Clash cores do not support HY2.
HY2 times out but Trojan works
HY2 requires UDP, which the current network may restrict. Keep the working Trojan TCP connection, compare Wi-Fi and mobile data, and report the results. A timeout alone does not prove the server is down.
Latency tests work but web pages do not
Check the connection switch, System Proxy and selected node. In Rule mode, check the Harbor group. In Global mode, also select Harbor or a node in GLOBAL. A latency test does not prove browser traffic is routed.
The browser works but another app does not
Check per-app exclusions. Some desktop apps and terminal programs ignore System Proxy; configure their own proxy or follow the official TUN instructions. Change one setting at a time.
Certificate errors or no internet after closing the client
Check device time, client version and subscription source; keep certificate verification enabled. If an exited client leaves a local system proxy behind, turn System Proxy off in that client. Do not erase all proxy settings.
06 · Usage and subscriptions
Should I use Rule, Global or Direct mode?
Start with the subscription's Rule mode: it keeps local network traffic direct and sends matching traffic to the Harbor group. Global mode needs a selection in GLOBAL. Direct does not use Harbor. Rule mode does not mean all mainland websites are automatically direct.
Must I enable DNS overrides?
No single setting is required for everyone. Start with the client's defaults. If logs show DNS errors, follow official documentation to check DNS, TUN and your local network. Do not change every setting on an otherwise working connection.
Should the IP be residential or have a zero risk score?
Harbor uses US datacenter exits, not residential IPs. Check the country, address, real access and usage. Third-party classifications and scores may differ; they are not guarantees of account safety.
Does a connection guarantee AI models and features?
No. Check the platform's own account eligibility, selected model, usage limits and errors. Connectivity does not prove access to any specific model or feature. Harbor does not include AI memberships or API credits.
What happens after renewal, changing devices or replacing my URL?
Renewals normally keep your subscription URL; update the profile and check expiry. Import the appropriate link on a new device. Replacing the URL invalidates the old link immediately; reimport on every device. Previously saved node passwords do not automatically change—contact support if credentials leaked.
Can I share my subscription or invite a friend?
Your subscription contains connection credentials; it is not an invitation link. Friends can register separately. A workspace referral link records the referral relationship. Registration alone does not activate a paid connection; refer to the currently published plan and reward details.
07 · Get support
Include your device and OS, client version, network type, HY2 / Trojan, the failing step and error text in your ticket. Hide subscription URLs, passwords and verification codes in screenshots.