iPhone / iPad, connected step by step.
Set up HKUVPN on iPhone or iPad: install Shadowrocket, copy the general subscription, add a Subscribe entry, update nodes and approve the system VPN connection.
7 chapters · 5 device types · Official client downloads
01 · Check that your connection is ready.
Creating an account, activating a plan and importing into a client are separate steps.
- Register with Google or your usual email—no invitation or school address needed. Open My connection after signing in.
- Check that the connection is active, unexpired and has data remaining. Registration alone does not include a paid connection.
- In Your subscription, copy the format for your client: the general subscription for Shadowrocket, or the Clash subscription for Clash Verge Rev and FlClash.
The full link contains connection credentials. Do not post it in public groups, online converters or screenshots.
02 · Download and install
Shadowrocket
Paid App Store app · purchased separately
- Find Shadowrocket in the App Store and check the developer is Shadow Launch Technology Limited. The app is a separate purchase, not included in a Harbor plan.
- Availability depends on your Apple account region and device compatibility. Use your own Apple account; Harbor does not need your account password.
- After installation, import your own subscription using the steps below. The system VPN permission appears on first connection.
Menu labels may vary by version, language and system. Refer to the client and its official documentation.
03 · Import your subscription, then connect.
- 01
Copy the Shadowrocket / general subscription
In Harbor, open My connection → Your subscription and copy the Shadowrocket / general subscription link. Do not use the Clash link.
- 02
Add a Subscribe entry
In Shadowrocket, tap + on the home screen. Set Type to Subscribe, paste the complete URL, name it Harbor and save.
You have saved a subscription. There is no need to enter a server password or port manually.
- 03
Update and select a node
Return home, update the subscription and check that Harbor nodes appear. Select HY2 or Trojan. A subscription name alone does not mean nodes have been imported.
Specific nodes are listed. If the list is empty, check subscription status and link format.
- 04
Connect and approve the system prompt
Turn on the connection. On first use, allow Shadowrocket to add a VPN configuration when the system asks. Check that the prompt is from the app you installed. Keep TLS certificate verification enabled.
- 05
Check real access
Open an ordinary HTTPS page, then check your exit IP and Harbor usage. If HY2 times out but Trojan works, keep using Trojan and report your network and error to support.
HY2 · UDP
Try HY2 if your network allows UDP. Keep the subscription's certificate and obfuscation settings.
Trojan · TCP
Try Trojan if HY2 times out. Keep TLS verification on; do not disable it to hide errors.
04 · Verify with real access.
- Check VPN status on mobile, or System Proxy / TUN and the current profile and node on desktop.
- Open an ordinary HTTPS page, then test your target app. Restrictions on one third-party service do not mean every connection failed.
- Check your exit country and address with IPinfo and compare with My connection. Usage records may update after a short delay. IPinfo
A US datacenter exit is not a residential IP. Risk scores or the length of AI responses are not connection tests.
05 · Start with the specific error.
Import fails or the format is invalid
Copy the complete link again. Use the general subscription for Shadowrocket, and the Clash subscription for Clash Verge Rev or FlClash. Check for a disabled account, expired plan, exhausted data or replaced URL.
The profile imports but no nodes appear
Update the subscription and select it as the current profile. An unknown proxy type error may require an update from the client's official source. Older Clash cores do not support HY2.
HY2 times out but Trojan works
HY2 requires UDP, which the current network may restrict. Keep the working Trojan TCP connection, compare Wi-Fi and mobile data, and report the results. A timeout alone does not prove the server is down.
Latency tests work but web pages do not
Check the connection switch, System Proxy and selected node. In Rule mode, check the Harbor group. In Global mode, also select Harbor or a node in GLOBAL. A latency test does not prove browser traffic is routed.
The browser works but another app does not
Check per-app exclusions. Some desktop apps and terminal programs ignore System Proxy; configure their own proxy or follow the official TUN instructions. Change one setting at a time.
Certificate errors or no internet after closing the client
Check device time, client version and subscription source; keep certificate verification enabled. If an exited client leaves a local system proxy behind, turn System Proxy off in that client. Do not erase all proxy settings.
06 · Usage and subscriptions
Should I use Rule, Global or Direct mode?
Start with the subscription's Rule mode: it keeps local network traffic direct and sends matching traffic to the Harbor group. Global mode needs a selection in GLOBAL. Direct does not use Harbor. Rule mode does not mean all mainland websites are automatically direct.
Must I enable DNS overrides?
No single setting is required for everyone. Start with the client's defaults. If logs show DNS errors, follow official documentation to check DNS, TUN and your local network. Do not change every setting on an otherwise working connection.
Should the IP be residential or have a zero risk score?
Harbor uses US datacenter exits, not residential IPs. Check the country, address, real access and usage. Third-party classifications and scores may differ; they are not guarantees of account safety.
Does a connection guarantee AI models and features?
No. Check the platform's own account eligibility, selected model, usage limits and errors. Connectivity does not prove access to any specific model or feature. Harbor does not include AI memberships or API credits.
What happens after renewal, changing devices or replacing my URL?
Renewals normally keep your subscription URL; update the profile and check expiry. Import the appropriate link on a new device. Replacing the URL invalidates the old link immediately; reimport on every device. Previously saved node passwords do not automatically change—contact support if credentials leaked.
Can I share my subscription or invite a friend?
Your subscription contains connection credentials; it is not an invitation link. Friends can register separately. A workspace referral link records the referral relationship. Registration alone does not activate a paid connection; refer to the currently published plan and reward details.
07 · Get support
Include your device and OS, client version, network type, HY2 / Trojan, the failing step and error text in your ticket. Hide subscription URLs, passwords and verification codes in screenshots.