Mac, connected step by step.
Set up HKUVPN on Mac with Clash Verge Rev or Shadowrocket. Match Apple Silicon or Intel, import your subscription, enable the proxy and verify access.
7 chapters · 5 device types · Official client downloads
01 · Check that your connection is ready.
Creating an account, activating a plan and importing into a client are separate steps.
- Register with Google or your usual email—no invitation or school address needed. Open My connection after signing in.
- Check that the connection is active, unexpired and has data remaining. Registration alone does not include a paid connection.
- In Your subscription, copy the format for your client: the general subscription for Shadowrocket, or the Clash subscription for Clash Verge Rev and FlClash.
The full link contains connection credentials. Do not post it in public groups, online converters or screenshots.
02 · Download and install
Clash Verge Rev
Open-source client
- Clash Verge Rev has separate Apple Silicon (arm64 / aarch64) and Intel (x64 / x86_64) builds. Check your chip under Apple menu → About This Mac.
- Open the official Clash Verge Rev installation page, select macOS and download the matching build. Install Shadowrocket from the App Store; pricing and compatibility are set by the store.
- Check the publisher and download source before responding to installation prompts. Follow the official documentation; do not disable certificate checks or system protections.
Menu labels may vary by version, language and system. Refer to the client and its official documentation.
03 · Import your subscription, then connect.
- 01
Copy your Clash subscription
Sign in to Harbor. In My connection → Your subscription, copy the full link labelled Clash subscription. Keep every URL parameter.
- 02
Import from a URL
Open Profiles in Clash Verge Rev. Paste the URL and import it, or create a remote profile with that URL. You can name it Harbor.
Harbor appears in the profile list. If the format is rejected, check that you copied the Clash link.
- 03
Update and activate the profile
Update the subscription, then click its card to make it the current profile. Saving a URL alone does not activate it.
Harbor is selected as the current profile.
- 04
Select a Harbor node
Open Proxies. Keep the supplied Rule mode and select an HY2 or Trojan node in the Harbor group. Run a latency test, then try opening a web page.
The node matches your subscription. Latency tests are diagnostic, not a bandwidth guarantee.
- 05
Enable System Proxy
Enable System Proxy on the home screen or in settings. Browsers and other apps that follow the system proxy can then use the connection. Starting the client does not automatically route every app.
- 06
Use TUN only if needed
If an app ignores the system proxy, follow the official instructions to install the service and enable TUN. This may require administrator permission. Confirm the browser works first.
HY2 · UDP
Try HY2 if your network allows UDP. Keep the subscription's certificate and obfuscation settings.
Trojan · TCP
Try Trojan if HY2 times out. Keep TLS verification on; do not disable it to hide errors.
04 · Verify with real access.
- Check VPN status on mobile, or System Proxy / TUN and the current profile and node on desktop.
- Open an ordinary HTTPS page, then test your target app. Restrictions on one third-party service do not mean every connection failed.
- Check your exit country and address with IPinfo and compare with My connection. Usage records may update after a short delay. IPinfo
A US datacenter exit is not a residential IP. Risk scores or the length of AI responses are not connection tests.
05 · Start with the specific error.
Import fails or the format is invalid
Copy the complete link again. Use the general subscription for Shadowrocket, and the Clash subscription for Clash Verge Rev or FlClash. Check for a disabled account, expired plan, exhausted data or replaced URL.
The profile imports but no nodes appear
Update the subscription and select it as the current profile. An unknown proxy type error may require an update from the client's official source. Older Clash cores do not support HY2.
HY2 times out but Trojan works
HY2 requires UDP, which the current network may restrict. Keep the working Trojan TCP connection, compare Wi-Fi and mobile data, and report the results. A timeout alone does not prove the server is down.
Latency tests work but web pages do not
Check the connection switch, System Proxy and selected node. In Rule mode, check the Harbor group. In Global mode, also select Harbor or a node in GLOBAL. A latency test does not prove browser traffic is routed.
The browser works but another app does not
Check per-app exclusions. Some desktop apps and terminal programs ignore System Proxy; configure their own proxy or follow the official TUN instructions. Change one setting at a time.
Certificate errors or no internet after closing the client
Check device time, client version and subscription source; keep certificate verification enabled. If an exited client leaves a local system proxy behind, turn System Proxy off in that client. Do not erase all proxy settings.
06 · Usage and subscriptions
Should I use Rule, Global or Direct mode?
Start with the subscription's Rule mode: it keeps local network traffic direct and sends matching traffic to the Harbor group. Global mode needs a selection in GLOBAL. Direct does not use Harbor. Rule mode does not mean all mainland websites are automatically direct.
Must I enable DNS overrides?
No single setting is required for everyone. Start with the client's defaults. If logs show DNS errors, follow official documentation to check DNS, TUN and your local network. Do not change every setting on an otherwise working connection.
Should the IP be residential or have a zero risk score?
Harbor uses US datacenter exits, not residential IPs. Check the country, address, real access and usage. Third-party classifications and scores may differ; they are not guarantees of account safety.
Does a connection guarantee AI models and features?
No. Check the platform's own account eligibility, selected model, usage limits and errors. Connectivity does not prove access to any specific model or feature. Harbor does not include AI memberships or API credits.
What happens after renewal, changing devices or replacing my URL?
Renewals normally keep your subscription URL; update the profile and check expiry. Import the appropriate link on a new device. Replacing the URL invalidates the old link immediately; reimport on every device. Previously saved node passwords do not automatically change—contact support if credentials leaked.
Can I share my subscription or invite a friend?
Your subscription contains connection credentials; it is not an invitation link. Friends can register separately. A workspace referral link records the referral relationship. Registration alone does not activate a paid connection; refer to the currently published plan and reward details.
07 · Get support
Include your device and OS, client version, network type, HY2 / Trojan, the failing step and error text in your ticket. Hide subscription URLs, passwords and verification codes in screenshots.