Does a VPN icon mean Shadowrocket is connected?

Allowing a VPN configuration and having a working node are two different things. The status bar alone will mislead you.

The first time you turn Shadowrocket’s switch on, the system asks whether to add a VPN configuration. After you allow it, the status bar or Control Center often shows VPN. Many people treat that badge as “a working node is connected.” It only means the system handed some traffic to this app’s tunnel. A tunnel does not mean the remote server is answering, or that the current mode will send pages through a node.

Keep these two steps separate or later troubleshooting will not make sense. If permission fails, the app cannot take over traffic, no matter how many nodes you have. If permission succeeded but the node is dead, granting permission again usually does not help.

Permission happens only at the system layer

The system prompt is roughly “Shadowrocket Would Like to Add VPN Configurations.” You must allow it, then complete Face ID, Touch ID, or the device passcode. If you deny it, the switch cannot really work. You can also check Settings → General → VPN & Device Management for a Shadowrocket entry. If it is missing, the configuration was not written.

If you tapped Don’t Allow, go back to Home and turn the switch on again. The system usually asks again. If there is still no entry, delete that VPN configuration and reopen the app. This step is unrelated to an expired subscription, and you do not need to change Type.

Successful permission only hands tunnel rights to the app. On an empty config, Home still shows Not Connected, and SERVER still lists Add Server. Turning the switch on with no node can still show VPN, because the tunnel can come up. There is no server to forward to, so pages behave like an empty pipe.

Select a node, then read the status left of the switch

After you import a subscription or add a node by hand, you must select a row in the list. With nothing selected, the app does not know where to send traffic. Then turn on the switch to the right of Not Connected. The label changes while it connects. After success, that row is no longer Not Connected.

The first block on Home is the connection row. Do not judge by whether a bottom tab turned blue, or whether the icon is refreshing in the background. Whether a node is selected is the highlight in the list, plus the text on that row.

When you change nodes, turn the switch off first or follow the app’s prompt, then tap another row. Tapping several rows without watching the highlight makes it easy to think you switched when you are still on the previous node.

Use Connectivity Test, not a “feel” from a webpage

Connectivity Test on Home shows whether the current node returns a latency number. It is a better first step than opening a random website, because sites also depend on rules, DNS, and the remote host. If the test has no result, spins for a long time, or clearly fails, try another node. Do not change system DNS first.

A number only means the probe got a reply. A particular site may still fail. Then check whether Global Routing is Direct, and whether rules sent that site direct. The reverse—test fails but a site that should stay direct still opens—often means you are actually on Direct, or rules left those sites local.

Do not reinstall to “refresh the test.” Reinstalling will not revive an expired subscription or a remote server. When a test fails, update the subscription, try another node, then decide whether to open Diagnostics.

A missing VPN badge also does not mean the app is broken

After you turn the switch off, the VPN badge should disappear. If it stays, check VPN status in system Settings, then confirm the switch in the app. Do not delete the configuration in system Settings and expect the app to reconnect by itself. Deleting it revokes permission. You will have to allow it again.

Some system versions show VPN in Control Center. That switch and the switch on Shadowrocket Home manage the same tunnel. Do not flip both, or the state can drift. Trust the copy on the app’s Home screen.

How this connects to the later tutorials

Screenshots for allow, select, and test are in Connect. If the test fails and the list is empty, go back to Import config and check Type and the URL. If the list has nodes and the test returns a number but behavior is still wrong, read How to choose Config, Proxy, or Direct. To walk through symptoms one by one, use Troubleshoot.

This article does not cover any node source. Without a valid config you can install the app and finish permission, but the connection will not succeed because of that. Material has to come from your own provider.