This guide is for anyone preparing to replace an iPhone, reset a device, or create a backup of an existing Shadowrocket setup. The key is to distinguish App Store purchase records, iCloud-synced data, Config files, and subscription details, then migrate in order: check the old device, back up each layer, restore on the new device, and verify everything. Seeing the connection switch return does not mean the entire configuration has been restored.
First, identify the four types of data to migrate
Migrating Shadowrocket is not a matter of copying one file. App Store purchase records, servers or subscriptions in Home, rule files in Config, and settings such as On Demand and DNS in Settings belong to different layers. Restoring one layer does not mean the others are complete.
The App Store handles purchasing and redownloading the app. Shadowrocket is a paid commercial app provided by Shadow Launch Technology Limited. Its app ID is 932747118, and the App Store is the only official source. Check the App Store page for the system requirements and compatibility on a new device.
iCloud sync transfers data supported by the app, while a Config export creates a visible copy of rule files that can be saved separately. Subscription URLs come from the service provider already used by the user. Whether they reappear after syncing must be confirmed on the new device, so do not rely on a single backup method.
Conclusion: make a checklist before syncing
Before switching devices, record the current Home selection, active Config file, Global Routing mode, and On Demand conditions. Check the new device against the same list; this makes missing items easier to spot than simply watching the main connection switch.
Run a full check on the old iPhone first
Before starting the migration, open Shadowrocket on the old iPhone. In Home, record the selected server or subscription group, then check whether Global Routing is set to Proxy, Direct, Config, or Scene. If you normally use rule-based routing, note the name of the active Config.
Next, open Config and confirm that the target rule file opens correctly and that the rule list is not blank. Then open Settings and record DNS, On Demand, and any other items you have changed. The Wi-Fi and cellular triggers under Settings → On Demand affect automatic connection behavior; the new device may require these conditions to be authorized or recreated.
- Confirm the app source: Open the Shadowrocket product page in the App Store and verify the developer, Shadow Launch Technology Limited, and app ID 932747118.
- Record the Home state: Note the selected item, subscription group name, and Global Routing mode. If needed, use a system screenshot to preserve the interface state.
- Check Config: Open the current configuration and confirm that custom DOMAIN-SUFFIX, GEOIP, IP-CIDR, and FINAL rules are still in the expected positions.
- Check Settings: Record DNS, On Demand, and any other switches that affect connectivity. Do not assume that system-level permissions will carry over automatically.
- Keep subscription details: If you use a subscription provided by a service provider you already use, confirm that the subscription URL is still available from the original account page and store the access credentials securely.
Enable iCloud sync and confirm the sync requirements
In the iPhone system settings, first confirm that iCloud Drive is enabled for the current Apple Account and that Shadowrocket is allowed to use iCloud. Then return to Shadowrocket, open Settings → iCloud, and enable the sync items shown in the app. Interface names may change with the current App Store version; follow the labels displayed in the app.
Do not immediately turn off or erase the old device after enabling sync. Keep it connected to the network, wait for syncing to complete, then return to Home and Config to confirm that the content remains visible and stable. iCloud sync takes time to propagate; no immediate change after enabling the switch does not by itself indicate a failure.
iCloud should be treated as only one part of the migration path. For important custom rules, also export a Config file. For subscriptions, keep the original URL provided by the service provider you already use. An example format is https://example.com/sub?token=xxxx; this URL only illustrates the field structure and cannot be used for connectivity.
iCloud sync check
- System entry
- Settings → Apple Account → iCloud
- App entry
- Settings → iCloud
- Requirements
- The same Apple Account and a working network connection
- Completion check
- Home and Config content appears consistently on the new device
The sync scope depends on the items listed in the current app. System VPN authorization still needs to be confirmed on the new device.
Manual copy check
- Rules entry
- Config → target configuration
- Save action
- Share or Export
- Recommended location
- An identifiable folder in Files
- Content to verify
- Rule order and the FINAL fallback
If the interface provides an information button, open the configuration details first, then look for Share or Export.
Export the Config file and keep a rule copy
Config files primarily contain rules and related configuration. In Config, select the file currently in use, then look for Share, Export, or similar actions in the details or action menu and save the file to Files. Depending on the interface layout, the entry may appear as an information button, more menu, or long-press action; follow the controls shown in the current app.
After exporting, use a text preview to inspect the key rules. Rules are matched from top to bottom, and the first matching rule determines the result. FINAL handles traffic not covered by earlier rules. During migration, identical filenames with different rule ordering can produce different routing results.
[Rule]
DOMAIN-SUFFIX,example.com,PROXY
DOMAIN-KEYWORD,example,DIRECT
GEOIP,CN,DIRECT
IP-CIDR,192.168.0.0/16,DIRECT
FINAL,PROXY
- Check file readability: After saving, confirm in Files that the file exists, has a clear name and purpose, and is not an unusually small empty file.
- Check key rules: Search for DOMAIN-SUFFIX, GEOIP, IP-CIDR, and FINAL, and confirm that the action field is still the expected PROXY, DIRECT, or REJECT.
- Check rule order: Specific domain rules should appear before broad matches and FINAL; otherwise, a broader rule may match first.
- Store sensitive information separately: Keep configuration files and subscription access credentials in locations protected by device permissions. Do not publish them on a public page.
Exporting a Config file does not fully copy every item in Home. Server entries, subscription update status, system VPN authorization, and On Demand conditions still need separate checks. The main value of a manual copy is that it makes rule content visible and provides a recovery path if iCloud sync is incomplete.
Restore Shadowrocket on the new iPhone
Once the new iPhone is ready, use the Apple Account associated with the original purchase to open the App Store and redownload the app from your purchased items or the Shadowrocket product page. If the purchase status looks wrong, first check the current App Store account and storefront region. Do not repeatedly create VPN configurations inside the app.
When Shadowrocket is opened for the first time, iOS requests permission to add a VPN configuration when connection features are enabled. This authorization is local to the new device and must be confirmed again. Even if Home and Config content sync through iCloud, a connection cannot be established without system authorization.
- Restore the app: Get Shadowrocket from the App Store, verify the developer and app ID, then open it.
- Enable iCloud: Confirm that iCloud Drive is available in the system, then open Settings → iCloud, enable the required sync items, and wait for the data to appear.
- Check Home: Confirm that the original items are present and that the selected entry is not empty or an expired record.
- Import Config: If iCloud did not restore the target rules, open the previously exported configuration from Files and choose to import it into Shadowrocket. Then set it as the current configuration in Config.
- Restore the subscription: For a subscription you already use, re-add or update it with the original URL. Afterward, check the item count and group name; do not judge availability solely by an “Update successful” message.
- Restore the routing mode: Return to Home and set Global Routing to the Proxy, Direct, Config, or Scene mode recorded before migration.
- Rebuild automatic connections: Open Settings → On Demand, review the Wi-Fi and cellular conditions again, and complete authorization as prompted by the system.
Conclusion: restore data before permissions
Restore Home and Config data first, choose the Global Routing mode next, and then establish system VPN and On Demand permissions. This makes it easier to determine whether a problem is missing content, an incorrect rule, or incomplete authorization on the new device.
Verify rules, DNS, and automatic connections after migration
After restoring, do not immediately delete the old device’s content. Temporarily set Global Routing on the new iPhone to Direct and confirm that the local network itself can access the internet; then switch back to the Config or Proxy mode used before migration. If Direct works but Config does not, focus on rule matching, DNS, and the active Config rather than reinstalling the app.
In Config mode, visit one destination that should match DIRECT and another that should match PROXY, then check the matched rules in the app log or request record. If every request falls through to FINAL, check that the domain rules appear before FINAL and that the DOMAIN-SUFFIX domain names are written correctly.
DNS settings can also cause a situation where the app shows as connected but domains do not open. Open Settings and check the DNS items recorded before migration. If an IP address works but the domain fails, check DNS resolution first. Do not change DNS, Config, and server items at the same time, or it will be difficult to tell which change fixed the issue.
Why can’t the new iPhone connect even though the configuration is present?
First confirm that the system has allowed Shadowrocket to add a VPN configuration, then check the selected item and Global Routing in Home. If it is set to Direct, traffic will not follow proxy rules. If it is using Config, continue by checking FINAL and the rule-match records.
What if Config is still empty after enabling iCloud?
Confirm that both devices use the same Apple Account, and check iCloud Drive and Shadowrocket’s iCloud permission in the system. If it is still empty after waiting for sync, import the Config file exported from the old device through Files, then verify the rule order.
Why hasn’t the subscription updated after being added?
First confirm that the URL comes from the account of the service provider you already use and that its credentials are still valid, then update it from Home or the subscription management area. If the request times out on the ordinary network, check whether the app offers an option to update through the current connection, and use the logs to determine whether the issue involves DNS, the network, or authorization.
Why doesn’t On Demand trigger under the previous Wi-Fi conditions?
Open Settings → On Demand, check whether the conditions have synced, and confirm that the new device has completed system VPN authorization. If the Wi-Fi name, cellular condition, or connection action is missing, recreate it from the old-device record instead of simply toggling the master switch.
When can migration preparation end on the old device?
Complete at least three checks: the subscription updates successfully, Config rules match as expected, and On Demand triggers under the configured network conditions. Also confirm that the App Store purchase status is normal and keep a readable copy of the Config file.
Final checks before completing the switch
The final review should cover four layers: purchase, data, rules, and permissions. For the purchase layer, confirm that Shadowrocket came from the App Store. For data, confirm that Home and subscription content are visible. For rules, confirm that Config is selected and FINAL is in the correct position. For permissions, confirm that system VPN and On Demand work as expected.
If the old and new devices are temporarily kept together, avoid editing the same Config on both sides in succession, as it becomes difficult to identify the final version. Choose one device as the current editing device, finish the rule changes, wait for iCloud sync, and export the file again with a date-based filename for archiving.
- The App Store product page lists Shadowrocket, the developer is Shadow Launch Technology Limited, and the app ID is 932747118.
- The current Home item, subscription group, and Global Routing match the old-device record.
- The key DOMAIN-SUFFIX, GEOIP, IP-CIDR, and FINAL rules in Config are in the correct order.
- DNS and On Demand have been checked in Settings, and system VPN permission has been established on the new device.
- Direct, Config, and Proxy modes have each passed one reproducible test for their intended use.
- The Config copy kept in Files opens successfully, and the subscription access credentials are stored in a clearly identified location.