Guides About 9 minutes

What Is a Subscription Link? How to Get, Import, and Update It

Learn what subscription links do, how to get one after signing in, import it into a client, update it, and respond if it is exposed.

A subscription link is the entry point a client uses to read route configurations. The server usually generates it, and the client uses it to retrieve node names, server addresses, ports, protocol parameters, and routing information. Instead of entering each setting by hand, copy the link from the account panel and import it into a compatible client to load the currently available routes.

A subscription link is neither a fixed route nor a connection protocol. It is better understood as an updatable configuration list: after the server changes its routes, the client can refresh the subscription and retrieve the list again. This distinction helps separate subscription update failures, node connection failures, and website access issues, so there is no need to keep deleting and reinstalling the client.

Key distinction The subscription distributes configuration, the protocol establishes the connection, the route type determines how traffic travels, and routing rules decide which requests use that connection. These concepts are related, but they are not interchangeable.

What a Subscription Link Contains—and What It Does Not

After requesting a subscription link, a client may receive a general collection of links or a structured configuration recognized by clients such as Clash and sing-box. The exact format depends on both the server and the client. An account panel may offer several formats; choose the one the client explicitly supports rather than copying any button labeled “subscription.”

A subscription typically describes route names, access addresses, ports, transport methods, encryption or authentication parameters, and labels used when the client builds proxy groups. Some formats can also carry rule groups, remote rule URLs, and DNS recommendations. Whether complete routing rules are included depends on how the server generates the subscription; some subscriptions provide nodes only, leaving routing to the client’s local configuration.

Common protocols include Shadowsocks, VMess, Trojan, VLESS, Hysteria2, and TUIC. A protocol name may appear in the subscription output, but the subscription link itself does not “run” these protocols. The client first parses the subscription, then creates a connection for each node using its associated protocol. If the client lacks support for a protocol or its required transport parameters, the node may remain unusable even when the subscription downloads successfully.

Concept Primary function Common symptoms
Subscription link Distributes nodes and configuration to the client Update failure, empty content, or incompatible format
Connection protocol Defines how the client communicates with the server Handshake failure, authentication failure, or unsupported client
Network route Determines the actual path traffic takes Speed, stability, and detours vary by time of day
Routing rules Determine whether a request connects directly, uses a proxy, or is rejected Some websites use the wrong exit route, or local services behave unexpectedly
DNS settings Resolve domain names to network addresses Resolution failure, inconsistent regional results, or leakage

A subscription generally does not save every preference configured in the client interface, such as startup behavior, local listening settings, the system proxy switch, or custom rules. When a subscription is updated, the client may replace subscription-generated nodes and proxy groups, but it usually will not correct every local setting automatically. If behavior changes after an update, check both the subscription content and the client’s local configuration.

How to Get a Subscription Link After Signing In

The safest way to get a subscription link is to enter the account panel through the official service website and choose a format that matches the client you use. Do not obtain links from chat history, cached search results, or pages forwarded by others: they may be outdated or unsuitable for your client.

  1. Open the ijvpn official website, go to the user panel, and sign in.
  2. Open the subscription or download section and confirm the operating system and client type you plan to use.
  3. Choose a subscription format supported by the client, then use the copy function to save the complete link.
  4. Switch to the client and add it through “Import from link,” “Remote configuration,” or a similarly named option.
  5. After the first update completes, check that the node list appears and confirm the proxy mode and routing strategy.

Do not manually trim the link when copying it, and do not remove trailing characters that appear meaningless. Subscription addresses often contain tokens used to identify account permissions; omitting any part can cause authentication to fail. If the panel offers a QR code, it usually encodes the same subscription information for easier scanning and does not change the subscription permissions.

Treat a subscription link as part of your account credentials. Do not publish it in public posts, screenshots, code repositories, cloud documents, or notes visible to multiple people. When describing an issue to support, provide the error message and non-sensitive excerpts from the client log instead of pasting the complete subscription address.

Check the format before copying A client being able to open a link does not mean it can parse every node inside it. If the panel offers both a general subscription and a dedicated configuration, prefer the type explicitly listed as supported in the client documentation.

Import Differences Across Windows, macOS, Android, and iOS

The labels differ by platform, but the basic process is the same: create a remote configuration, paste the subscription link, update it, choose a node, and enable the system proxy or virtual network interface mode as needed. What matters is not where the button appears, but which configuration formats and protocols the client supports and how it takes control of network traffic.

Desktop Platforms: Choose Between a System Proxy and a Virtual Network Interface

Windows and macOS clients often provide both system proxy and virtual network interface modes. A system proxy mainly affects apps that follow the operating system’s proxy settings; it is simple to configure, but some software ignores those settings. Virtual network interface mode can handle a broader range of network requests and suits unified routing, but it usually requires additional system permissions and is more likely to conflict with other network tools, enterprise security software, or existing virtual interfaces.

After importing on desktop, first check when the remote configuration was last updated successfully, then open the node list. If nodes are present but the browser cannot access websites, check whether the system proxy is enabled, whether the routing mode is correct, and whether the browser has its own proxy setting. Do not assume that every system request uses the selected route merely because the client shows “Connected.”

Mobile Platforms: Check System Permissions and Background Limits

Android and iOS clients usually take control of traffic through the VPN interface provided by the system. The first connection requires confirmation of network configuration permission. If the connection frequently drops when switching apps after importing a subscription, check background activity limits, battery-saving policies, and network switching behavior before assuming the subscription has failed.

Importing from a QR code is convenient on mobile, but scan only content displayed directly in the account panel. If the QR code is saved in a photo library or synced to a shared space, it carries the same risk as publishing the complete link. After changing devices, get a fresh link from the panel instead of relying on an old screenshot.

Client Compatibility Matters More Than Similar Interfaces

Even when different clients all support “subscriptions,” their support for protocols, transport layers, and rule syntax may differ. A client that reads Shadowsocks and Trojan may not support VLESS, Hysteria2, or TUIC nodes in the subscription; supporting a protocol name does not guarantee compatibility with every extension parameter. If some nodes disappear, first check the client’s version notes and the subscription format before importing it again.

When Should You Update a Subscription?

A subscription does not need to be updated before every connection. Normally, the client keeps the last successfully retrieved configuration and may continue using its locally stored nodes even when the subscription server is temporarily unreachable. The main purpose of an update is to retrieve route changes, renamed nodes, changed protocol parameters, and configurations that have been withdrawn.

You can update the subscription when the account panel reports configuration changes, the node list differs from the panel, several nodes show authentication issues at once, or you are returning to a client that has not been updated for a long time. A single inaccessible website, a speed change on one route, or occasional packet loss on the current network is not necessarily related to the subscription version; repeated updates usually will not fix a route-level problem.

When an update fails, first determine whether it is a “download failure” or a “parsing failure.” Download failures are usually related to the current network, DNS resolution, system time, an expired link, or access permissions. Parsing failures are more likely caused by an incompatible subscription format, truncated content, or a client version that cannot recognize new fields.

How to tell: If old nodes still appear but updating reports a network error, check the subscription access path first. If the subscription downloads but no nodes appear or a format warning is shown, check client compatibility first. If the update succeeds but one route cannot connect, investigate the protocol, route, and local network instead.

How Do Direct, Relay, and IEPL Routes Differ?

Node names in a subscription may identify direct, relay, or IEPL routes. These terms describe network paths, not subscription formats. A direct route usually means that the user’s network connects straight to an overseas server. The path is simpler, but its actual quality depends more heavily on the public routing between the local carrier and the destination region.

A relay route first reaches a nearby entry point or one with more suitable routing conditions, then travels through the relay network to the exit. This is generally intended to improve public-network detours or cross-network connectivity, but a relay is not automatically faster. The entry location, exit location, current network, and time of use all affect the result.

IEPL is commonly used to describe an enterprise-grade international private line or a related transport method, with a different path structure from an ordinary public-network connection. For most users, a more practical approach is to consider the destination region, application type, and actual connection performance rather than judging quality by the label alone. Route labels cannot replace local testing, because the same route may perform differently on different access networks.

When choosing, narrow the options by region and purpose first, then compare actual access. Text and web browsing prioritize stable connections and reliable resolution. Meetings, real-time collaboration, and continuous uploads are more sensitive to jitter and interruptions. Large file transfers are often affected by local bandwidth, server-side limits, and the cross-border path together. A subscription provides selectable configurations, but it cannot remove these objective network conditions.

How to Check Routing Rules and DNS Leaks

After importing a subscription, you usually still need to choose a running mode such as global, rules, or direct. Global mode sends more requests through the proxy route and is useful for briefly isolating routing errors. Rules mode chooses a path based on domain, network address, or application matches and is better suited to everyday use. Direct mode typically pauses proxying while retaining the client configuration.

Common signs of a routing error include an international website not using the selected route, a local service being sent to an overseas exit, or different resources on the same page taking different paths. Temporarily switch to global mode for comparison. If global mode works but rules mode does not, the issue is usually in rule matching, rule versions, or DNS results rather than in the subscription itself.

A DNS leak occurs when domain queries are not handled through the intended path and are instead sent to a resolver you did not intend to use. This can produce inconsistent regional results, mismatch domain resolution with the proxy exit, or expose the resolver environment used by the local network. To avoid this, keep the client’s DNS mode, routing rules, and system network takeover method consistent.

Changing only the system DNS does not necessarily solve the problem: the browser may have its own encrypted DNS, and the client may also include a separate DNS module. Check the client DNS settings, the browser’s independent settings, the system network configuration, and whether virtual network interface mode is actually handling queries. After making changes, clear old DNS caches and reconnect so cached results are not mistaken for the current configuration.

What to Do If a Subscription Link Is Exposed

If a complete subscription link appears in a public screenshot, shared document, public repository, or a message with an uncertain audience, treat it as exposed credentials. Deleting the public content alone is not enough because the link may already have been copied or cached. The safest response is to open the account panel and use its reset, regenerate, or revoke-old-link function so the original token becomes invalid.

After resetting it, copy the new link from the panel and replace the old subscription in your own client. Some clients bind remote configurations to local names, so editing the address is enough; others require deleting the old remote configuration and importing it again. Update after replacing it, confirm that nodes are retrieved normally, then clear notes, synced clipboard history, and old QR codes.

If the panel has no clear reset option, submit a ticket through the support page explaining that the subscription link may have been exposed and asking for the old credential to be revoked. You do not need to include the complete old link; provide account details that can identify the subscription and describe how it was exposed.

Do not just rename the client entry Renaming a remote configuration does not change the server-side token or invalidate a link that has already been exposed. The effective response is to revoke the old subscription credential and import the new link on controlled devices.

Troubleshooting Order for Subscription Update Failures

Effective troubleshooting starts at the subscription layer and then moves through the client, protocol, route, and target website. Change one condition at a time so you can identify which setting made a difference. Repeatedly toggling multiple switches, deleting every configuration, or changing clients at the same time removes useful points of comparison.

  1. Return to the account panel, confirm that the subscription is still available, and copy the complete address again.
  2. Try updating on the current network and note whether the client reports a network, authentication, or parsing error.
  3. Confirm that the import format matches the client and check whether the client supports the protocols included in the subscription.
  4. After a successful update, choose one route to test basic connectivity without first adding complex custom rules.
  5. Once basic connectivity works, restore routing and then check DNS, the browser’s independent proxy, and the system takeover method.
  6. Only when several routes show the same behavior should you check the local network, system time, firewall, and conflicts with other network tools.

If the subscription updates, nodes connect, and only a specific website behaves unexpectedly, the cause may be the site’s regional policy, cache, account region, browser environment, or routing result. Resetting the subscription again is unlikely to help. Compare different routes in a cache-free session and confirm that the site’s requests actually use the expected exit.

If client logs contain server addresses, authentication fields, or subscription tokens, redact them before submitting. The error type, stage, and sequence of events are usually enough to locate the issue. Never post complete sensitive configuration in a public discussion area.

Safer Everyday Subscription Link Practices

Subscription links reduce manual configuration and keep route information up to date, but that convenience depends on using a compatible client and managing credentials carefully. In daily use, get configurations from the official panel, choose a supported format, and update when needed instead of leaving the link scattered across multiple tools.

When moving to a new device, sign in to the panel and get the subscription again. Before decommissioning the old device, delete its remote configuration. When sharing networking experience, show only the protocol type, error details, and settings that contain no credentials. If you suspect the link has left your control, resetting it is safer than waiting for suspicious activity.

Remember that a successful subscription update only means the client obtained the configuration. It does not mean every route, protocol, or website will produce the same result on the current network. Evaluate the subscription, client compatibility, route path, routing, and DNS separately to find the real source of the problem quickly.

Conclusion: A subscription link is an entry point for distributing configuration. The correct process is to get the matching format from the account panel, import it into a compatible client, update it as needed, and treat the link as sensitive credentials. When something fails, first identify whether the issue is downloading, parsing, connecting, or routing, then take the appropriate action.
Start Free