What VpnService permission actually allows

After enabling the proxy in Clash for Android, the client typically calls Android’s VpnService API. Android then shows a “Connection request” or “This app wants to set up a VPN connection” prompt, and a key or VPN indicator appears in the status bar. This permission is not subscription sign-in access or authentication for a traditional corporate VPN; it allows the client to create a local virtual network interface.

Once the virtual interface is established, Android routes the selected apps’ IP traffic to the client. The Clash core then chooses the exit according to rules, policy groups, and proxies in the configuration: connections matching DIRECT go straight to the destination, connections matching a proxy policy use the selected proxy, and requests matching REJECT are blocked. This is similar to desktop TUN mode, allowing browsers, messaging apps, and apps without manual proxy support to use rule-based routing.

Three key facts about the permission prompt

  • Usually, only one VPN can stay active in the same user profile. If a corporate VPN, WireGuard, an ad blocker, or another proxy app is already connected, starting Clash may disconnect it or report that the VPN is already in use by another app.
  • Permission is tracked per app. Android may ask again after the first activation, reinstalling the client, clearing app data, or installing a package signed differently.
  • The system key icon is normal. It indicates that VpnService is running, but does not by itself prove that the proxy is usable. Confirm connectivity with latency tests and by opening real webpages.

How the local VPN relates to remote proxy servers

Android groups this connection under “VPN” in Settings, but VpnService itself only receives traffic on the device. The actual remote connection is established by the proxy server specified in the Clash configuration. In other words, “VPN connected” only means that the virtual interface was created. An expired subscription, an unreachable proxy, incorrect DNS settings, or a mismatched rule can still prevent apps from reaching the internet.

Some clients also offer “proxy-only mode” or local HTTP and SOCKS ports. Common ports include HTTP 7890, SOCKS 7891, and the mixed port 7890; always follow the values in the configuration’s port, socks-port, or mixed-port fields. Manual proxying only covers apps explicitly configured to use that port, while VpnService mode is better suited to device-wide routing. Do not enable both without understanding the traffic path.

Handling the permission prompt and first connection

Recommended first-launch sequence

  1. Import a working subscription or local YAML configuration first, then run a configuration update.
  2. Open the proxy or policy-group page and select a working proxy. A latency result does not guarantee that every website will load, but it helps rule out completely unreachable proxies.
  3. Return to the client home screen and enable the “Service,” “Connect,” or “Start” switch. Button labels may vary slightly between clients.
  4. When Android displays the VPN connection request, verify the app name and choose “Allow.”
  5. Wait for the VPN indicator to appear in the status bar, then open a regular webpage and a site that requires proxy routing to verify the direct and proxy paths separately.

Android clients using the Clash Meta (mihomo) core may label the operating mode “VPN mode,” “TUN,” or “Service mode.” These labels emphasize different aspects, but if the client ultimately calls Android VpnService, Android will show the VPN permission prompt. Some versions also offer app bypass, proxy-only selected apps, IPv6 routing, and system DNS takeover. Keep the defaults during the first connection, then adjust each option after the basic path works.

Allowed, then disconnected immediately

Open Android’s system VPN page first and check for another VPN configured to reconnect automatically. On stock Android 14 and Android 15, the usual path is “Settings” → “Network & internet” → “VPN”; on Samsung One UI, it is commonly “Settings” → “Connections” → “More connection settings” → “VPN”; on other Android skins it may be under “Settings” → “More connections” → “VPN.” Disconnect the old VPN, then return to Clash and start the service again.

If no other VPN is active, the conflict is often caused by “Always-on VPN.” Open the settings beside the old VPN and disable “Always-on VPN” and “Block connections without VPN.” The latter may also be called VPN lockdown; it cuts off all network access when the specified VPN fails to connect. Disable it while troubleshooting, then re-enable it if needed once the configuration is stable.

Notification permission on Android 13 and later

Android 13 introduced runtime notification permission. VpnService permission and notification permission are separate settings, but clients generally need to run as a foreground service and show an ongoing notification. Allow notifications on first launch so you can see the running status, current upload and download speeds, and the stop button. If notification access was denied, go to “Settings” → “Apps” → “Clash client” → “Notifications” and turn on “Allow notifications.”

When notifications are disabled, some systems still let the foreground service run, but the user cannot easily see its status. Other heavily customized Android skins more aggressively restrict invisible background tasks. Therefore, when investigating a disconnect a few minutes after the screen locks, check notification permission, battery settings, and auto-start permission together.

Why battery optimization affects proxy stability

While connected, Clash for Android must continuously maintain the virtual network interface, DNS queries, TCP or UDP sessions, and proxy keepalives. After the screen turns off, Android’s Doze mode defers ordinary background work; customized Android skins may additionally freeze apps, clean up processes, or manage background power use. Once the client process is frozen, the VPN icon may remain briefly while new connections fail, followed by Android removing the VPN entirely.

Typical symptoms and how to interpret them

Symptom Check first How to confirm
Disconnects 5 to 15 minutes after the screen locks Battery optimization and background activity Stable with the screen on, then fails after a consistent period with the screen off
Disconnects immediately after clearing recent apps Task locking and auto-start Stays connected when the app is not cleared from recent apps
Does not recover after restarting the phone Boot launch and auto-start Connects after opening the client manually
Fails only on mobile data Background data and data-saving features Works on Wi-Fi but stops transferring after switching to 4G or 5G
VPN icon is present, but webpages time out Proxy, DNS, and core status Restarting the service restores it briefly, or switching proxies fixes it

The goal of adding the client to the battery whitelist is not unlimited resource usage. It is to prevent the system from misclassifying a persistent network service as ordinary background work that can be deferred. Actual idle power use also depends on the proxy protocol, signal strength, rule complexity, DNS mode, and traffic volume. Maintaining a connection over a weak 4G signal can use more power than a stable Wi-Fi connection, so do not judge it solely by a single ranking on the system battery page.

General Android settings checklist

  • Go to “Settings” → “Apps” → “Clash client” → “App battery usage” and choose “Unrestricted” or “Allow background activity.”
  • Go to “Settings” → “Apps” → “Special app access” → “Battery optimization,” switch to “All apps,” find the client, and choose “Don’t optimize.”
  • Go to “Settings” → “Apps” → “Clash client” → “Mobile data & Wi-Fi,” allow background data, and, when needed, allow “Unrestricted data usage.”
  • Enable client notifications and keep the ongoing foreground-service notification visible.
  • If the system provides auto-start or associated-start permissions, allow the client to start automatically.
  • Lock the client in the recent-apps screen to prevent one-tap cleanup from terminating its process.

Menu names vary across Android versions and manufacturer skins. If you cannot find an option, search the top of Settings for “battery optimization,” “auto-start,” “background activity,” or “unrestricted.” After making changes, lock the screen for at least 20 minutes, then test over both Wi-Fi and mobile data. Do not rely on the VPN icon alone.

Settings paths on Xiaomi, Huawei, OPPO, vivo, and other Android skins

Xiaomi HyperOS and MIUI

  1. Go to “Settings” → “Apps” → “Manage apps” → select the Clash client → “Battery saver,” then choose “No restrictions.”
  2. Go to “Settings” → “Apps” → “Permissions” → “Autostart,” and enable it for the client.
  3. Open recent apps, swipe up on or press and hold the client card, and tap the lock icon to pin the task. On some launchers, pull the card down and tap the lock instead.
  4. Open “Data usage” on the app details page and make sure WLAN, mobile data, and background data are allowed.

On some HyperOS versions, battery controls are under “Settings” → “Battery” → “App battery saver.” If the system still stops the service after the screen locks, confirm that the target app is set to “No restrictions” and disable any option that pauses background activity for it.

Huawei HarmonyOS and EMUI

  1. Go to “Settings” → “Apps & services” → “App launch.”
  2. Find the Clash client and turn off “Manage automatically.”
  3. In the manual management dialog, enable “Allow auto-launch,” “Allow secondary launch,” and “Allow background activity.”
  4. Go to “Settings” → “Battery” → “More battery settings” and check the options related to network connectivity during sleep.
  5. Go to “Settings” → “Mobile network” → “Data usage” → “Network access,” and allow the client to use mobile data and WLAN.

If only “Allow auto-launch” is enabled while “Allow background activity” is off, the client may still be frozen after the screen locks. Check all three permissions together. A one-tap optimization from the system manager may also restore battery warnings, so review App launch again after a system update.

OPPO ColorOS and OnePlus OxygenOS

  1. Go to “Settings” → “Apps” → “App management” → select the client → “Battery usage.”
  2. Enable “Allow foreground activity,” “Allow background activity,” and “Allow auto-launch.” Some versions label the last option “Allow app auto-start.”
  3. Go to “Settings” → “Battery” → “More settings” → “Optimize battery use,” find the client, and choose “Don’t optimize.”
  4. In recent apps, tap the menu in the top-right corner of the client card and choose “Lock.”
  5. Allow background mobile data on the app’s “Data usage” page.

ColorOS “Auto optimize battery use” may tighten background permissions again after an app has been unused for a long time. If disconnects return after a few days, first check whether battery management still allows background activity instead of repeatedly deleting and reimporting the subscription.

vivo OriginOS and Funtouch OS

  1. Go to “Settings” → “Apps & permissions” → “Permission management” → “Auto-start,” and enable it for the client.
  2. Go to “Settings” → “Battery” → “Background power consumption management,” select the client, and set it to “Allow high background power consumption.”
  3. Open recent apps, find the client card, and choose “Lock.”
  4. Go to “i Manager” → “Data management” → “Network management,” and allow WLAN, mobile data, and background network access.

“Allow high background power consumption” is especially important on vivo devices. Despite sounding like a performance mode, it allows persistent network services to keep working after the screen locks. If only auto-start is enabled, background policy may still stop the active VpnService.

Honor MagicOS

  1. Go to “Settings” → “Apps” → “App launch.”
  2. Turn off automatic management for the client, then manually enable auto-start, secondary launch, and background activity.
  3. Go to “Settings” → “Battery” → “More battery settings” and check the sleep network settings.
  4. Allow background data under “Data usage” in the app details.

MagicOS uses app-launch management logic similar to some EMUI versions. If the service exits frequently after a system upgrade, reopen this page and confirm manual management, since system migration or reinstalling the app may restore the default policy.

Samsung One UI

  1. Go to “Settings” → “Battery” → “Background usage limits” → “Never auto sleeping apps,” and add the Clash client.
  2. Go to “Settings” → “Apps” → select the client → “Battery,” and choose “Unrestricted.”
  3. Go to “Settings” → “Connections” → “Data usage” → “Allowed networks for apps,” and confirm that background data is available.
  4. Check “Settings” → “Connections” → “More connection settings” → “VPN” and rule out other always-on VPNs.

Troubleshooting app-specific proxying, DNS, and background disconnects together

Confirm the app scope first

Many Android clients let you choose “Bypass selected apps” or “Proxy selected apps.” These modes are opposites: the first sends listed apps directly to the internet, while the second sends only listed apps into VpnService. If a browser works but one app always connects directly, check whether that app is excluded before editing the rules file.

System components can also affect sign-in and push notifications. For example, an app may complete OAuth sign-in in an external browser. If the main app uses the proxy while the browser bypasses it, the sign-in page and callback may use different networks. During troubleshooting, temporarily disable app-specific filtering so every app enters the VPN; once it works, add apps to the bypass list one at a time.

VPN connected, but domains do not open

Test an IP address and a domain separately first. If the proxy returns a latency result, IP connections work, but domain requests time out, focus on DNS. With the mihomo core, common fields include dns.enable, nameserver, fallback, enhanced-mode, and fake-ip-range. YAML indentation must be consistent, and the hyphen before each list item must not be omitted.

dns:
  enable: true
  ipv6: false
  enhanced-mode: fake-ip
  fake-ip-range: 198.18.0.1/16
  nameserver:
    - 1.1.1.1
    - 8.8.8.8

This example only illustrates the field structure; it does not mean every network should use the same DNS servers. If the subscription provider supplies a complete DNS section, keep that configuration first. Android’s “Private DNS” can also interfere with the client’s DNS handling. If resolution behaves abnormally, temporarily go to “Settings” → “Network & internet” → “Private DNS,” select “Automatic,” and compare the results.

Use system information to check whether the process was terminated

If you have access to a computer for debugging, use ADB to inspect VPN and process status. Enable USB debugging in Developer options, then run the command below. Output fields vary across Android versions; focus on whether the current VPN package, foreground service, and process still exist.

adb shell dumpsys connectivity
adb shell dumpsys activity services
adb shell dumpsys deviceidle
adb shell pidof client package name

If pidof returns a process ID before the screen locks but returns nothing afterward, the system has usually terminated the process. If the process and VPN interface still exist but traffic no longer increases, check the proxy session, DNS, or core logs. A timeout entry usually points to a connection timeout; configuration parsing errors mean you should return to the YAML and inspect its fields and indentation.

Stable operation and routine checks

After granting permission and configuring the whitelist, run a fixed test sequence: connect to Wi-Fi, start the service, and open a webpage; lock the screen for 20 minutes and test again; switch to 4G or 5G, wait 30 seconds, and test; return to the client from recent apps and confirm that the service status and traffic counters are still updating. If all four steps pass, VpnService, background permissions, and network switching are basically stable.

System permissions worth keeping enabled

  • VPN connection permission, to create the local virtual network interface.
  • Notification permission, to show foreground-service status and controls.
  • Background activity and battery-optimization exemption, to maintain the connection while the screen is locked.
  • Auto-start permission, to restore the service according to the client’s settings after a reboot.
  • Background data permission, to keep the client online over mobile data and in data-saving modes.

Do not change every setting at once when the connection is unstable

Change one variable at a time and record the test time. Disconnect other VPNs first, then set battery usage to “Unrestricted” and test with the screen locked; only if it still disconnects should you enable auto-start and task locking. If the network works but specific websites fail, investigate rules and DNS instead of adding more system permissions. This separates system process killing, proxy failures, and configuration errors.

After updating the client, upgrading Android, or reinstalling the app, review VPN permission, notifications, battery policy, and auto-start status. Android may preserve some permissions or manage the app as new. Subscription updates usually do not change system permissions, but they may alter policy-group names, the DNS section, or rule order. If only certain apps misbehave after an update, compare the configuration changes first.

A complete stable setup comes down to four points: let the current Clash client own the system VPN; allow the foreground service to show notifications; add the client to the battery and background-activity allowlists; and test Wi-Fi, mobile data, and screen-locked scenarios separately. The VPN icon is only the starting point—ongoing traffic, correct routing, and reliable DNS resolution are the final checks.