What the “VPN Configuration” Prompt Means: iOS VPN Entries and Toggles

The “VPN Configuration” prompt that appears on your first connection comes from iOS, not from any setting inside Shadowrocket. This article explains what the prompt does, where the matching entry lives in Settings, and what happens if you tap Don’t Allow or delete the configuration.

In brief

The first time you flip the connection switch in Shadowrocket, iOS shows a system prompt asking to add a VPN configuration. This article covers who generates that prompt, what entry appears in Settings after you tap Allow, how it relates to the Home toggle, and what happens if you tap Don’t Allow or delete the configuration — useful if you have just installed the app or are troubleshooting a connection problem.

Who shows the prompt: system dialogs vs. in-app settings

The first time you turn on the connection switch on Home, the dialog that appears is generated by iOS: the title reads something like “Shadowrocket” Would Like to Add VPN Configurations, the body explains that network activity on the device may be filtered or monitored while a VPN is in use, and the bottom offers two buttons, Don’t Allow and Allow. It is not part of the Shadowrocket interface, and it does not mean you accidentally tapped one of the app’s settings.

This prompt comes from the iOS network extension mechanism: any app that wants to take over traffic at the system level must first have a VPN configuration written by the system, which then establishes the tunnel. The app can only make the request — the prompt text and the authentication (device passcode, Face ID, or Touch ID) are handled by the system. The device name and the phrase “all network activity” appear in the prompt precisely because it describes system-level behavior, not a feature inside one app.

App requests a connectionSystem shows the promptAllow and authenticateVPN configuration is writtenSystem establishes the tunnel

After you tap Allow and complete authentication, the configuration is written to the system and the tunnel comes up right away: the status line at the top of Home switches to connected, and the VPN icon appears in the top-right corner of the status bar. The same configuration is not requested again on later connections.

How to tell them apart: a dialog whose title includes the app name and whose buttons are Don’t Allow / Allow is a system dialog; switches, lists, and settings inside the app never appear in that form.

After you allow: the matching entry in Settings

Once authorization is complete, the system stores a VPN configuration belonging to Shadowrocket and creates a matching entry in Settings. On iOS 15 and later the path is Settings → General → VPN & Device Management → VPN; on earlier versions this item sits directly under Settings → General → VPN. The entry in the list is usually named after the app, with a status line on the right showing Connected or Not Connected.

Also, as long as any VPN configuration exists on the device, a VPN row appears on the main Settings screen below Personal Hotspot, so you can check the current status without drilling into submenus.

  1. Open the settings path

    Settings → General → VPN & Device Management → VPN opens the list of VPN configurations.

  2. Check the entry name

    Find the configuration named Shadowrocket: a status line reading Connected means the tunnel is running, while Not Connected means it is not.

  3. View configuration details

    Tap the info button (i) to the right of the entry to see basic details for the configuration and the Delete VPN option.

  4. Note where to delete

    Delete VPN removes the whole configuration; before doing so, the system asks for your device passcode or Face ID / Touch ID verification.

One thing to keep in mind: the system entry only records which app provides the tunnel and its current status. It does not contain subscription URLs, rule files, or server details — all of that stays inside the app. If other apps on the device have also created configurations, the list will show several entries, so check names and sources when you compare them.

How the switches relate: the Home toggle and the system VPN row control the same tunnel

The connection switch at the top of Home and the VPN row in Settings control the same tunnel. Turn the switch on in the app and the system entry changes to Connected; turn it off in Settings and the in-app switch flips back to off, with the Home status line following to not connected. The two are simply two views of one state — there is no in-between state where the app is connected but the system is not.

The reverse also works: the switch in Settings can start the tunnel on its own. As long as the configuration exists, you can turn the VPN on from Settings without opening Shadowrocket, and traffic is still routed by the rules saved in the app. On Demand builds on the same foundation — Settings → On Demand inside the app defines the network conditions under which the system starts this tunnel automatically, and it is the system, not the app interface, that carries it out.

2 entry points
The Home toggle and the VPN row in Settings control the same tunnel
1 authorization
Each configuration only needs to be allowed once; the prompt returns only after you delete it
iOS 15+
The path is Settings → General → VPN & Device Management → VPN

The VPN icon in the top-right corner of the status bar is the third thing to watch: when it appears, the tunnel is active; when it disappears, the tunnel is down. During troubleshooting, read all three together — the Home status line, the Settings entry, and the status bar icon — to quickly tell “the tunnel never came up” apart from “the tunnel is up but routing or the server is the problem.”

What happens after you tap Don’t Allow or delete the configuration

Tapping Don’t Allow in the system dialog writes no configuration at all, and the connection switch returns to off on its own; subscriptions, rules, and settings already saved in the app are unaffected. When you want to connect again, flip the switch back on, the same prompt appears, and you can choose Allow.

You tapped Don’t Allow in the prompt and the Home switch snapped back to off

Cause and fix: there is no usable VPN configuration on the device, so the app cannot start a tunnel — turn the switch on again, choose Allow in the system prompt, and complete passcode or biometric verification.

The VPN icon in the status bar disappears and an established connection drops

Cause and fix: the tunnel was shut down on the system side, most often because the VPN was turned off manually in Settings or the configuration was deleted — first confirm the entry exists in Settings and shows Connected. If the tunnel is fine but pages will not load, check whether Global Routing is stuck on Direct.

After deleting the VPN configuration, the switch turns on and immediately flips back off

Cause and fix: deleting removed only the system-side tunnel authorization; app data is still there, but no tunnel can be established — turn the switch on again, choose Allow in the system prompt, and the configuration is written again.

The “VPN Configuration” prompt keeps reappearing within a short time

Cause and fix: the previous verification was not completed, or several entries with the same name exist on the device — delete the extra entries in Settings → General → VPN & Device Management → VPN, then authorize once more.

Allow is a system-level authorization, and it is a separate matter from payment: Shadowrocket itself is a one-time purchase client, purchase records are managed by your Apple ID, and deleting the configuration does not change what you own. The one-time client purchase and any server plan are two independent expenses, and the authorization prompt involves neither.

If the tunnel is running when you delete the configuration, the connection drops immediately. Once deletion is complete, the subscriptions, rules, and server list inside the app are untouched, and everything works as before after you authorize again.

Reinstalling, switching devices, and On Demand: when the prompt comes back

The system stores the authorization only for this configuration on this device. When you uninstall the app, the system removes the VPN configuration it created as well; after reinstalling, the prompt appears again on the first connection — this is normal, it does not mean the authorization failed, and it has nothing to do with your purchase status.

Moving to a new iPhone or iPad works the same way: the new device has no existing configuration, so you must allow it once on the first connection. You can download the app again from your App Store purchase history with the Apple ID you bought it with, at no extra charge.

On Demand rules are stored inside the app, but they only take effect through the VPN configuration in the system: once the configuration is deleted, On Demand will not trigger any connection; after you authorize again, the rules keep working under the conditions saved in Settings → On Demand.

Do I have to allow it again every time I open the app?

No. A given VPN configuration is authorized only once; the system shows the prompt again only after you delete the configuration, reinstall the app, or move to a new device.

If I turn off the VPN in Settings, do I lose the rules in the app?

No. Turning it off only stops the current tunnel; rules, subscriptions, and settings all stay in the app, and routing continues under the same rules when you turn it back on.

How do I revoke this authorization completely?

Go to Settings → General → VPN & Device Management → VPN, tap the info button (i) next to the Shadowrocket entry, choose Delete VPN, and verify your identity. Data inside the app is unaffected, and the next connection will ask for authorization again.

After I tap Allow, where does my traffic go?

The prompt grants the system permission to use the tunnel provided by Shadowrocket; where traffic actually goes is decided by the servers and rules you configure in the app, and the prompt itself changes no server settings.

I switched to a new iPhone — why does the prompt appear again?

The new device has no existing VPN configuration, so the first connection always prompts again; restore the app from your App Store purchase history with the Apple ID you bought it with, then authorize once.

Get Shadowrocket on the App Store

A paid app with a one-time purchase, sold only on the App Store; developer Shadow Launch Technology Limited, app ID 932747118.

Verify the official app View the quick start guide
Verify the official App Store version