How to Set Up a Trojan Server in Shadowrocket: Password, SNI, and TLS Settings

Learn how Trojan uses TLS and how to enter Address, Port, Password, and SNI in Shadowrocket’s Add Server screen, including common mistakes.

At a glance

If you already have Trojan connection details, start by checking Address, Port, and Password, then enter SNI and any other TLS settings as specified by your provider. This guide covers manual setup, verification, and troubleshooting. Field names may vary by app version.

What to check first for a Trojan connection

Trojan uses TLS to establish a connection. In a Shadowrocket server entry, Address and Port specify the connection destination, while Password provides the authentication value agreed on with the server. SNI is the server name sent during the TLS handshake. Each field serves a different purpose: a reachable Address and Port do not guarantee that Password or the certificate name is correct.

Find the complete settings in your existing service details. Don’t guess the port based on the protocol, and don’t use a subscription URL as the server Address: a subscription URL retrieves configuration, while the server Address identifies the actual connection destination. If your details only include an import link and not individual parameters, import it as provided, then review the resulting entry in the app.

4 fields
Check Address, Port, Password, and SNI first
443
Examples of common TLS ports—not fixed Trojan ports
1–65535
Valid numeric range for TCP Port
2 fields
Check the connection destination and TLS server name separately

Enter each field in Add Server

Manual setup is for cases where you have the server fields. In Shadowrocket, open Home, tap the “+” in the upper-right corner to open Add Server, and set Type to Trojan. Then enter the values from your own service details. Field order may vary between app screens; if some options are collapsed, expand the TLS settings and check them there. Don’t guess values for parameters that weren’t provided.

  1. Gather your connection details

    Have your Trojan server address, port, and Password ready, along with any SNI or additional TLS parameters listed in your details. Keep server settings separate from the subscription URL.

  2. Choose Type

    In Home → “+” → Add Server, set Type to Trojan. Don’t select a different protocol just because your details mention TLS.

  3. Enter the destination

    Enter the server hostname or IP in Address, and the specified number in Port. For example, use 443 only if your details say so; the port cannot be inferred from the protocol.

  4. Check authentication

    Enter the value provided by the server in Password, preserving capitalization and removing any extra spaces introduced when copying. If your details specify an SNI, enter it in the corresponding TLS field.

  5. Save and test

    Save the entry, return to Home, select the server you just added, and test the connection. If it fails, compare Address, Port, Password, and SNI with your original details, in that order.

The example domain example.com is only there to illustrate the field format; it is not a server you can connect to. Use the values from your own connection details. In particular, don’t paste a full webpage address, including https://, a path, or query parameters, into the Address or SNI field when it asks for a hostname.

Common mistakes with Address, Port, and Password

Address is the network connection destination. It can be a domain or an IP, as specified in your service details; it is not the same as SNI. Preserve the full domain name—for example, edge.example.com and example.com are different names. If your details give an IP for Address and a domain for SNI, enter each value in its own field rather than using the same value for both.

Port is a numeric port. Port 443 is commonly used with TLS, but a server can use another port. The port used by a subscription website, an admin panel, or an example configuration does not replace the port actually set on the server. Check Port alongside Address: different ports on the same domain may lead to different services.

FieldWhat to enterCommon mix-up
AddressThe hostname or IP specified in the server detailsPasting a subscription URL or webpage address with a path
PortThe port number paired with that AddressChanging it to 443 just because the protocol is Trojan
PasswordThe complete authentication value for that server entryMissing characters or including spaces at either end when copying
SNIThe TLS server name specified in your detailsMistaking it for Password or automatically copying Address

Password must match the value agreed on with the server, including capitalization, symbols, and length. If the connection fails after pasting it, check for a leading or trailing newline or space, then make sure you haven’t used your account login password instead of the Trojan Password. Never show the full Password in a public screenshot or support request.

Troubleshooting order: check the destination first

If Address or Port doesn’t match the current server, changing SNI or Password won’t fix the wrong destination. First confirm that Address and Port come from the same set of details, then check the TLS and authentication fields.

How SNI relates to TLS settings

SNI is the server name sent during the TLS handshake. It is usually a domain name that lets the server identify which name and certificate to use; it is not a full URL entered in a web browser. If your details specify an SNI, use that exact value. If they don’t, don’t guess based on a service name or subscription domain—check with the source of your connection details for the settings required by that server entry.

Certificate validation checks whether the certificate presented by the remote endpoint matches the expected name and other requirements. If you see a name mismatch or validation error, first check SNI, your device’s date and time, and any TLS settings specified in your details. Also confirm that the server’s certificate is valid. Skipping certificate validation removes this identity check and should not be treated as a routine troubleshooting step.

Change one setting at a time when troubleshooting, then save and test again. Note what happened before and after each change. If you replace Address, SNI, and TLS options all at once, you won’t know which setting was originally wrong—even if the connection starts working.

Troubleshoot by symptom after saving

A connection test and actual traffic routing are two separate things. First, select the Trojan entry you just saved on Home and check whether the test reaches the server. Then check the connection toggle and Global Routing. If Global Routing is set to Direct, the app handles traffic as a direct connection; saving a server entry alone doesn’t mean it is carrying web requests. Check the active configuration or scene as well when using Config or Scene.

Still can’t connect with Port set to 443?

Check Port against your original details. 443 is only a common example. Also check Address for an extra protocol prefix, slash, or space.

Seeing a TLS or certificate error?

Compare SNI character by character with the domain specified in your details, check your device’s date and time, and verify the listed TLS parameters. If it still fails, confirm the server’s certificate status.

The test passes, but web traffic doesn’t use this connection?

First confirm that this server is selected on Home, then check whether Global Routing is set to Direct. If you’re using Config or Scene, also check the relevant rules and scene settings.

There’s already an entry with the same name in your subscription. Should you add one manually?

Check whether the imported subscription entry already has complete settings. Manual setup creates a separate entry. After updating the subscription, make sure you know whether you’re testing the subscription entry or the one you added manually.

If you already have a subscription and the connection starts failing after an update, first check whether the selected server entry changed, then compare the visible fields before and after the update. A subscription URL such as https://example.com/sub?token=xxxx is only a format example and should not be entered in Trojan’s Address field. Check the subscription content and manually added entries separately to avoid mistaking an import issue for a TLS problem.

What to keep after checking the settings

Keep a record of the fields without including Password: note that Type is Trojan, how Address and Port correspond, whether SNI was explicitly specified in your details, and which Global Routing setting was active during testing. If you need to contact the provider of your connection details, describing a specific symptom—such as “connection destination unreachable,” “TLS name mismatch,” or “test passes but routing is Direct”—is more useful than simply saying it doesn’t work.

Finally, reopen the saved entry and check that Address, Port, Password, and SNI still match your own details. If the server settings have changed—such as the port, authentication value, or certificate name—update the entry using the latest details. An entry appearing on Home doesn’t mean its settings still match the current server.

More on Shadowrocket and getting started

Check the App Store listing on the official listing verification page, then follow the guide to review where to add a server and how to configure the connection in the app.

Visit the official listing verification page View the guide
Verify the official App Store listing