In simple terms, a subscription link is the configuration gateway between your account panel and a proxy client. After reading the link’s response, the client can identify available routes, server addresses, ports, protocols, and connection settings. It is not a regular web bookmark or merely a download URL. Understanding its role helps prevent failed imports, stale server lists, and accidental exposure.

For beginners, “account login,” “subscription link,” and “single-server configuration” are easy to confuse. Your account gets you into the service panel; a subscription link passes a set of configurations to the client; a single server entry represents one connectable route. In most cases, you do not need to enter server parameters manually—copy the subscription link from the panel and let a compatible client parse it.

What exactly is inside a subscription link?

A subscription link is usually a web address containing unique credentials. When a client requests it, the server returns organized configuration data. Services and clients do not all use the same format, but the purpose is the same: deliver a server list and the parameters needed to connect.

The configuration may include route names, entry servers, ports, encryption or authentication settings, transport methods, and labels that identify regions or route types. Once parsed, the client usually shows cities, countries, or intended uses rather than raw parameters. When the service changes an entry point or configuration, updating the subscription retrieves the new list.

A subscription link is not a network protocol. Shadowsocks, VMess, Trojan, VLESS, Hysteria2, and TUIC are different connection protocols or protocol families; the subscription simply passes their configurations to the client in bulk. Whether a route works depends on the client supporting that protocol and its transport settings.

Item Primary purpose Suitable for public sharing Common actions
Account panel Manage plans, retrieve configurations, and handle service matters Not suitable Sign in to the user panel
Subscription link Provide a complete set of route configurations to the client Not suitable Copy, import, update
Single server entry Provide connection parameters for one route Not suitable Import separately or troubleshoot temporarily
Client configuration name Help identify local configuration groups Usually does not contain complete credentials Rename, sort, switch

Some links show a long string of text when opened in a browser, some trigger a download, and others display an error because the request method is not supported. That does not necessarily mean the link is invalid. Subscription data is primarily meant for clients to read, not for presentation as a human-friendly webpage. When troubleshooting, start with the client and import method recommended by the service panel.

Get your subscription from the user panel and store it securely

The reliable place to get a subscription is the service’s own user panel—not search results, unfamiliar tutorial attachments, or configurations forwarded by someone else. After signing in, look for a subscription, client download, or connection configuration section with a copy option. JrVPN does not require an email address when you get started; once you complete the panel flow, follow the page instructions to obtain the client and subscription configuration.

Before copying the link, make sure no shared tool on the device is set to read the clipboard automatically. Do not display the full page during a livestream, screen recording, or remote presentation. If you need to contact support, provide the client name, operating system, and error message; unless the ticket process specifically asks for it, do not paste the complete subscription URL.

“Subscription conversion” means converting one configuration format into another that a different client can read. The process must access the original subscription data, so the converter’s trust boundary matters. Prefer a compatible format provided directly by the service panel, or convert it locally with a trusted tool. Do not hand real credentials to an unknown website just to save one step.

Bottom line for beginners: Choose the client first, then copy the subscription format that matches it. Do not grab a link and repeatedly submit it to different conversion sites; that increases exposure and makes it harder to identify where the problem occurred.

Import your subscription link into clients on different platforms

Platform interfaces vary, but the import flow is broadly the same: install a compatible client, open its subscription or configuration-group section, paste the link, update it, and choose a server from the resulting list. A successful import only means the client received the configuration; it does not confirm that system traffic is using the selected route as intended. Check the connection status and routing results afterward.

  1. Copy the subscription link that matches your current client from the user panel.
  2. Open the client’s subscription manager, configuration manager, or remote-configuration page.
  3. Choose import from a link and paste the address you just copied.
  4. Save the configuration, run an update, and wait for the client to parse the server list.
  5. Choose a route for your current use case, then set global proxying, rule-based routing, or proxying for selected apps as needed.
  6. After connecting, check the exit address, DNS resolution path, and whether the target app follows the intended rules.

Importing on Windows and macOS

Desktop clients typically offer more complete subscription management and routing options. After importing, check the differences between the system proxy, virtual network adapter mode, and rule mode. The system proxy mainly affects apps that follow system proxy settings; virtual adapter mode can handle more types of traffic but is also more likely to conflict with security software, other network tools, or enterprise policies.

A macOS client may request system authorization the first time you enable its network extension, which is required to create a system-level network tunnel. A Windows client using virtual adapter mode may likewise need to install a supporting component. If the connection fails, do not repeatedly delete the subscription. First check system permissions, the active mode, and conflicts with other proxy tools.

Importing on Android and iOS

Mobile clients generally use the system VPN interface to handle traffic. A common advantage of Android clients is per-app proxying, which lets you choose which apps use a route and which stay on the local connection. Wording for options such as “bypass local network,” “proxy selected apps only,” and “exclude selected apps” may differ or even be reversed between clients, so read the option descriptions before enabling them.

iOS clients are constrained by the system network-extension framework. After importing a subscription, allow the client to add a VPN configuration. If the server list is present but an app still cannot reach its target service, check rule mode, DNS settings, and whether another network extension is enabled instead of assuming the subscription link is invalid.

Platform Common names for the import entry What to check after importing Common differences
Windows Subscription management, remote configuration System proxy, virtual adapter, and firewall Usually offers more routing modes
macOS Configuration, subscription Network-extension authorization and system proxy System permission prompts are more concentrated
Android Subscription, configuration file Per-app proxying and background operation Power-saving policies vary by system and can affect connections
iOS Remote resource, subscription VPN configuration authorization and rule mode Client capabilities are shaped by the network-extension framework

How often does subscription updating run?

There is no single update schedule that applies to every client. Update behavior is usually controlled by the client: some check at launch, some allow a recurring interval, and others request the subscription only when you click Update. The server returns the current configuration when the subscription URL is requested, but it cannot force every client to refresh its local list.

So if the panel has changed a route but the client still shows its old name, the local subscription may simply be out of date. Manually update it from the subscription-management page, then check the update time or see whether the server list changed. If the update fails, keep the error message and check whether the network can reach the subscription URL.

More frequent updates are not always better. During normal use, let the client update at launch or according to a suitable background policy. Repeatedly refreshing while connected may reload the current route. Mobile operating systems also restrict background activity and may pause scheduled tasks, so manually updating once after an important change is more reliable.

The difference between updating, reloading, and re-importing

“Update subscription” fetches the latest configuration using the existing URL and should usually be your first choice. “Reload configuration” generally makes the client reread content already saved locally and may not contact the server. “Re-import” creates a new configuration group and can leave duplicate routes if used carelessly. Unless the original configuration is damaged, the credentials have changed, or the client says it cannot recognize the format, there is no need to re-import every time.

Update rule of thumb: Manually update the existing subscription first and watch for changes in the list. Delete the old group and re-import only when the link has been reset, the configuration group is damaged, or the format is incompatible.

How to verify the connection and routing after import

Seeing a server list is only the first step. A proper check should confirm that the connection is established, the target app uses the intended exit, DNS requests follow the expected path, and local sites are not routed unnecessarily. Testing whether a webpage opens cannot tell you whether the rules and DNS are configured correctly.

If the client offers global, rule-based, and direct modes, beginners should first understand their boundaries. Global mode generally sends more traffic through the selected route and is useful for testing whether routing rules are causing access problems. Rule mode matches domains, addresses, or apps to different exits and is better for daily use. Direct mode mainly pauses proxy forwarding; it does not mean a route is connected.

The value of split routing is sending requests that need international routes through the proxy while keeping local services on a direct connection. Outdated rules may send a target domain to the wrong exit, while overly broad rules route unrelated traffic unnecessarily. If the browser works but an app does not, check whether that app follows the system proxy, needs virtual adapter mode, or is excluded by a per-app rule.

Why DNS leak checks matter

DNS converts domain names into network addresses. After connecting through a route, if domain lookups are still handled by an unexpected local resolver, results may not match the exit region, some domains may fail to load, or the request path may be exposed to the local network. This is commonly called a DNS leak.

Prefer the DNS and routing combination provided by the client, and avoid stacking multiple system-level DNS tools. If the client supports remote resolution, rule matching, and virtual-adapter handling, follow its documentation to choose compatible settings. After making changes, disconnect and reconnect, then test the target app instead of merely refreshing an existing browser tab.

Are IEPL dedicated lines, relays, and direct routes included in a subscription?

A subscription may use route names or group labels to identify IEPL dedicated lines, relays, or direct routes, but these names describe how routes are organized—not the subscription format itself. The client still builds a connection from the server parameters it receives, and “subscription imported successfully” alone cannot verify the underlying path type.

A direct route usually connects the device straight to the remote server. Its path is simple, but performance depends more heavily on public-network quality between the local network and the remote server. A relay connects to a nearby or more suitable entry point first, then uses an intermediate link to reach the exit, which can improve cross-network routing. An IEPL dedicated line uses a controlled cross-border transport path rather than ordinary public-internet routing, but the final experience still depends on local access, entry load, exit status, and the target service.

Route names help users choose by intended use, but they should not be the only deciding factor. One subscription can contain routes with different protocols and paths. Start with the target region and use case, then consider local-network compatibility. If one route fails, try another protocol or path in the same region instead of repeatedly fetching the subscription.

What to do after a subscription link is exposed

Once a subscription link has appeared publicly, do not simply delete the message and keep using it. The link may already have been cached by webpages, indexed by search engines, saved by sync tools, or copied by others. The safer approach is to update the subscription credentials in the user panel so the old link expires, then delete the old configuration from your clients and import the new link.

  1. Find the option to update credentials, reset the subscription, or use an equivalent function in the user panel.
  2. After updating, stop using the original link and do not continue forwarding the old QR code.
  3. Delete the old subscription group from every device so the client does not keep requesting the invalid URL.
  4. Import the new link and run a subscription update once.
  5. Check that all frequently used devices have switched; if you cannot confirm, describe the exposure scenario in a support ticket.

If the client only reports that the subscription request failed, do not immediately assume the link was exposed. The failure may also come from the local network, an incompatible client format, an incorrect system clock, certificate verification issues, or a temporarily unreachable subscription URL. Determine exposure from facts such as whether it was shared publicly or accessed by an unknown device; troubleshoot connection failures through the network path step by step.

A support ticket can include the error text, time of occurrence, operating system, client name, and connection mode, but mask the unique credentials in the subscription URL. If support needs more information, use the official ticket process rather than posting the complete link in a public comment section.

Bottom line: Treat a subscription link that was shared publicly as exposed credentials. Update the credentials and replace the old configuration on every device; deleting the public post alone cannot ensure that links already circulated are invalid.

How to troubleshoot common import failures

The client reports a format error

First check that the copied content is complete and that no spaces, quotation marks, or explanatory text were added at the beginning or end. Then confirm that the client supports the subscription format and protocols involved. Some clients read only their own configuration system, so a valid link may still be impossible for them to parse. Return to the panel and choose the matching import entry instead of editing the subscription manually.

Import succeeded but the list is empty

The client may not have actually run the update, may have kept an empty group after parsing failed, or the subscription may have returned no compatible configuration. Open subscription management, check the error, update manually, and confirm that the system clock and network access are working. If another supported client can read the same link, the issue is more likely the original client’s format support or cache.

Routes are present but every connection fails

First rule out system permissions and client-mode issues, then check whether the local network restricts the relevant transport. Protocol support cannot be judged by the name alone: a client labeled as supporting VLESS may not support every transport combination used by the subscription. Shadowsocks, VMess, Trojan, VLESS, Hysteria2, and TUIC are not interchangeable; the client needs the corresponding implementation.

The browser works, but other apps do not

This is usually related to the scope of the system proxy or per-app rules. The browser may follow the system proxy while other apps connect directly. Traffic paths become consistent only after enabling a suitable virtual adapter mode or adjusting per-app rules. Enterprise devices may also be restricted by system policies, so check device-management requirements before making changes.

Duplicate routes appear after updating

Check whether the same link was imported into multiple configuration groups or whether both the old and new subscriptions remain. Identify the active group first, then delete duplicates. Do not rely on route names alone: after server-side renaming, old cached entries and new configurations may look similar while representing different items.

Once you understand how subscription links work, troubleshooting becomes much clearer: the panel provides credentials and configuration, the subscription delivers the server list, the client parses protocols and applies routing, and system network settings determine whether traffic can be handled. Checking these layers separately is usually more effective than repeatedly reinstalling software.