Installation and Migration · Clash Technical Blog

How to Download and Install Clash for Mac: Chip Selection and First-Time Setup

Choose the Apple silicon or Intel Mac installer, then address Gatekeeper, subscription import, system proxy, and any old-client remnants in that order.

  • macOS
  • Apple Silicon
  • Intel
On this page

Before downloading, use “About This Mac” to identify Apple Silicon or Intel

Open “About This Mac” from the Apple menu. If Chip says Apple M1, M2, M3, or a later Apple series, choose the Apple Silicon / arm64 build. If Processor says Intel, choose the x64 / Intel build. Used and managed devices do not always follow assumptions based on purchase year, so system information is the most reliable source.

Download the macOS asset from the Release page of the actual project, such as Clash Verge Rev; the file list should match the version tag and release notes. Do not use a similarly named “cracked Mac edition” from a file-sharing site or assume a file is maintained merely because Clash appears in its name.

Mac and asset labels

What the Mac reportsOption
Apple M-series chiparm64 / Apple Silicon
Intel processorx64 / Intel
UniversalContains both architectures and is usually larger
Unable to determineReturn to “About This Mac” and check instead of guessing

A DMG is only installation media; drag the app into Applications

Standard installation process

  1. Open the downloaded DMG

    Wait for Finder to show the app icon and Applications folder.

  2. Drag the app into Applications

    After copying finishes, launch it from the Applications folder; do not keep running it from the DMG.

  3. Eject the disk image

    Once the app is copied, eject the DMG from the Finder sidebar.

  4. Keep the original Release information

    You will need the version and architecture later for troubleshooting and updates.

If an older version with the same name already exists in Applications, completely quit its menu bar process before replacing it. An old ClashX instance, another Mihomo client, or VPN software may alternately change the system proxy and make the new installation look broken.

Handle “developer cannot be verified” under Privacy & Security

When macOS first opens an app downloaded from the internet, it may say the developer cannot be verified or the app was blocked. Recheck the project Release, version, and filename, then open “System Settings > Privacy & Security,” find the recently blocked item, and follow the system's “Open Anyway” flow.

Do not run a global command that disables Gatekeeper or install an unknown signing patch to bypass the prompt. A per-app exception from the system is sufficient, while other downloads remain protected. If the app is reported as damaged, redownload the asset for the correct architecture instead of immediately removing security attributes.

After the menu bar icon appears, wait for the core status to stabilize

An interface on first launch does not mean Mihomo is ready. Open settings or logs and confirm that the core is not repeatedly exiting and that the client can read and write its configuration directory. No subscription has been imported yet, so any core failed or permission denied message belongs to the local installation layer.

If the app opens only after a Rosetta prompt, you probably chose an Intel build. Although Apple silicon can run some Intel apps, use the project's arm64 version to reduce extra dependencies and avoid confusion during future updates.

For the first configuration, use only the subscription and system proxy

On the Profiles screen, add a Clash- or Mihomo-compatible subscription, update it manually, and select it. Open Proxies, pin one node, keep the mode on Rule, then enable System Proxy. macOS may request permission to change the system proxy; the requesting app should be the client you just installed.

When the browser opens a familiar site, the corresponding connection should appear in Connections. Do not enable TUN or install a network extension until the ordinary system proxy works. Otherwise, one failure will involve the subscription, node, system proxy, and network permissions at once.

Visible results of the first connection

  • The Profile shows the current update time
  • You can select a specific node in Proxies
  • The current client writes the macOS system proxy
  • Connections shows the browser request you just made

An app that will not open and a web page that will not open are separate troubleshooting paths

The app icon has a prohibited symbol

Check the macOS version requirement and app architecture, then download the matching build.

The app says it is damaged

Redownload it from the original Release and confirm that the file is complete and from the same source.

Subscription update returns 401 / 403

The link credential or account status has a problem unrelated to macOS permissions.

The browser fails and Connections is empty

Confirm that System Proxy was written, and quit other proxy clients.

The connection enters Clash but shows timeout

Switch to another verified node; there is no need to reinstall the DMG.

Return to the layer corresponding to the first screen where the error appears. Only after the app starts, the Profile updates, and a node can be selected should a web connection failure send you to proxy and rule troubleshooting.

Before uninstalling or switching clients, restore direct networking on macOS

Before uninstalling, rolling back, or migrating to another client, disable the system proxy and TUN in the current app and quit completely from the menu bar. Closing only the window can leave a background process listening on the local proxy port. Dragging the app directly to Trash then leaves web requests pointing to an address with no listener.

In macOS network settings, confirm that HTTP, HTTPS, and SOCKS proxies have been removed; the browser should directly reach locally accessible sites. After direct access returns, delete the app from Applications and remove data you no longer need. During migration, reimport the subscription instead of overwriting one client's data directory with another's.

After the new client enables System Proxy, a new browser request in Connections proves that stale proxy state is gone. This Mac has now completed its first setup from architecture selection and app installation through Gatekeeper approval, subscription import, and the system proxy. For future version changes, repeat the same quit and direct-access checks.

References