Security, Privacy, and Permissions FAQ
Covers risks involving Clash subscription tokens, node passwords, external-controller secrets, logs, and system permissions, along with security precautions for Dashboard access, certificates, and third-party installers.
Handle possible exposure or excessive privilege first
When tokens, secrets, control ports, or system permissions are involved, reduce the attack surface before continuing troubleshooting.
How Should I Protect Subscription Tokens, Node Passwords, and Secrets?Subscription tokens, node passwords, WireGuard private keys, and external-controller secrets are sensitive. If exposed, they may be used by someone else or allow access to a local control interface.How Can I Configure external-controller, Dashboard, and secret More Safely?external-controller is a runtime control API that can read policy groups, connections, and logs. If it is exposed to a network, set a secret and restrict who can access it.What Permissions and Privacy Considerations Apply to Clash Clients?Common permissions include system proxy control, launch at startup, network extensions, VPN/TUN, notifications, and local file access. Logs may contain domain names, IP addresses, matched rules, and error details.What If Dashboard Will Not Open, Cannot Connect to 9090, or Shows unauthorized?Dashboard must connect to the external-controller API. Failures usually involve the listening address, port, secret, cross-origin access, reverse proxy, or firewall.What If Multiple VPNs, Proxy Tools, or Security Apps Conflict?When multiple tools change the system proxy, routes, DNS, VPN interfaces, or certificates, Clash may lose connectivity, rules, or TUN. Test one network path at a time.
