Back to tools

Local configuration tool

Hysteria2 to sing-box JSON

Bandwidth becomes up_mbps and down_mbps, and port hopping becomes the server_ports array.

Your links stay on this device

Conversion happens entirely in your browser. Links are not uploaded, saved, or placed in the page URL.

This page accepts Hysteria2 links, one per line.
Targets sing-box 1.11 or newer — earlier versions do not accept route rule actions or server_ports.
Routing preset

Conversion result

Why some links are rejected

A parameter that cannot be mapped without changing how the connection behaves is reported rather than dropped. For sing-box that mostly means XHTTP, a transport it does not have at all, plus certificate pinning and TUIC v4 tokens. Renames that sing-box does read — reduce_rtt becoming zero_rtt_handshake — happen here instead of failing quietly on your device.

How to import into sing-box

Save the JSON as your config file, or import it as a local profile in SFI, SFA or SFM. The Proxy selector outbound is already wired up, so switching nodes does not mean editing the file.

How Hysteria2 fields map to sing-box

What this converter actually does, line by line. On the left is how it is written in a Hysteria2 link; on the right is the field it becomes in the sing-box config.

In the linkIn the sing-box configNotes
password@host:portpassword / server / server_portThe Hysteria 2 URI spec allows a colon inside the auth string, so it is kept intact.
snitls.server_nameHysteria2 runs over QUIC, so TLS is always on and neither target has a tls toggle to set.
obfs=salamander + obfs-passwordobfs.type / obfs.passwordsalamander is the only obfuscation defined; obfs without a password is an error.
up / downup_mbps / down_mbps (100)Mihomo wants a string with a unit, sing-box wants a bare number. Both are produced for you.
mportserver_ports (["8000:9000"])Port hopping. The separators differ — a hyphen in Mihomo, a colon in sing-box.
alpn / insecuretls.alpn / tls.insecureinsecure and allowInsecure are the same parameter; using both is an error.
pinSHA256Rejected with an errorCertificate pinning has no equivalent field in either target, and dropping it would weaken the connection.
fpRejected with an erroruTLS fingerprints are a TCP-TLS concept; a QUIC handshake has nowhere to put one.

FAQ

Which client do I use after converting Hysteria2 to sing-box?
Use an official sing-box 1.11+ client (SFI, SFA and SFM included). Versions below 1.11 reject the route rule actions this config uses and fail to load.
Is this Hysteria2 converter free, and does it upload my node links?
It is free and needs no account. The conversion is done by JavaScript inside this page, on your own machine: links are never uploaded, never written into the page URL, and never stored. Closing the tab is all the cleanup there is.
Can I convert a subscription link straight to sing-box?
Yes, but paste the body the subscription URL returns — usually one long base64 string — rather than the URL itself, which the browser cannot fetch across origins. Mixed protocols in one subscription are fine. Subscription to sing-box converter
The sing-box config converted fine but will not connect — what now?
This page only translates links into a config: it checks the structure, never whether the server is reachable. Confirm the same link works in the client you copied it from, then check the client version — server_ports and route rule actions need sing-box 1.11 or newer.

Other converters

This creates a one-time local configuration, not an auto-updating subscription. It checks configuration structure, not whether a server is reachable.

© 2026