Local configuration tool
Trojan to sing-box JSON
Transports are renamed to sing-box's vocabulary, where HTTPUpgrade is its own type rather than a WebSocket flag.
Conversion happens entirely in your browser. Links are not uploaded, saved, or placed in the page URL.
Conversion result
Why some links are rejected
A parameter that cannot be mapped without changing how the connection behaves is reported rather than dropped. For sing-box that mostly means XHTTP, a transport it does not have at all, plus certificate pinning and TUIC v4 tokens. Renames that sing-box does read — reduce_rtt becoming zero_rtt_handshake — happen here instead of failing quietly on your device.
How to import into sing-box
Save the JSON as your config file, or import it as a local profile in SFI, SFA or SFM. The Proxy selector outbound is already wired up, so switching nodes does not mean editing the file.
How Trojan fields map to sing-box
What this converter actually does, line by line. On the left is how it is written in a Trojan link; on the right is the field it becomes in the sing-box config.
| In the link | In the sing-box config | Notes |
|---|---|---|
password@host:port | password / server / server_port | The whole userinfo is the password, so a colon inside it is preserved rather than split off. |
sni (legacy: peer) | tls.server_name | peer is the older spelling and maps onto sni; supplying both is an error. |
security=reality + pbk / sid | tls.reality.public_key / short_id | Trojan over REALITY is unusual but valid, and converts the same way VLESS does. |
fp / alpn | tls.utls.fingerprint / tls.alpn | Trojan is TLS-only, so these always apply. |
type=ws / grpc / httpupgrade | transport.type: "ws" / "grpc" / "httpupgrade" | Transports are renamed per target; HTTPUpgrade is a WebSocket flag in Mihomo and a type of its own elsewhere. |
type=h2 | transport.type: "http" | Xray has removed the HTTP/2 transport, so that target refuses the line instead of rewriting it as XHTTP — a different protocol on the wire. |
type=xhttp | Rejected with an error | Rejected for sing-box, which has no such transport. |
allowInsecure=1 | tls.insecure: true | Converted with a warning attached. Xray removed the option, so that target refuses the link instead. |
FAQ
- Which client do I use after converting Trojan to sing-box?
- Use an official sing-box 1.11+ client (SFI, SFA and SFM included). Versions below 1.11 reject the route rule actions this config uses and fail to load.
- Is this Trojan converter free, and does it upload my node links?
- It is free and needs no account. The conversion is done by JavaScript inside this page, on your own machine: links are never uploaded, never written into the page URL, and never stored. Closing the tab is all the cleanup there is.
- Can I convert a subscription link straight to sing-box?
- Yes, but paste the body the subscription URL returns — usually one long base64 string — rather than the URL itself, which the browser cannot fetch across origins. Mixed protocols in one subscription are fine. Subscription to sing-box converter
- The sing-box config converted fine but will not connect — what now?
- This page only translates links into a config: it checks the structure, never whether the server is reachable. Confirm the same link works in the client you copied it from, then check the client version — server_ports and route rule actions need sing-box 1.11 or newer.
This creates a one-time local configuration, not an auto-updating subscription. It checks configuration structure, not whether a server is reachable.