Local configuration tool
VLESS to sing-box JSON
Emits uTLS and REALITY blocks in sing-box's nested shape, with a selector outbound ready to use.
Conversion happens entirely in your browser. Links are not uploaded, saved, or placed in the page URL.
Conversion result
Why some links are rejected
A parameter that cannot be mapped without changing how the connection behaves is reported rather than dropped. For sing-box that mostly means XHTTP, a transport it does not have at all, plus certificate pinning and TUIC v4 tokens. Renames that sing-box does read — reduce_rtt becoming zero_rtt_handshake — happen here instead of failing quietly on your device.
How to import into sing-box
Save the JSON as your config file, or import it as a local profile in SFI, SFA or SFM. The Proxy selector outbound is already wired up, so switching nodes does not mean editing the file.
How VLESS fields map to sing-box
What this converter actually does, line by line. On the left is how it is written in a VLESS link; on the right is the field it becomes in the sing-box config.
| In the link | In the sing-box config | Notes |
|---|---|---|
uuid@host:port | uuid / server / server_port | The part before @ is the UUID; anything that is not a valid UUID is rejected. |
security=tls | tls.enabled: true | Without security=tls the link is treated as plaintext and the TLS-only parameters below are rejected. |
security=reality + pbk / sid | tls.reality.public_key / short_id | sid must be hex of even length, 16 characters at most. |
sni | tls.server_name | Falls back to the server address when absent. Each client spells it differently: servername in Mihomo, server_name in sing-box, serverName in Xray. |
fp | tls.utls.fingerprint | Defaults to chrome. An unrecognised fingerprint is an error, not a silent fallback. |
alpn | tls.alpn | Comma-separated in the link, an array in every target format. |
flow=xtls-rprx-vision | flow | Passed through as-is. It only means anything over TCP with TLS or REALITY. |
type=ws + path / host | transport.type: "ws" | host becomes the Host header. ed and eh become max-early-data and early-data-header-name. |
type=grpc + serviceName | transport.service_name | gun mode only; mode=multi is rejected. |
type=h2 / type=http | transport.type: "http" | Xray has removed the HTTP/2 transport, so that target refuses the line instead of rewriting it as XHTTP — a different protocol on the wire. |
type=xhttp | Rejected with an error | Mihomo needs 1.19 or newer and Xray needs 24.11 or newer; sing-box has no XHTTP transport at all, so that target rejects the line. |
type=httpupgrade | transport.type: "httpupgrade" | Mihomo models HTTPUpgrade as a flag on WebSocket; the other two make it its own transport type. |
allowInsecure=1 | tls.insecure: true | Converted with a warning — turning certificate checks off gives up protection against interception. Xray removed the option in favour of certificate pinning, so that target refuses the link. |
packetEncoding | packet_encoding | packet-encoding and packetEncoding are accepted as the same parameter. |
pqv / spx / pcs / vcn / ech | Rejected with an error | REALITY fields added after 2024 that have no faithful equivalent yet — reported rather than dropped. |
FAQ
- Which client do I use after converting VLESS to sing-box?
- Use an official sing-box 1.11+ client (SFI, SFA and SFM included). Versions below 1.11 reject the route rule actions this config uses and fail to load.
- Is this VLESS converter free, and does it upload my node links?
- It is free and needs no account. The conversion is done by JavaScript inside this page, on your own machine: links are never uploaded, never written into the page URL, and never stored. Closing the tab is all the cleanup there is.
- Can I convert a subscription link straight to sing-box?
- Yes, but paste the body the subscription URL returns — usually one long base64 string — rather than the URL itself, which the browser cannot fetch across origins. Mixed protocols in one subscription are fine. Subscription to sing-box converter
- The sing-box config converted fine but will not connect — what now?
- This page only translates links into a config: it checks the structure, never whether the server is reachable. Confirm the same link works in the client you copied it from, then check the client version — server_ports and route rule actions need sing-box 1.11 or newer.
This creates a one-time local configuration, not an auto-updating subscription. It checks configuration structure, not whether a server is reachable.