Back to tools

Local configuration tool

VMess to sing-box JSON

Maps alterId and cipher onto sing-box's alter_id and security fields.

Your links stay on this device

Conversion happens entirely in your browser. Links are not uploaded, saved, or placed in the page URL.

This page accepts VMess links, one per line.
Targets sing-box 1.11 or newer — earlier versions do not accept route rule actions or server_ports.
Routing preset

Conversion result

Why some links are rejected

A parameter that cannot be mapped without changing how the connection behaves is reported rather than dropped. For sing-box that mostly means XHTTP, a transport it does not have at all, plus certificate pinning and TUIC v4 tokens. Renames that sing-box does read — reduce_rtt becoming zero_rtt_handshake — happen here instead of failing quietly on your device.

How to import into sing-box

Save the JSON as your config file, or import it as a local profile in SFI, SFA or SFM. The Proxy selector outbound is already wired up, so switching nodes does not mean editing the file.

How VMess fields map to sing-box

What this converter actually does, line by line. On the left is how it is written in a VMess link; on the right is the field it becomes in the sing-box config.

In the linkIn the sing-box configNotes
iduuidvmess:// is base64-encoded JSON; these are its field names, not URL parameters.
add / portserver / server_portport is accepted as a string or a number, the way different exporters write it.
aidalter_idA non-zero alterId gets a warning: it selects the MD5 authentication path that has since been removed.
scysecurityauto, aes-128-gcm, chacha20-poly1305, none and zero are accepted.
pstagThe node name. Falls back to server:port when the field is empty.
tls: "tls" + snitls.enabled + tls.server_nameVMess is spelled the same way as VLESS in every target: servername, server_name, serverName.
fp / alpntls.utls.fingerprint / tls.alpnfp defaults to chrome when the payload leaves it out.
net=ws + path / hosttransport.type: "ws"This is the shape v2rayN exports most often.
net=grpc / httpupgradetransport.type: "grpc" / "httpupgrade"Mihomo folds HTTPUpgrade into WebSocket; the other two give it its own type.
net=h2 / net=httptransport.type: "http"Xray has removed the HTTP/2 transport, so that target refuses the line instead of rewriting it as XHTTP — a different protocol on the wire.
net=xhttpRejected with an errorsing-box has no XHTTP transport, so the line is rejected instead of downgraded.
type (header obfuscation, e.g. "http")Rejected with an errorHeader obfuscation other than none has no equivalent in any of the three formats.

FAQ

Which client do I use after converting VMess to sing-box?
Use an official sing-box 1.11+ client (SFI, SFA and SFM included). Versions below 1.11 reject the route rule actions this config uses and fail to load.
Is this VMess converter free, and does it upload my node links?
It is free and needs no account. The conversion is done by JavaScript inside this page, on your own machine: links are never uploaded, never written into the page URL, and never stored. Closing the tab is all the cleanup there is.
Can I convert a subscription link straight to sing-box?
Yes, but paste the body the subscription URL returns — usually one long base64 string — rather than the URL itself, which the browser cannot fetch across origins. Mixed protocols in one subscription are fine. Subscription to sing-box converter
The sing-box config converted fine but will not connect — what now?
This page only translates links into a config: it checks the structure, never whether the server is reachable. Confirm the same link works in the client you copied it from, then check the client version — server_ports and route rule actions need sing-box 1.11 or newer.

Other converters

This creates a one-time local configuration, not an auto-updating subscription. It checks configuration structure, not whether a server is reachable.

© 2026