Local configuration tool
VMess to sing-box JSON
Maps alterId and cipher onto sing-box's alter_id and security fields.
Conversion happens entirely in your browser. Links are not uploaded, saved, or placed in the page URL.
Conversion result
Why some links are rejected
A parameter that cannot be mapped without changing how the connection behaves is reported rather than dropped. For sing-box that mostly means XHTTP, a transport it does not have at all, plus certificate pinning and TUIC v4 tokens. Renames that sing-box does read — reduce_rtt becoming zero_rtt_handshake — happen here instead of failing quietly on your device.
How to import into sing-box
Save the JSON as your config file, or import it as a local profile in SFI, SFA or SFM. The Proxy selector outbound is already wired up, so switching nodes does not mean editing the file.
How VMess fields map to sing-box
What this converter actually does, line by line. On the left is how it is written in a VMess link; on the right is the field it becomes in the sing-box config.
| In the link | In the sing-box config | Notes |
|---|---|---|
id | uuid | vmess:// is base64-encoded JSON; these are its field names, not URL parameters. |
add / port | server / server_port | port is accepted as a string or a number, the way different exporters write it. |
aid | alter_id | A non-zero alterId gets a warning: it selects the MD5 authentication path that has since been removed. |
scy | security | auto, aes-128-gcm, chacha20-poly1305, none and zero are accepted. |
ps | tag | The node name. Falls back to server:port when the field is empty. |
tls: "tls" + sni | tls.enabled + tls.server_name | VMess is spelled the same way as VLESS in every target: servername, server_name, serverName. |
fp / alpn | tls.utls.fingerprint / tls.alpn | fp defaults to chrome when the payload leaves it out. |
net=ws + path / host | transport.type: "ws" | This is the shape v2rayN exports most often. |
net=grpc / httpupgrade | transport.type: "grpc" / "httpupgrade" | Mihomo folds HTTPUpgrade into WebSocket; the other two give it its own type. |
net=h2 / net=http | transport.type: "http" | Xray has removed the HTTP/2 transport, so that target refuses the line instead of rewriting it as XHTTP — a different protocol on the wire. |
net=xhttp | Rejected with an error | sing-box has no XHTTP transport, so the line is rejected instead of downgraded. |
type (header obfuscation, e.g. "http") | Rejected with an error | Header obfuscation other than none has no equivalent in any of the three formats. |
FAQ
- Which client do I use after converting VMess to sing-box?
- Use an official sing-box 1.11+ client (SFI, SFA and SFM included). Versions below 1.11 reject the route rule actions this config uses and fail to load.
- Is this VMess converter free, and does it upload my node links?
- It is free and needs no account. The conversion is done by JavaScript inside this page, on your own machine: links are never uploaded, never written into the page URL, and never stored. Closing the tab is all the cleanup there is.
- Can I convert a subscription link straight to sing-box?
- Yes, but paste the body the subscription URL returns — usually one long base64 string — rather than the URL itself, which the browser cannot fetch across origins. Mixed protocols in one subscription are fine. Subscription to sing-box converter
- The sing-box config converted fine but will not connect — what now?
- This page only translates links into a config: it checks the structure, never whether the server is reachable. Confirm the same link works in the client you copied it from, then check the client version — server_ports and route rule actions need sing-box 1.11 or newer.
This creates a one-time local configuration, not an auto-updating subscription. It checks configuration structure, not whether a server is reachable.