Xray outbound JSON: server configuration
A node file is an object containing an outbounds array. Manual single-node editing requires exactly one element. Normal file/text import can extract multiple nodes. Use Servers → Add server → Manual JSON, or Import file.
The root is not a bare outbound object. Routing, DNS and inbounds in an ordinary server import are not installed as a full configuration.
Collect the server’s actual parameters
| Area | Required information |
|---|---|
| Identity | Display tag, protocol, server address and numeric port |
| VLESS / VMess | Actual user UUID; provider’s encryption/security and flow where applicable |
| Trojan / Shadowsocks / SOCKS | Password, encryption method or username/password as required by that protocol |
| Transport | Provider’s network, path, Host, service name and other transport parameters |
| TLS | Whether enabled, certificate server name and optional provider-required ALPN/fingerprint |
| REALITY | Server name, fingerprint, public key/password, short ID and required flow |
Do not infer these values from a server’s display name or country. Do not add allowInsecure, TLS bypasses or a Vision flow merely to make an error disappear. Match the server configuration.
VLESS over TLS
Template: replace server.example.com, port and dummy UUID; confirm that the server uses RAW/TCP with TLS. The TLS server name can differ from the address: copy the provider’s value.
{
"outbounds": [
{
"tag": "My VLESS server",
"protocol": "vless",
"settings": {
"vnext": [
{
"address": "server.example.com",
"port": 443,
"users": [
{
"id": "00000000-0000-4000-8000-000000000001",
"encryption": "none"
}
]
}
]
},
"streamSettings": {
"network": "raw",
"security": "tls",
"tlsSettings": {
"serverName": "server.example.com"
}
}
}
]
}For XHTTP, replace the transport with the provider’s network: "xhttp" and xhttpSettings (host, path, mode, and any required extra). For WebSocket use network: "ws" and wsSettings (host, path). These are alternatives, not settings to combine indiscriminately. For gRPC use the provider’s grpcSettings.serviceName.
VLESS over REALITY
Template: the public key placeholder is deliberately unresolved. Replace it and every provider-specific value before saving. realitySettings.password here carries the server’s public key, not its private key. Add user flow only when required.
JSON: outbound-vless-reality.json
{
"outbounds": [
{
"tag": "My REALITY server",
"protocol": "vless",
"settings": {
"vnext": [
{
"address": "server.example.com",
"port": 443,
"users": [
{
"id": "00000000-0000-4000-8000-000000000001",
"encryption": "none"
}
]
}
]
},
"streamSettings": {
"network": "raw",
"security": "reality",
"realitySettings": {
"serverName": "cover.example.com",
"fingerprint": "chrome",
"password": "REPLACE_WITH_REALITY_PUBLIC_KEY",
"shortId": "0123456789abcdef"
}
}
}
]
}VMess over WebSocket and TLS
Template: replace the host, UUID, path and transport details. This is a normal Xray outbound, not the retired vmess://Base64(JSON) VMessQrCode format.
{
"outbounds": [
{
"tag": "My VMess server",
"protocol": "vmess",
"settings": {
"vnext": [
{
"address": "server.example.com",
"port": 443,
"users": [
{
"id": "00000000-0000-4000-8000-000000000001",
"security": "auto"
}
]
}
]
},
"streamSettings": {
"network": "ws",
"security": "tls",
"wsSettings": {
"path": "/proxy",
"host": "server.example.com"
},
"tlsSettings": {
"serverName": "server.example.com"
}
}
}
]
}Other proxy protocols
The same envelope preserves complete protocol settings; OneXray does not rebuild nodes from a fixed form.
- Trojan:
settings.serverscontainsaddress,port,password; transport/TLS belongs instreamSettings. - Shadowsocks:
settings.serverscontainsaddress,port,method,password; copy the provider’s exact cipher/key requirements. - SOCKS:
settings.serverscontainsaddress,port, and optionalusers: [{"user":"…","pass":"…"}]. SOCKS itself is not encrypted; do not describe it as TLS. - Additional Core protocols should be used only when the bundled Core supports their exact JSON. Lack of a standard share URI does not imply lack of native JSON support.
Protocol references: VLESS, VMess, Trojan, Shadowsocks, SOCKS. Check the version boundary before using newer fields.
Naming, dependencies and sharing
Use tag for the node name. Do not generate the old name alias or abuse sendThrough. Normal mode assigns runtime tags, so another imported node’s display tag is not a stable cross-node reference. For a final exit use Smart Routing’s final-exit selection; for fully specified chains use Raw JSON.
Do not put cross-node dialerProxy or proxySettings.tag references in an independent node template. Keep dependencies together in Raw JSON instead.
JSON preserves more information than standard share links. VMessAEAD/VLESS links, Shadowsocks, SOCKS and Trojan remain supported; legacy VMessQrCode is not. For AI generation, prefer the full JSON document and the correct import path.