Skip to content

Xray outbound JSON: server configuration

A node file is an object containing an outbounds array. Manual single-node editing requires exactly one element. Normal file/text import can extract multiple nodes. Use Servers → Add server → Manual JSON, or Import file.

The root is not a bare outbound object. Routing, DNS and inbounds in an ordinary server import are not installed as a full configuration.

Collect the server’s actual parameters

Area Required information
Identity Display tag, protocol, server address and numeric port
VLESS / VMess Actual user UUID; provider’s encryption/security and flow where applicable
Trojan / Shadowsocks / SOCKS Password, encryption method or username/password as required by that protocol
Transport Provider’s network, path, Host, service name and other transport parameters
TLS Whether enabled, certificate server name and optional provider-required ALPN/fingerprint
REALITY Server name, fingerprint, public key/password, short ID and required flow

Do not infer these values from a server’s display name or country. Do not add allowInsecure, TLS bypasses or a Vision flow merely to make an error disappear. Match the server configuration.

VLESS over TLS

Template: replace server.example.com, port and dummy UUID; confirm that the server uses RAW/TCP with TLS. The TLS server name can differ from the address: copy the provider’s value.

JSON: outbound-vless-tls.json

{
  "outbounds": [
    {
      "tag": "My VLESS server",
      "protocol": "vless",
      "settings": {
        "vnext": [
          {
            "address": "server.example.com",
            "port": 443,
            "users": [
              {
                "id": "00000000-0000-4000-8000-000000000001",
                "encryption": "none"
              }
            ]
          }
        ]
      },
      "streamSettings": {
        "network": "raw",
        "security": "tls",
        "tlsSettings": {
          "serverName": "server.example.com"
        }
      }
    }
  ]
}

For XHTTP, replace the transport with the provider’s network: "xhttp" and xhttpSettings (host, path, mode, and any required extra). For WebSocket use network: "ws" and wsSettings (host, path). These are alternatives, not settings to combine indiscriminately. For gRPC use the provider’s grpcSettings.serviceName.

VLESS over REALITY

Template: the public key placeholder is deliberately unresolved. Replace it and every provider-specific value before saving. realitySettings.password here carries the server’s public key, not its private key. Add user flow only when required.

JSON: outbound-vless-reality.json

{
  "outbounds": [
    {
      "tag": "My REALITY server",
      "protocol": "vless",
      "settings": {
        "vnext": [
          {
            "address": "server.example.com",
            "port": 443,
            "users": [
              {
                "id": "00000000-0000-4000-8000-000000000001",
                "encryption": "none"
              }
            ]
          }
        ]
      },
      "streamSettings": {
        "network": "raw",
        "security": "reality",
        "realitySettings": {
          "serverName": "cover.example.com",
          "fingerprint": "chrome",
          "password": "REPLACE_WITH_REALITY_PUBLIC_KEY",
          "shortId": "0123456789abcdef"
        }
      }
    }
  ]
}

VMess over WebSocket and TLS

Template: replace the host, UUID, path and transport details. This is a normal Xray outbound, not the retired vmess://Base64(JSON) VMessQrCode format.

JSON: outbound-vmess-ws.json

{
  "outbounds": [
    {
      "tag": "My VMess server",
      "protocol": "vmess",
      "settings": {
        "vnext": [
          {
            "address": "server.example.com",
            "port": 443,
            "users": [
              {
                "id": "00000000-0000-4000-8000-000000000001",
                "security": "auto"
              }
            ]
          }
        ]
      },
      "streamSettings": {
        "network": "ws",
        "security": "tls",
        "wsSettings": {
          "path": "/proxy",
          "host": "server.example.com"
        },
        "tlsSettings": {
          "serverName": "server.example.com"
        }
      }
    }
  ]
}

Other proxy protocols

The same envelope preserves complete protocol settings; OneXray does not rebuild nodes from a fixed form.

  • Trojan: settings.servers contains address, port, password; transport/TLS belongs in streamSettings.
  • Shadowsocks: settings.servers contains address, port, method, password; copy the provider’s exact cipher/key requirements.
  • SOCKS: settings.servers contains address, port, and optional users: [{"user":"…","pass":"…"}]. SOCKS itself is not encrypted; do not describe it as TLS.
  • Additional Core protocols should be used only when the bundled Core supports their exact JSON. Lack of a standard share URI does not imply lack of native JSON support.

Protocol references: VLESS, VMess, Trojan, Shadowsocks, SOCKS. Check the version boundary before using newer fields.

Naming, dependencies and sharing

Use tag for the node name. Do not generate the old name alias or abuse sendThrough. Normal mode assigns runtime tags, so another imported node’s display tag is not a stable cross-node reference. For a final exit use Smart Routing’s final-exit selection; for fully specified chains use Raw JSON.

Do not put cross-node dialerProxy or proxySettings.tag references in an independent node template. Keep dependencies together in Raw JSON instead.

JSON preserves more information than standard share links. VMessAEAD/VLESS links, Shadowsocks, SOCKS and Trojan remain supported; legacy VMessQrCode is not. For AI generation, prefer the full JSON document and the correct import path.

Last updated on