Hako configuration reference
Use this reference whenever you need to inspect mihomo YAML. A first configuration does not need to begin with 185 fields: start with the best-practice template, then return to the exact field when a specific need appears.
Keep the configuration understandable
A trusted configuration that contains only what you need is easier to verify and less likely to produce surprising behavior after an update.
Browse by topic
Field support status
- Supported: consumed directly by the Hako core.
- Managed / limited: accepted, but repaired, forced, or replaced for Apple networking.
- Advanced: recognized by the core but may open a local service or control surface.
- Unsupported: removed or ineffective inside Apple Packet Tunnel.
- Not applicable: belongs to Android, Linux, or another environment.
185 fields shown
| Field | Type | iOS | macOS | tvOS | Platform notes |
|---|---|---|---|---|---|
dns.cache-algorithm | string | Supported | Supported | Supported | Consumed by the Hako core. |
dns.cache-max-size | int | Supported | Supported | Supported | Consumed by the Hako core. |
dns.default-nameserver | []string | Managed / limited | Managed / limited | Managed / limited | Accepted, but Hako may force, repair, split, or replace the value for Apple networking. |
dns.direct-nameserver | []string | Supported | Supported | Supported | Consumed by the Hako core. |
dns.direct-nameserver-follow-policy | bool | Supported | Supported | Supported | Consumed by the Hako core. |
dns.enable | bool | Managed / limited | Managed / limited | Managed / limited | Accepted, but Hako may force, repair, split, or replace the value for Apple networking. |
dns.enhanced-mode | C.DNSMode | Supported | Supported | Supported | Consumed by the Hako core. |
dns.fake-ip-filter | []string | Supported | Supported | Supported | Consumed by the Hako core. |
dns.fake-ip-filter-mode | C.FilterMode | Supported | Supported | Supported | Consumed by the Hako core. |
dns.fake-ip-range | string | Supported | Supported | Supported | Consumed by the Hako core. |
dns.fake-ip-range6 | string | Supported | Supported | Supported | Consumed by the Hako core. |
dns.fake-ip-ttl | int | Supported | Supported | Supported | Consumed by the Hako core. |
dns.fallback | []string | Supported | Supported | Supported | Consumed by the Hako core. |
dns.fallback-filter.domain | []string | Supported | Supported | Supported | Consumed by the Hako core. |
dns.fallback-filter.geoip | bool | Supported | Supported | Supported | Consumed by the Hako core. |
dns.fallback-filter.geoip-code | string | Supported | Supported | Supported | Consumed by the Hako core. |
dns.fallback-filter.geosite | []string | Supported | Supported | Supported | Consumed by the Hako core. |
dns.fallback-filter.ipcidr | []string | Supported | Supported | Supported | Consumed by the Hako core. |
dns.fallback-lazy-query | bool | Supported | Supported | Supported | Consumed by the Hako core. |
dns.ipv6 | bool | Supported | Supported | Supported | Consumed by the Hako core. |
dns.ipv6-timeout | uint | Supported | Supported | Supported | Consumed by the Hako core. |
dns.listen | string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
dns.listen-routing-mark | int | Unsupported | Unsupported | Unsupported | Removed or not consumed in the Apple Packet Tunnel runtime. |
dns.nameserver | []string | Supported | Supported | Supported | Consumed by the Hako core. |
dns.nameserver-policy | *orderedmap.OrderedMap[string, any] | Supported | Supported | Supported | Consumed by the Hako core. |
dns.prefer-h3 | bool | Supported | Supported | Supported | Consumed by the Hako core. |
dns.proxy-server-nameserver | []string | Supported | Supported | Supported | Consumed by the Hako core. |
dns.proxy-server-nameserver-policy | *orderedmap.OrderedMap[string, any] | Supported | Supported | Supported | Consumed by the Hako core. |
dns.respect-rules | bool | Supported | Supported | Supported | Consumed by the Hako core. |
dns.use-hosts | bool | Supported | Supported | Supported | Consumed by the Hako core. |
dns.use-system-hosts | bool | Supported | Supported | Supported | Consumed by the Hako core. |
experimental.dialer-ip4p-convert | bool | Advanced | Advanced | Advanced | Parsed by the core, but not a stable product-level promise. |
experimental.fingerprints | []string | Advanced | Advanced | Advanced | Parsed by the core, but not a stable product-level promise. |
experimental.quic-go-disable-ecn | bool | Advanced | Advanced | Advanced | Parsed by the core, but not a stable product-level promise. |
experimental.quic-go-disable-gso | bool | Advanced | Advanced | Advanced | Parsed by the core, but not a stable product-level promise. |
clash-for-android.append-system-dns | bool | Not applicable | Not applicable | Not applicable | Belongs to Android, Linux, or another non-Apple environment. |
clash-for-android.ui-subtitle-pattern | string | Not applicable | Not applicable | Not applicable | Belongs to Android, Linux, or another non-Apple environment. |
disable-keep-alive | bool | Supported | Supported | Supported | Consumed by the Hako core. |
etag-support | bool | Supported | Supported | Supported | Consumed by the Hako core. |
external-controller | string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
external-controller-cors.allow-origins | []string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
external-controller-cors.allow-private-network | bool | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
external-controller-pipe | string | Not applicable | Not applicable | Not applicable | Belongs to Android, Linux, or another non-Apple environment. |
external-controller-routing-mark | int | Not applicable | Not applicable | Not applicable | Belongs to Android, Linux, or another non-Apple environment. |
external-controller-tls | string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
external-controller-unix | string | Advanced | Advanced | Unsupported | Can expose a listener or control surface. Use only with explicit access control and strong credentials. Unix-domain controller sockets are unavailable on tvOS. |
external-doh-server | string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
external-ui | string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
external-ui-name | string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
external-ui-url | string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
find-process-mode | process.FindProcessMode | Unsupported | Supported | Unsupported | Removed or not consumed in the Apple Packet Tunnel runtime. Consumed by the Hako core. |
geo-auto-update | bool | Managed / limited | Managed / limited | Managed / limited | Available through Hako-managed resources; manual paths and update behavior are platform-dependent. Uses Hako-managed, memory-conscious resources; tvOS caches may be cleared. |
geo-update-interval | int | Not applicable | Not applicable | Not applicable | Belongs to Android, Linux, or another non-Apple environment. |
geodata-loader | string | Managed / limited | Managed / limited | Managed / limited | Available through Hako-managed resources; manual paths and update behavior are platform-dependent. Uses Hako-managed, memory-conscious resources; tvOS caches may be cleared. |
geodata-mode | bool | Managed / limited | Managed / limited | Managed / limited | Available through Hako-managed resources; manual paths and update behavior are platform-dependent. Uses Hako-managed, memory-conscious resources; tvOS caches may be cleared. |
geosite-matcher | string | Supported | Supported | Supported | Consumed by the Hako core. |
geox-url.asn | string | Managed / limited | Managed / limited | Managed / limited | Available through Hako-managed resources; manual paths and update behavior are platform-dependent. Uses Hako-managed, memory-conscious resources; tvOS caches may be cleared. |
geox-url.geoip | string | Managed / limited | Managed / limited | Managed / limited | Available through Hako-managed resources; manual paths and update behavior are platform-dependent. Uses Hako-managed, memory-conscious resources; tvOS caches may be cleared. |
geox-url.geosite | string | Managed / limited | Managed / limited | Managed / limited | Available through Hako-managed resources; manual paths and update behavior are platform-dependent. Uses Hako-managed, memory-conscious resources; tvOS caches may be cleared. |
geox-url.mmdb | string | Managed / limited | Managed / limited | Managed / limited | Available through Hako-managed resources; manual paths and update behavior are platform-dependent. Uses Hako-managed, memory-conscious resources; tvOS caches may be cleared. |
global-client-fingerprint | string | Not applicable | Not applicable | Not applicable | Belongs to Android, Linux, or another non-Apple environment. |
global-ua | string | Supported | Supported | Supported | Consumed by the Hako core. |
hosts | map[string]any | Supported | Supported | Supported | Consumed by the Hako core. |
ipv6 | bool | Supported | Supported | Supported | Consumed by the Hako core. |
keep-alive-idle | int | Supported | Supported | Supported | Consumed by the Hako core. |
keep-alive-interval | int | Supported | Supported | Supported | Consumed by the Hako core. |
log-level | log.LogLevel | Supported | Supported | Supported | Consumed by the Hako core. |
mode | T.TunnelMode | Supported | Supported | Supported | Consumed by the Hako core. |
secret | string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
tcp-concurrent | bool | Supported | Supported | Supported | Consumed by the Hako core. |
unified-delay | bool | Supported | Supported | Supported | Consumed by the Hako core. |
allow-lan | bool | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
authentication | []string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
bind-address | string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
inbound-mptcp | bool | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
inbound-tfo | bool | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
interface-name | string | Unsupported | Unsupported | Unsupported | Linux-style interface, mark, or iptables routing is unavailable in Apple Packet Tunnel. |
iptables.bypass | []string | Not applicable | Not applicable | Not applicable | Belongs to Android, Linux, or another non-Apple environment. |
iptables.dns-redirect | bool | Not applicable | Not applicable | Not applicable | Belongs to Android, Linux, or another non-Apple environment. |
iptables.enable | bool | Not applicable | Not applicable | Not applicable | Belongs to Android, Linux, or another non-Apple environment. |
iptables.inbound-interface | string | Not applicable | Not applicable | Not applicable | Belongs to Android, Linux, or another non-Apple environment. |
lan-allowed-ips | []netip.Prefix | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
lan-disallowed-ips | []netip.Prefix | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
listeners | []map[string]any | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
mixed-port | int | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
port | int | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
redir-port | int | Unsupported | Unsupported | Unsupported | Removed or not consumed in the Apple Packet Tunnel runtime. |
routing-mark | int | Unsupported | Unsupported | Unsupported | Linux-style interface, mark, or iptables routing is unavailable in Apple Packet Tunnel. |
skip-auth-prefixes | []netip.Prefix | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
socks-port | int | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
ss-config | string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
tproxy-port | int | Unsupported | Unsupported | Unsupported | Removed or not consumed in the Apple Packet Tunnel runtime. |
tuic-server.alpn | []string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
tuic-server.authentication-timeout | int | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
tuic-server.certificate | string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
tuic-server.congestion-controller | string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
tuic-server.cwnd | int | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
tuic-server.enable | bool | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
tuic-server.listen | string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
tuic-server.max-idle-time | int | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
tuic-server.max-udp-relay-packet-size | int | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
tuic-server.private-key | string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
tuic-server.token | []string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
tuic-server.users | map[string]string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
tun.auto-detect-interface | bool | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.auto-redirect | bool | Not applicable | Not applicable | Not applicable | Belongs to Android, Linux, or another non-Apple environment. |
tun.auto-redirect-input-mark | uint32 | Not applicable | Not applicable | Not applicable | Belongs to Android, Linux, or another non-Apple environment. |
tun.auto-redirect-iproute2-fallback-rule-index | int | Not applicable | Not applicable | Not applicable | Belongs to Android, Linux, or another non-Apple environment. |
tun.auto-redirect-output-mark | uint32 | Not applicable | Not applicable | Not applicable | Belongs to Android, Linux, or another non-Apple environment. |
tun.auto-route | bool | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.device | string | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.disable-icmp-forwarding | bool | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.dns-hijack | []string | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.enable | bool | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.endpoint-independent-nat | bool | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.exclude-dst-port | []uint16 | Unsupported | Unsupported | Unsupported | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.exclude-dst-port-range | []string | Unsupported | Unsupported | Unsupported | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.exclude-interface | []string | Unsupported | Unsupported | Unsupported | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.exclude-mac-address | []string | Unsupported | Unsupported | Unsupported | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.exclude-package | []string | Not applicable | Not applicable | Not applicable | Belongs to Android, Linux, or another non-Apple environment. |
tun.exclude-src-port | []uint16 | Unsupported | Unsupported | Unsupported | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.exclude-src-port-range | []string | Unsupported | Unsupported | Unsupported | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.exclude-uid | []uint32 | Unsupported | Unsupported | Unsupported | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.exclude-uid-range | []string | Unsupported | Unsupported | Unsupported | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.file-descriptor | int | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.gso | bool | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.gso-max-size | uint32 | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.icmp-timeout | int64 | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.include-android-user | []int | Not applicable | Not applicable | Not applicable | Belongs to Android, Linux, or another non-Apple environment. |
tun.include-interface | []string | Unsupported | Unsupported | Unsupported | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.include-mac-address | []string | Unsupported | Unsupported | Unsupported | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.include-package | []string | Not applicable | Not applicable | Not applicable | Belongs to Android, Linux, or another non-Apple environment. |
tun.include-uid | []uint32 | Unsupported | Unsupported | Unsupported | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.include-uid-range | []string | Unsupported | Unsupported | Unsupported | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.inet4-route-address | []netip.Prefix | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.inet4-route-exclude-address | []netip.Prefix | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.inet6-address | []netip.Prefix | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.inet6-route-address | []netip.Prefix | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.inet6-route-exclude-address | []netip.Prefix | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.iproute2-rule-index | int | Not applicable | Not applicable | Not applicable | Belongs to Android, Linux, or another non-Apple environment. |
tun.iproute2-table-index | int | Not applicable | Not applicable | Not applicable | Belongs to Android, Linux, or another non-Apple environment. |
tun.loopback-address | []netip.Addr | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.mtu | uint32 | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.recvmsgx | bool | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.route-address | []netip.Prefix | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.route-address-set | []string | Not applicable | Not applicable | Not applicable | Belongs to Android, Linux, or another non-Apple environment. |
tun.route-exclude-address | []netip.Prefix | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.route-exclude-address-set | []string | Not applicable | Not applicable | Not applicable | Belongs to Android, Linux, or another non-Apple environment. |
tun.sendmsgx | bool | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.stack | C.TUNStack | Supported | Supported | Supported | iOS, macOS, and tvOS support gVisor, System, and Mixed. A dedicated Mixed runtime stack identifier will follow in a later Core delivery. |
tun.strict-route | bool | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tun.udp-timeout | int64 | Managed / limited | Managed / limited | Managed / limited | Apple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields. |
tunnels | []LC.Tunnel | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
vmess-config | string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
ntp.dialer-proxy | string | Managed / limited | Managed / limited | Managed / limited | Used as protocol time offset; it does not change the Apple system clock. |
ntp.enable | bool | Managed / limited | Managed / limited | Managed / limited | Used as protocol time offset; it does not change the Apple system clock. |
ntp.interval | int | Managed / limited | Managed / limited | Managed / limited | Used as protocol time offset; it does not change the Apple system clock. |
ntp.port | int | Managed / limited | Managed / limited | Managed / limited | Used as protocol time offset; it does not change the Apple system clock. |
ntp.server | string | Managed / limited | Managed / limited | Managed / limited | Used as protocol time offset; it does not change the Apple system clock. |
ntp.write-to-system | bool | Unsupported | Unsupported | Unsupported | Hako never writes the Apple system clock. |
profile.store-fake-ip | bool | Supported | Supported | Managed / limited | Consumed by the Hako core. Small state can persist, but tvOS file-backed data must be treated as clearable. |
profile.store-selected | bool | Supported | Supported | Managed / limited | Consumed by the Hako core. Small state can persist, but tvOS file-backed data must be treated as clearable. |
proxy-providers | map[string]map[string]any | Managed / limited | Managed / limited | Managed / limited | Hako downloads, validates, and materializes remote content in a product-managed path. Hako manages this provider cache; tvOS may clear it and the app must be able to rebuild it. |
rule-providers | map[string]map[string]any | Managed / limited | Managed / limited | Managed / limited | Hako downloads, validates, and materializes remote content in a product-managed path. Hako manages this provider cache; tvOS may clear it and the app must be able to rebuild it. |
proxies | []map[string]any | Supported | Supported | Supported | Consumed by the Hako core. |
proxy-groups | []map[string]any | Supported | Supported | Supported | Consumed by the Hako core. |
rules | []string | Supported | Supported | Supported | Consumed by the Hako core. |
sub-rules | map[string][]string | Supported | Supported | Supported | Consumed by the Hako core. |
tls.certificate | string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
tls.client-auth-cert | string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
tls.client-auth-type | string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
tls.custom-certifactes | []string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
tls.ech-key | string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
tls.private-key | string | Advanced | Advanced | Advanced | Can expose a listener or control surface. Use only with explicit access control and strong credentials. |
sniffer.enable | bool | Supported | Supported | Supported | Consumed by the Hako core. |
sniffer.force-dns-mapping | bool | Supported | Supported | Supported | Consumed by the Hako core. |
sniffer.force-domain | []string | Supported | Supported | Supported | Consumed by the Hako core. |
sniffer.override-destination | bool | Supported | Supported | Supported | Consumed by the Hako core. |
sniffer.parse-pure-ip | bool | Supported | Supported | Supported | Consumed by the Hako core. |
sniffer.port-whitelist | []string | Supported | Supported | Supported | Consumed by the Hako core. |
sniffer.skip-domain | []string | Supported | Supported | Supported | Consumed by the Hako core. |
sniffer.skip-dst-address | []string | Supported | Supported | Supported | Consumed by the Hako core. |
sniffer.skip-src-address | []string | Supported | Supported | Supported | Consumed by the Hako core. |
sniffer.sniff | map[string]RawSniffingConfig | Supported | Supported | Supported | Consumed by the Hako core. |
sniffer.sniffing | []string | Supported | Supported | Supported | Consumed by the Hako core. |
Version and sources
This page describes the shipping Hako / mihomo 1.19.30 core. The field list comes from Hako's current configuration pipeline and is informed by the pinned MetaCubeX configuration documentation. Upstream documentation defines mihomo semantics; Hako's adaptation and tests determine the Apple-platform status shown here.
The field reference is updated alongside stable Hako releases and Apple-platform adaptation.