Skip to content

Hako configuration reference

Use this reference whenever you need to inspect mihomo YAML. A first configuration does not need to begin with 185 fields: start with the best-practice template, then return to the exact field when a specific need appears.

Keep the configuration understandable

A trusted configuration that contains only what you need is easier to verify and less likely to produce surprising behavior after an update.

Browse by topic

Field support status

  • Supported: consumed directly by the Hako core.
  • Managed / limited: accepted, but repaired, forced, or replaced for Apple networking.
  • Advanced: recognized by the core but may open a local service or control surface.
  • Unsupported: removed or ineffective inside Apple Packet Tunnel.
  • Not applicable: belongs to Android, Linux, or another environment.

185 fields shown

FieldTypeiOSmacOStvOSPlatform notes
dns.cache-algorithmstringSupportedSupportedSupportedConsumed by the Hako core.
dns.cache-max-sizeintSupportedSupportedSupportedConsumed by the Hako core.
dns.default-nameserver[]stringManaged / limitedManaged / limitedManaged / limitedAccepted, but Hako may force, repair, split, or replace the value for Apple networking.
dns.direct-nameserver[]stringSupportedSupportedSupportedConsumed by the Hako core.
dns.direct-nameserver-follow-policyboolSupportedSupportedSupportedConsumed by the Hako core.
dns.enableboolManaged / limitedManaged / limitedManaged / limitedAccepted, but Hako may force, repair, split, or replace the value for Apple networking.
dns.enhanced-modeC.DNSModeSupportedSupportedSupportedConsumed by the Hako core.
dns.fake-ip-filter[]stringSupportedSupportedSupportedConsumed by the Hako core.
dns.fake-ip-filter-modeC.FilterModeSupportedSupportedSupportedConsumed by the Hako core.
dns.fake-ip-rangestringSupportedSupportedSupportedConsumed by the Hako core.
dns.fake-ip-range6stringSupportedSupportedSupportedConsumed by the Hako core.
dns.fake-ip-ttlintSupportedSupportedSupportedConsumed by the Hako core.
dns.fallback[]stringSupportedSupportedSupportedConsumed by the Hako core.
dns.fallback-filter.domain[]stringSupportedSupportedSupportedConsumed by the Hako core.
dns.fallback-filter.geoipboolSupportedSupportedSupportedConsumed by the Hako core.
dns.fallback-filter.geoip-codestringSupportedSupportedSupportedConsumed by the Hako core.
dns.fallback-filter.geosite[]stringSupportedSupportedSupportedConsumed by the Hako core.
dns.fallback-filter.ipcidr[]stringSupportedSupportedSupportedConsumed by the Hako core.
dns.fallback-lazy-queryboolSupportedSupportedSupportedConsumed by the Hako core.
dns.ipv6boolSupportedSupportedSupportedConsumed by the Hako core.
dns.ipv6-timeoutuintSupportedSupportedSupportedConsumed by the Hako core.
dns.listenstringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
dns.listen-routing-markintUnsupportedUnsupportedUnsupportedRemoved or not consumed in the Apple Packet Tunnel runtime.
dns.nameserver[]stringSupportedSupportedSupportedConsumed by the Hako core.
dns.nameserver-policy*orderedmap.OrderedMap[string, any]SupportedSupportedSupportedConsumed by the Hako core.
dns.prefer-h3boolSupportedSupportedSupportedConsumed by the Hako core.
dns.proxy-server-nameserver[]stringSupportedSupportedSupportedConsumed by the Hako core.
dns.proxy-server-nameserver-policy*orderedmap.OrderedMap[string, any]SupportedSupportedSupportedConsumed by the Hako core.
dns.respect-rulesboolSupportedSupportedSupportedConsumed by the Hako core.
dns.use-hostsboolSupportedSupportedSupportedConsumed by the Hako core.
dns.use-system-hostsboolSupportedSupportedSupportedConsumed by the Hako core.
experimental.dialer-ip4p-convertboolAdvancedAdvancedAdvancedParsed by the core, but not a stable product-level promise.
experimental.fingerprints[]stringAdvancedAdvancedAdvancedParsed by the core, but not a stable product-level promise.
experimental.quic-go-disable-ecnboolAdvancedAdvancedAdvancedParsed by the core, but not a stable product-level promise.
experimental.quic-go-disable-gsoboolAdvancedAdvancedAdvancedParsed by the core, but not a stable product-level promise.
clash-for-android.append-system-dnsboolNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
clash-for-android.ui-subtitle-patternstringNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
disable-keep-aliveboolSupportedSupportedSupportedConsumed by the Hako core.
etag-supportboolSupportedSupportedSupportedConsumed by the Hako core.
external-controllerstringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
external-controller-cors.allow-origins[]stringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
external-controller-cors.allow-private-networkboolAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
external-controller-pipestringNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
external-controller-routing-markintNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
external-controller-tlsstringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
external-controller-unixstringAdvancedAdvancedUnsupportedCan expose a listener or control surface. Use only with explicit access control and strong credentials. Unix-domain controller sockets are unavailable on tvOS.
external-doh-serverstringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
external-uistringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
external-ui-namestringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
external-ui-urlstringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
find-process-modeprocess.FindProcessModeUnsupportedSupportedUnsupportedRemoved or not consumed in the Apple Packet Tunnel runtime. Consumed by the Hako core.
geo-auto-updateboolManaged / limitedManaged / limitedManaged / limitedAvailable through Hako-managed resources; manual paths and update behavior are platform-dependent. Uses Hako-managed, memory-conscious resources; tvOS caches may be cleared.
geo-update-intervalintNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
geodata-loaderstringManaged / limitedManaged / limitedManaged / limitedAvailable through Hako-managed resources; manual paths and update behavior are platform-dependent. Uses Hako-managed, memory-conscious resources; tvOS caches may be cleared.
geodata-modeboolManaged / limitedManaged / limitedManaged / limitedAvailable through Hako-managed resources; manual paths and update behavior are platform-dependent. Uses Hako-managed, memory-conscious resources; tvOS caches may be cleared.
geosite-matcherstringSupportedSupportedSupportedConsumed by the Hako core.
geox-url.asnstringManaged / limitedManaged / limitedManaged / limitedAvailable through Hako-managed resources; manual paths and update behavior are platform-dependent. Uses Hako-managed, memory-conscious resources; tvOS caches may be cleared.
geox-url.geoipstringManaged / limitedManaged / limitedManaged / limitedAvailable through Hako-managed resources; manual paths and update behavior are platform-dependent. Uses Hako-managed, memory-conscious resources; tvOS caches may be cleared.
geox-url.geositestringManaged / limitedManaged / limitedManaged / limitedAvailable through Hako-managed resources; manual paths and update behavior are platform-dependent. Uses Hako-managed, memory-conscious resources; tvOS caches may be cleared.
geox-url.mmdbstringManaged / limitedManaged / limitedManaged / limitedAvailable through Hako-managed resources; manual paths and update behavior are platform-dependent. Uses Hako-managed, memory-conscious resources; tvOS caches may be cleared.
global-client-fingerprintstringNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
global-uastringSupportedSupportedSupportedConsumed by the Hako core.
hostsmap[string]anySupportedSupportedSupportedConsumed by the Hako core.
ipv6boolSupportedSupportedSupportedConsumed by the Hako core.
keep-alive-idleintSupportedSupportedSupportedConsumed by the Hako core.
keep-alive-intervalintSupportedSupportedSupportedConsumed by the Hako core.
log-levellog.LogLevelSupportedSupportedSupportedConsumed by the Hako core.
modeT.TunnelModeSupportedSupportedSupportedConsumed by the Hako core.
secretstringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tcp-concurrentboolSupportedSupportedSupportedConsumed by the Hako core.
unified-delayboolSupportedSupportedSupportedConsumed by the Hako core.
allow-lanboolAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
authentication[]stringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
bind-addressstringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
inbound-mptcpboolAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
inbound-tfoboolAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
interface-namestringUnsupportedUnsupportedUnsupportedLinux-style interface, mark, or iptables routing is unavailable in Apple Packet Tunnel.
iptables.bypass[]stringNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
iptables.dns-redirectboolNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
iptables.enableboolNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
iptables.inbound-interfacestringNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
lan-allowed-ips[]netip.PrefixAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
lan-disallowed-ips[]netip.PrefixAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
listeners[]map[string]anyAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
mixed-portintAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
portintAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
redir-portintUnsupportedUnsupportedUnsupportedRemoved or not consumed in the Apple Packet Tunnel runtime.
routing-markintUnsupportedUnsupportedUnsupportedLinux-style interface, mark, or iptables routing is unavailable in Apple Packet Tunnel.
skip-auth-prefixes[]netip.PrefixAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
socks-portintAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
ss-configstringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tproxy-portintUnsupportedUnsupportedUnsupportedRemoved or not consumed in the Apple Packet Tunnel runtime.
tuic-server.alpn[]stringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tuic-server.authentication-timeoutintAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tuic-server.certificatestringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tuic-server.congestion-controllerstringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tuic-server.cwndintAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tuic-server.enableboolAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tuic-server.listenstringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tuic-server.max-idle-timeintAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tuic-server.max-udp-relay-packet-sizeintAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tuic-server.private-keystringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tuic-server.token[]stringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tuic-server.usersmap[string]stringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tun.auto-detect-interfaceboolManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.auto-redirectboolNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
tun.auto-redirect-input-markuint32Not applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
tun.auto-redirect-iproute2-fallback-rule-indexintNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
tun.auto-redirect-output-markuint32Not applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
tun.auto-routeboolManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.devicestringManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.disable-icmp-forwardingboolManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.dns-hijack[]stringManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.enableboolManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.endpoint-independent-natboolManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.exclude-dst-port[]uint16UnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.exclude-dst-port-range[]stringUnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.exclude-interface[]stringUnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.exclude-mac-address[]stringUnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.exclude-package[]stringNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
tun.exclude-src-port[]uint16UnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.exclude-src-port-range[]stringUnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.exclude-uid[]uint32UnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.exclude-uid-range[]stringUnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.file-descriptorintManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.gsoboolManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.gso-max-sizeuint32Managed / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.icmp-timeoutint64Managed / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.include-android-user[]intNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
tun.include-interface[]stringUnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.include-mac-address[]stringUnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.include-package[]stringNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
tun.include-uid[]uint32UnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.include-uid-range[]stringUnsupportedUnsupportedUnsupportedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.inet4-route-address[]netip.PrefixManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.inet4-route-exclude-address[]netip.PrefixManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.inet6-address[]netip.PrefixManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.inet6-route-address[]netip.PrefixManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.inet6-route-exclude-address[]netip.PrefixManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.iproute2-rule-indexintNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
tun.iproute2-table-indexintNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
tun.loopback-address[]netip.AddrManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.mtuuint32Managed / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.recvmsgxboolManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.route-address[]netip.PrefixManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.route-address-set[]stringNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
tun.route-exclude-address[]netip.PrefixManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.route-exclude-address-set[]stringNot applicableNot applicableNot applicableBelongs to Android, Linux, or another non-Apple environment.
tun.sendmsgxboolManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.stackC.TUNStackSupportedSupportedSupportediOS, macOS, and tvOS support gVisor, System, and Mixed. A dedicated Mixed runtime stack identifier will follow in a later Core delivery.
tun.strict-routeboolManaged / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tun.udp-timeoutint64Managed / limitedManaged / limitedManaged / limitedApple Network Extension owns routes and interfaces; Hako may force or ignore desktop TUN fields.
tunnels[]LC.TunnelAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
vmess-configstringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
ntp.dialer-proxystringManaged / limitedManaged / limitedManaged / limitedUsed as protocol time offset; it does not change the Apple system clock.
ntp.enableboolManaged / limitedManaged / limitedManaged / limitedUsed as protocol time offset; it does not change the Apple system clock.
ntp.intervalintManaged / limitedManaged / limitedManaged / limitedUsed as protocol time offset; it does not change the Apple system clock.
ntp.portintManaged / limitedManaged / limitedManaged / limitedUsed as protocol time offset; it does not change the Apple system clock.
ntp.serverstringManaged / limitedManaged / limitedManaged / limitedUsed as protocol time offset; it does not change the Apple system clock.
ntp.write-to-systemboolUnsupportedUnsupportedUnsupportedHako never writes the Apple system clock.
profile.store-fake-ipboolSupportedSupportedManaged / limitedConsumed by the Hako core. Small state can persist, but tvOS file-backed data must be treated as clearable.
profile.store-selectedboolSupportedSupportedManaged / limitedConsumed by the Hako core. Small state can persist, but tvOS file-backed data must be treated as clearable.
proxy-providersmap[string]map[string]anyManaged / limitedManaged / limitedManaged / limitedHako downloads, validates, and materializes remote content in a product-managed path. Hako manages this provider cache; tvOS may clear it and the app must be able to rebuild it.
rule-providersmap[string]map[string]anyManaged / limitedManaged / limitedManaged / limitedHako downloads, validates, and materializes remote content in a product-managed path. Hako manages this provider cache; tvOS may clear it and the app must be able to rebuild it.
proxies[]map[string]anySupportedSupportedSupportedConsumed by the Hako core.
proxy-groups[]map[string]anySupportedSupportedSupportedConsumed by the Hako core.
rules[]stringSupportedSupportedSupportedConsumed by the Hako core.
sub-rulesmap[string][]stringSupportedSupportedSupportedConsumed by the Hako core.
tls.certificatestringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tls.client-auth-certstringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tls.client-auth-typestringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tls.custom-certifactes[]stringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tls.ech-keystringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
tls.private-keystringAdvancedAdvancedAdvancedCan expose a listener or control surface. Use only with explicit access control and strong credentials.
sniffer.enableboolSupportedSupportedSupportedConsumed by the Hako core.
sniffer.force-dns-mappingboolSupportedSupportedSupportedConsumed by the Hako core.
sniffer.force-domain[]stringSupportedSupportedSupportedConsumed by the Hako core.
sniffer.override-destinationboolSupportedSupportedSupportedConsumed by the Hako core.
sniffer.parse-pure-ipboolSupportedSupportedSupportedConsumed by the Hako core.
sniffer.port-whitelist[]stringSupportedSupportedSupportedConsumed by the Hako core.
sniffer.skip-domain[]stringSupportedSupportedSupportedConsumed by the Hako core.
sniffer.skip-dst-address[]stringSupportedSupportedSupportedConsumed by the Hako core.
sniffer.skip-src-address[]stringSupportedSupportedSupportedConsumed by the Hako core.
sniffer.sniffmap[string]RawSniffingConfigSupportedSupportedSupportedConsumed by the Hako core.
sniffer.sniffing[]stringSupportedSupportedSupportedConsumed by the Hako core.

Version and sources

This page describes the shipping Hako / mihomo 1.19.30 core. The field list comes from Hako's current configuration pipeline and is informed by the pinned MetaCubeX configuration documentation. Upstream documentation defines mihomo semantics; Hako's adaptation and tests determine the Apple-platform status shown here.

The field reference is updated alongside stable Hako releases and Apple-platform adaptation.