Local configuration tool
Hysteria2 to sing-box JSON
Bandwidth becomes up_mbps and down_mbps, and port hopping becomes the server_ports array.
Conversion happens entirely in your browser. Links are not uploaded, saved, or placed in the page URL.
Conversion result
Why some links are rejected
A parameter that cannot be mapped without changing how the connection behaves is reported rather than dropped. For sing-box that mostly means XHTTP, a transport it does not have at all, plus certificate pinning and TUIC v4 tokens. Renames that sing-box does read — reduce_rtt becoming zero_rtt_handshake — happen here instead of failing quietly on your device.
How to import into sing-box
Save the JSON as your config file, or import it as a local profile in SFI, SFA or SFM. The Proxy selector outbound is already wired up, so switching nodes does not mean editing the file.
How Hysteria2 fields map to sing-box
What this converter actually does, line by line. On the left is how it is written in a Hysteria2 link; on the right is the field it becomes in the sing-box config.
| In the link | In the sing-box config | Notes |
|---|---|---|
password@host:port | password / server / server_port | The Hysteria 2 URI spec allows a colon inside the auth string, so it is kept intact. |
sni | tls.server_name | Hysteria2 runs over QUIC, so TLS is always on and neither target has a tls toggle to set. |
obfs=salamander + obfs-password | obfs.type / obfs.password | salamander is the only obfuscation defined; obfs without a password is an error. |
up / down | up_mbps / down_mbps (100) | Mihomo wants a string with a unit, sing-box wants a bare number. Both are produced for you. |
mport | server_ports (["8000:9000"]) | Port hopping. The separators differ — a hyphen in Mihomo, a colon in sing-box. |
alpn / insecure | tls.alpn / tls.insecure | insecure and allowInsecure are the same parameter; using both is an error. |
pinSHA256 | Rejected with an error | Certificate pinning has no equivalent field in either target, and dropping it would weaken the connection. |
fp | Rejected with an error | uTLS fingerprints are a TCP-TLS concept; a QUIC handshake has nowhere to put one. |
FAQ
- Which client do I use after converting Hysteria2 to sing-box?
- Use an official sing-box 1.11+ client (SFI, SFA and SFM included). Versions below 1.11 reject the route rule actions this config uses and fail to load.
- Is this Hysteria2 converter free, and does it upload my node links?
- It is free and needs no account. The conversion is done by JavaScript inside this page, on your own machine: links are never uploaded, never written into the page URL, and never stored. Closing the tab is all the cleanup there is.
- Can I convert a subscription link straight to sing-box?
- Yes, but paste the body the subscription URL returns — usually one long base64 string — rather than the URL itself, which the browser cannot fetch across origins. Mixed protocols in one subscription are fine. Subscription to sing-box converter
- The sing-box config converted fine but will not connect — what now?
- This page only translates links into a config: it checks the structure, never whether the server is reachable. Confirm the same link works in the client you copied it from, then check the client version — server_ports and route rule actions need sing-box 1.11 or newer.
This creates a one-time local configuration, not an auto-updating subscription. It checks configuration structure, not whether a server is reachable.