iOS must-read: why you delete the old config and re-scan after regenerating your UUID
Plenty of iOS users hit 'Regenerate UUID' in the console, and suddenly their client (Shadowrocket, Streisand, and the like) can't connect. The first reaction is usually 'is the node down?' The node is fine — the real problem is that the config you imported into your client is tightly bound to your UUID. Change the UUID and the old config dies instantly. Once you understand the link, recovery is just a few taps.
What exactly is a UUID
A UUID is the unique credential the server uses to know 'who you are.' Every VLESS node and every subscription you save in a client embeds that UUID inside the link (something like vless://your-uuid@server-address...). When the server receives a connection, it uses that UUID to decide whether you're a valid user and whose traffic to bill. Think of it as the key to your line.
Change the UUID and the old config dies immediately
After regenerating your UUID, the server only accepts the new key. The old nodes and cached subscriptions in your client still carry the old key — the server rejects them outright, so nothing connects. This isn't a node failure; the key simply no longer matches.
The correct four steps on iOS after rotating your UUID
- 1
Delete the old config in your client
In Shadowrocket / Streisand and similar clients, remove the old nodes and old subscription entries you imported earlier. This is the critical step — leftover old entries will never connect and only cloud your troubleshooting.
- 2
Sign back in on the web
Regenerating your UUID signs out all your devices. Log back into the console with your username and password.
- 3
Get the subscription again from the Nodes page
Open the Nodes page in the console and tap 'Get subscription QR.' The subscription/QR you get here already carries the new UUID.
- 4
Re-scan / re-add the subscription in your client
Scan the new QR with your client, or copy the new subscription link and add it. Now the key matches and your connection is restored.
Why deleting the old config is a security must
The whole point of regenerating your UUID is to instantly invalidate an old subscription URL that may have leaked. If you only add the new config but leave the old one on your device, the old UUID lingers — it can misconnect and, worse, it undercuts the security value of the rotation. Deleting the old config is what makes it a clean key rotation.
Remember one line: a new UUID means a new key, which means every old config is void. On iOS, 'delete the old config + re-scan to add it' isn't optional after regenerating your UUID — it's a required step every single time.