Skip to content

sing-box — Config Layout ​

sing-box reads a single JSON document at startup. The root object maps to Go struct _Options at option/options.go:14 (exported as Options via a type alias whose UnmarshalJSONContext enforces strict unknown-field checking — typos in your config produce a startup error, not silent ignoring).

Root keys ​

KeyGo fieldTypePageDescription
$schemaSchemastring(none)JSON Schema URI for editor completion / validation; no runtime effect. sing-box schema generates one matching the current build.
logLog*LogOptionsLogSeverity, output, timestamp, disable toggle.
dnsDNS*DNSOptionsDNSDNS servers, rules, hosts, fakeip.
ntpNTP*NTPOptionsNTPOptional embedded NTP client.
certificateCertificate*CertificateOptionsCertificateRoot-CA bundle source for TLS verification.
certificate_providersCertificateProviders[]CertificateProviderTLSReusable certificate providers (acme, tailscale, cloudflare-origin-ca), referenced by tag from inbound TLS certificate_provider.
http_clientsHTTPClients[]HTTPClient(none)Reusable HTTP clients (engine, version, dialer, TLS, HTTP/2 / QUIC parameters) for remote rule-sets, certificate providers and DERP verify_client_url.
network_namespacesNetworkNamespaces[]NetworkNamespaceTUNLinux network namespaces (default, unshare), referenced by tag from the TUN, listen and dial netns fields.
endpointsEndpoints[]EndpointEndpointsEndpoint inbound/outbound (WireGuard, Tailscale, OpenVPN client / server, OpenConnect).
inboundsInbounds[]InboundInboundsList of listening services.
outboundsOutbounds[]OutboundOutboundsList of upstream targets.
routeRoute*RouteOptionsRouteRouting rules, rule-set, default outbound.
servicesServices[]ServiceServicesBackground services (resolved, derp, ssm-api, api, hysteria-realm, usbip-server / usbip-client).
experimentalExperimental*ExperimentalOptionsExperimentalCache file, Clash API, V2Ray API, pprof debug.

Each DNS server declares a type; the untyped "address": "tls://…" format is not supported (see DNS).

At a glance ​

json
{
  "log": { "level": "info", "timestamp": true },
  "dns": { "servers": [{ "type": "tls", "tag": "google", "server": "8.8.8.8" }] },
  "ntp": { "enabled": true, "server": "time.cloudflare.com" },
  "certificate": { "store": "system" },
  "inbounds": [],
  "outbounds": [],
  "route": { "final": "direct" },
  "experimental": {
    "cache_file": { "enabled": true },
    "clash_api": { "external_controller": "127.0.0.1:9090" }
  }
}

Source: option/options.go:14-31 · v1.14.2 (af6e64c)

Core Tutorial by Argsment