Skip to content

Inbounds ​

inbounds is the array of listening services. Unlike Xray-core there is no nested settings block: each entry is a flat object — the type / tag envelope below plus the selected type's own fields merged at the same level. The envelope is decoded first, then the remaining keys are decoded into the option struct registered for type, with unknown fields rejected.

Envelope ​

FieldTypeDefaultAllowed valuesDescription
typestring—tun | redirect | tproxy | direct | socks | http | mixed | shadowsocks | snell | vmess | trojan | naive | shadowtls | vless | anytls | hysteria | tuic | hysteria2 | cloudflaredInbound type. Selects which option struct the rest of the object is decoded into. An unregistered value fails at startup with "unknown inbound type".
tagstring——Unique name for this inbound. Referenced by routing rules (inbound) and by log lines.

Source: option/inbound.go:21-25 · pinned at v1.14.2 (af6e64c)

Per-type fields are documented on the protocol pages: TUN, Redirect & TProxy, Direct, HTTP & SOCKS (also mixed), Shadowsocks, VMess, Trojan, Naive, VLESS, AnyTLS, Hysteria2, TUIC. snell and cloudflared are documented on Snell and cloudflared.

Shared listen fields (ListenOptions) ​

Every socket-based inbound embeds ListenOptions; the fields appear at the same flat level as the envelope.

FieldTypeDefaultAllowed valuesDescription
listen*badoption.Addr——Address to bind, e.g. "::" or "127.0.0.1".
listen_portuint16——Port to listen on.
bind_interfacestring——Network interface to bind the listener to.
routing_markFwMark——SO_MARK (fwmark) to set on the listening socket. Linux only.
reuse_addrboolfalsetrue | falseSet SO_REUSEADDR on the listener.
netnsstring——Network namespace to listen in: a name or path, or the tag of a top-level network_namespaces entry. Linux only.
disable_tcp_keep_aliveboolfalsetrue | falseTurn TCP keep-alive off for accepted connections.
tcp_keep_alivebadoption.Duration——Keep-alive idle period before probes start. Duration string, e.g. "15m".
tcp_keep_alive_intervalbadoption.Duration——Interval between keep-alive probes. Duration string.
tcp_fast_openboolfalsetrue | falseEnable TCP Fast Open on the listener.
tcp_multi_pathboolfalsetrue | falseEnable Multipath TCP (requires Go MPTCP support on the platform).
udp_fragment*boolfalsetrue | falseAllow fragmenting UDP packets larger than the MTU instead of dropping them.
udp_timeoutUDPTimeoutCompat——Idle timeout for UDP NAT entries. Duration string; the effective default depends on the sniffed protocol.
detourstring——Forward accepted connections straight into another inbound, addressed by its tag.
proxy_protocolbool——Not supported: there is no PROXY-protocol header support; setting it is an error.
proxy_protocol_accept_no_headerbool——Not supported, like proxy_protocol.

Source: option/inbound.go:79-103 · pinned at v1.14.2 (af6e64c)

Minimal example ​

json
{
  "inbounds": [
    {
      "type": "mixed",
      "tag": "mixed-in",
      "listen": "127.0.0.1",
      "listen_port": 2080
    }
  ]
}

Notes ​

  • The strict unmarshaler applies inside inbound entries too: a typo in any field name is a startup error, not silently ignored.
  • Inbounds have no sniffing fields: sniff, sniff_override_destination, sniff_timeout, domain_strategy and udp_disable_domain_unmapping are rejected at startup with an error pointing to the rule-actions migration. Sniffing lives in route rules.
  • shadowsocksr is registered only as a stub that errors: sing-box has no ShadowsocksR implementation.
  • hysteria, tuic and hysteria2 require a build with the with_quic tag, and cloudflared one with with_cloudflared (official release binaries include both).
  • snell is the Snell server side, matching the snell outbound.
  • cloudflared runs an embedded Cloudflare Tunnel client, authenticated by the tunnel token, and routes the tunnel's incoming TCP, UDP and ICMP traffic through sing-box's router. It does not listen on a local socket, so ListenOptions does not apply to it.

Cross-core notes ​

  • Xray-core nests protocol fields in a settings object and keeps sniffing per-inbound. See Xray Inbounds.
  • mihomo uses individual root keys (port, socks-port, mixed-port, …) plus a listeners list. See HTTP & SOCKS and Redirect & TProxy.

Source: option/inbound.go:21-25 · v1.14.2 (af6e64c)

Core Tutorial by Argsment