Inbounds
inbounds is the array of listening services. Unlike Xray-core there is no nested settings block: each entry is a flat object — the type / tag envelope below plus the selected type's own fields merged at the same level. The envelope is decoded first, then the remaining keys are decoded into the option struct registered for type, with unknown fields rejected.
Envelope
| Field | Type | Default | Allowed values | Description |
|---|---|---|---|---|
type | string | — | tun | redirect | tproxy | direct | socks | http | mixed | shadowsocks | snell | vmess | trojan | naive | shadowtls | vless | anytls | hysteria | tuic | hysteria2 | cloudflared | Inbound type. Selects which option struct the rest of the object is decoded into. An unregistered value fails at startup with "unknown inbound type". |
tag | string | — | — | Unique name for this inbound. Referenced by routing rules (inbound) and by log lines. |
Source: option/inbound.go:21-25 · pinned at v1.14.2 (af6e64c)
Per-type fields are documented on the protocol pages: TUN, Redirect & TProxy, Direct, HTTP & SOCKS (also mixed), Shadowsocks, VMess, Trojan, Naive, VLESS, AnyTLS, Hysteria2, TUIC. snell and cloudflared are documented on Snell and cloudflared.
Shared listen fields (ListenOptions)
Every socket-based inbound embeds ListenOptions; the fields appear at the same flat level as the envelope.
| Field | Type | Default | Allowed values | Description |
|---|---|---|---|---|
listen | *badoption.Addr | — | — | Address to bind, e.g. "::" or "127.0.0.1". |
listen_port | uint16 | — | — | Port to listen on. |
bind_interface | string | — | — | Network interface to bind the listener to. |
routing_mark | FwMark | — | — | SO_MARK (fwmark) to set on the listening socket. Linux only. |
reuse_addr | bool | false | true | false | Set SO_REUSEADDR on the listener. |
netns | string | — | — | Network namespace to listen in: a name or path, or the tag of a top-level network_namespaces entry. Linux only. |
disable_tcp_keep_alive | bool | false | true | false | Turn TCP keep-alive off for accepted connections. |
tcp_keep_alive | badoption.Duration | — | — | Keep-alive idle period before probes start. Duration string, e.g. "15m". |
tcp_keep_alive_interval | badoption.Duration | — | — | Interval between keep-alive probes. Duration string. |
tcp_fast_open | bool | false | true | false | Enable TCP Fast Open on the listener. |
tcp_multi_path | bool | false | true | false | Enable Multipath TCP (requires Go MPTCP support on the platform). |
udp_fragment | *bool | false | true | false | Allow fragmenting UDP packets larger than the MTU instead of dropping them. |
udp_timeout | UDPTimeoutCompat | — | — | Idle timeout for UDP NAT entries. Duration string; the effective default depends on the sniffed protocol. |
detour | string | — | — | Forward accepted connections straight into another inbound, addressed by its tag. |
proxy_protocol | bool | — | — | Not supported: there is no PROXY-protocol header support; setting it is an error. |
proxy_protocol_accept_no_header | bool | — | — | Not supported, like proxy_protocol. |
Source: option/inbound.go:79-103 · pinned at v1.14.2 (af6e64c)
Minimal example
{
"inbounds": [
{
"type": "mixed",
"tag": "mixed-in",
"listen": "127.0.0.1",
"listen_port": 2080
}
]
}Notes
- The strict unmarshaler applies inside inbound entries too: a typo in any field name is a startup error, not silently ignored.
- Inbounds have no sniffing fields:
sniff,sniff_override_destination,sniff_timeout,domain_strategyandudp_disable_domain_unmappingare rejected at startup with an error pointing to the rule-actions migration. Sniffing lives in route rules. shadowsocksris registered only as a stub that errors: sing-box has no ShadowsocksR implementation.hysteria,tuicandhysteria2require a build with thewith_quictag, andcloudflaredone withwith_cloudflared(official release binaries include both).snellis the Snell server side, matching thesnelloutbound.cloudflaredruns an embedded Cloudflare Tunnel client, authenticated by the tunneltoken, and routes the tunnel's incoming TCP, UDP and ICMP traffic through sing-box's router. It does not listen on a local socket, soListenOptionsdoes not apply to it.
Cross-core notes
- Xray-core nests protocol fields in a
settingsobject and keeps sniffing per-inbound. See Xray Inbounds. - mihomo uses individual root keys (
port,socks-port,mixed-port, …) plus alistenerslist. See HTTP & SOCKS and Redirect & TProxy.
Source: option/inbound.go:21-25 · v1.14.2 (af6e64c)
