...

Your subscription link is a credential, not a setting

AllianceInterStellar TeamSeptember 17, 2026
AllianceInterStellar TeamopSeptember 17, 2026

A distinction that matters more than it looks like it should.

A node link is a single endpoint frozen at the moment you pasted it. The schemes the app recognises:

vless:// · vmess:// · trojan:// · ss:// · hysteria2:// (also hy2://, hy://) · tuic:// · wg:// · ssh:// · warp://

A WireGuard configuration pasted as text is recognised too, by its [Interface] header.

An http:// or https:// URL is a subscription. It is fetched, and can be refreshed later to pick up nodes your provider added or removed. That is the difference — a pasted node never changes, a subscription does.

Why we call it a credential

Anyone holding your subscription URL can use your service. It is not a configuration value to paste into a support thread, a screenshot, or an issue report. A QR code of one is the same credential in a form that is easy to photograph over your shoulder.

If you think one has leaked, regenerate it with your provider rather than trying to work out whether it was used.

The same goes for settings exports. A full export is plain text and can carry account-linked secrets. Where the app offers an *anonymised* export, use that one when sharing with someone else.