# free-nodes/clashfree: A Daily-Updated Clash Subscription Feed and What It Actually Contains

> The repository publishes one YAML subscription file per day and a README that mixes node dumps, client links and affiliate airport promotions. Here is what the files hold, how to point a Clash client at them, and why the whole thing is a stopgap rather than a service.

**free-nodes/clashfree** — clash节点、免费clash节点、免费节点、免费梯子、clash科学上网、clash翻墙、clash订阅链接、clash for Windows、clash教程、免费公益节点、最新clash免费节点订阅地址、clash免费节点每日更新

- Repository: https://github.com/free-nodes/clashfree
- Website: https://clashgithub.com
- Stars: 16,753 · Forks: 1,370
- Language: Unknown
- License: not declared
- Published: 2026-09-21 · Updated: 2026-09-21 · Language: en
- Canonical page: https://hysenlabs.com/projects/free-nodes-clashfree

## What free-nodes/clashfree publishes, and who it is aimed at

This repository is not software. It is a publishing pipeline whose output is a Clash-format YAML file. The README states that all free Clash nodes are scraped from the network and asks that they not be used for illegal purposes. The top-level directory listing shows the shape of that output: README.md, sub.png, sub.yml, and one dated file per day, clash20260917.yml through clash20260921.yml. The README's own update line carries a timestamp, 2026-09-21 13:29:13, which is consistent with a scheduled job that rewrites the README and drops a new dated file.

The audience is narrow. It is for someone who already runs a Clash-compatible client (Clash Verge Rev, Clash Meta for Android, shadowrocket, flclash, all linked from the README's client table) and who wants a subscription URL to paste in without paying for one. The README also links a Clash for Windows tutorial. Nothing here helps you run a server, choose a protocol, or diagnose a failing tunnel. It is a supply of endpoints, refreshed daily, and that is the entire product.

## Reading the dated YAML: ports, controller and proxy entries

The README embeds a sample of the subscription format. The header block sets port: 7890 for HTTP, socks-port: 7891, allow-lan: true, mode: Rule, log-level: info, and external-controller: 127.0.0.1:9090. Those are the standard Clash listener defaults; the external controller on loopback is what a GUI client talks to. Two choices in that header deserve attention. allow-lan: true means the proxy listeners bind beyond loopback, so on a shared network the proxy port is reachable by other machines unless the client or the OS firewall blocks it. mode: Rule means traffic is routed by rules rather than everything going through the tunnel, and the sample shown does not include a rules block, so the client's own default rule set applies.

Below the header the file is a flat proxies list. Every entry in the sample follows the same shape: a name like "未知 SS-01 | free-nodes", a server IP, a port, type: ss, cipher: 2022-blake3-chacha20-poly1305, and a base64 password. The ports cluster on a handful of values (61312, 56927, 45819, 59924, 59319, 50356), which suggests the endpoints are not independent but come from a small number of hosts or a shared template. The names carry no geography, no provider and no load information, so a client's latency test is the only signal you get about which one works. There is no update interval, no health check and no expiry field in the sample.

## Loading the subscription into a Clash client

The repository ships no installer. The README points to client downloads in a wiki under a separate account, so the install step happens outside this project. On desktop, Clash Verge Rev is the Windows entry in the client table; on Android, Clash Meta for Android; on iOS, shadowrocket; on macOS, flclash. Install one of those first, because the YAML is useless without a Clash-compatible core to parse it.

Once a client is running, the practical move is to open the README's download link, which points at the dated file for the current day, for example clash20260921.yml. The repository keeps the previous days alongside it, so you can pick a specific date instead of always taking the newest. The README's own header block, which is what a client expects to find at the top of the file, looks like this:

```yaml
port: 7890
socks-port: 7891
allow-lan: true
mode: Rule
log-level: info
external-controller: 127.0.0.1:9090
```

Before importing, inspect the file in a text editor. Count the proxy entries to see whether the day's scrape produced anything usable, and check that the controller line matches the loopback value shown above. If it points at a remote address instead, change it to 127.0.0.1:9090 before loading the file, because a remote controller endpoint exposes the client's API to whoever owns that address. Then import the local file into your client as a profile and run the built-in latency test; the sample gives no other way to rank the entries.

## The failure modes you should expect from a scraped node list

The most likely outcome on any given day is that a large share of the proxies do not connect. These are scraped endpoints, and the README says so. A Shadowsocks server that was alive when the scrape ran can be offline, rate-limited, or reconfigured by the time you import the file. Because every entry uses the same cipher and a similar port set, a single upstream change can take out a whole group at once rather than degrading gradually.

The second failure mode is trust. You are routing traffic through machines you did not choose, operated by someone you cannot identify, with credentials published in a public Git repository. The README's own warning about illegal use is a disclaimer, not a security control. Anything sent through those proxies is visible to the endpoint operator to the extent the protocol and the destination allow. A subscription feed like this is the wrong tool for logging into a work account, handling payment details, or anything where the operator of the exit node matters.

The third is durability. The repository has no releases, no licence file and no issue tracker visible in the listing. The README's update timestamp shows the pipeline ran on 2026-09-21, and the last push to the repository was on 2026-09-21, so the feed is current as of that date. That says nothing about next month. There is no versioning, no changelog and no deprecation notice; when the pipeline stops, the newest file simply stops changing, and a client configured against the raw URL keeps loading the same stale list.

## How this differs from a paid airport subscription

The README itself makes the comparison, and not subtly. Two airport promotions sit above the node dump: ORYMI, described with a free tier of 20 GB, a 5 Mbps bandwidth limit, one simultaneous device and streaming unlocks, and 星辰加速, described as 9 yuan per month with 150 GB, no bandwidth limit and no device cap. Both entries carry referral links and discount codes, and both are followed by a note that the jump link may be blocked and that you should use the unstable free subscription below first if it fails.

That note is the honest part of the page. The difference in approach is not protocol or client support; both sides feed the same Clash client. It is who operates the endpoint. An airport subscription is a commercial relationship with a named operator, a stated quota and a support channel, and the free nodes here are an unattributed scrape with none of those. The trade is explicit: the README offers the free list as a way to reach the paid links when the paid links are unreachable. If your requirement is a stable exit with a quota you can plan around, the airport model is the one that matches it, and this repository is the fallback, not the other way round.

## Licence, maintenance and what upgrading actually means here

There is no licence file in the repository listing, which matters more than it does for a typical project. The YAML files redistribute connection credentials for servers the project does not own, scraped from sources it does not name. A licence file would not resolve that; its absence just removes any stated permission to reuse the content. Treat the files as data you consume at your own risk rather than as a project you can fork, vendor or redistribute.

Upgrading is not a version bump. The unit of change is the date in the filename, and the repository keeps a rolling window of recent days (clash20260917.yml through clash20260921.yml in the listing). If you pin a dated file, nothing updates and nothing breaks; you keep a working set until the endpoints die. If you always take the newest file, you inherit whatever the scrape produced that morning, including an empty or malformed list. The README does not document rollback, so the practical rollback is keeping the previous day's file on disk and switching the profile back to it. The last push to the repository was on 2026-09-21, and the README's own timestamp matches that day, so the feed was live as of that date; the listing gives no information about what happens after.

## Conclusion

Use free-nodes/clashfree only as a disposable, short-lived source of test endpoints for a Clash-compatible client, and never for anything you would not want a stranger's server to see. Do not adopt it as infrastructure: there is no licence, no support channel, no SLA and no guarantee that tomorrow's file resembles today's. Before you point a client at it, open the dated YAML and check three things yourself: that the proxies list is populated, that the external-controller line is 127.0.0.1:9090 and not a remote address, and that the file you are about to import is the one dated today rather than a stale sibling.

## FAQ

### What is the Clash app that free-nodes/clashfree subscriptions are used with?

Clash is the client family that parses the YAML format this repository publishes. The README lists Clash Verge Rev for Windows, Clash Meta for Android, shadowrocket for iOS and flclash for macOS, and links a Clash for Windows tutorial.

### Where can I find free Clash nodes?

free-nodes/clashfree publishes a dated Clash YAML file in its repository root, with the current day's file linked from the README under the free node sharing heading. The README states the nodes are scraped from the network.

### Does free-nodes/clashfree provide a Clash subscription URL I can paste into a client?

Yes. The README's download link points at the dated YAML file on the main branch, for example clash20260921.yml, and that file is in Clash subscription format with port, socks-port, external-controller and a proxies list. The repository also keeps sub.yml and the previous days' files.

### How often are the free Clash nodes in free-nodes/clashfree updated?

The README's update line reads 2026-09-21 13:29:13 and the top-level listing contains one dated file per day from clash20260917.yml to clash20260921.yml, which is consistent with a daily refresh. The README does not state a schedule or a guarantee.

### Is free-nodes/clashfree safe to use for sensitive traffic?

The README only says the nodes are scraped from the network and asks that they not be used for illegal purposes. It gives no statement about who operates the endpoints or how traffic is handled, and the proxies list exposes server addresses and passwords in a public repository.

## Sources

- [free-nodes/clashfree on GitHub](https://github.com/free-nodes/clashfree)
- [Issues](https://github.com/free-nodes/clashfree/issues)
- [Project website](https://clashgithub.com)
- [README](https://github.com/free-nodes/clashfree/blob/main/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/free-nodes-clashfree
