# Semporia/TikTok-Unlock: Rule-Set Routing for Region-Locked TikTok on iPhone and iPad

> A small repository of proxy rule lists that redirect TikTok traffic to an unlock-capable node. It replaces the old MitM certificate approach, but the node itself does the real work.

**Semporia/TikTok-Unlock** — TikTok 無需拔卡解鎖最新支援  iPhone &iPad 、TikTok&TikTok TestFlight，地區切換 、視頻發佈 、 live 直播 、點贊 評論、私信聊天等！

- Repository: https://github.com/Semporia/TikTok-Unlock
- Website: https://semporia.github.io/iTunes.html
- Stars: 12,054 · Forks: 836
- Language: JavaScript
- License: not declared
- Published: 2026-09-21 · Updated: 2026-09-21 · Language: en
- Canonical page: https://hysenlabs.com/projects/semporia-tiktok-unlock

## What the project actually ships, and who it is for

The repository is not an app. The top level holds README.md and four directories: Loon/, Quantumult-X/, Shadowrocket/ and Surge/. Each directory carries a TikTok.list rule set for one iOS proxy client. That is the entire deliverable.

The audience is narrow and specific: someone on an iPhone or iPad who already pays for a proxy service, already runs one of those four clients, and wants the App Store build of TikTok to show content from a region other than mainland China. The README frames the problem as region access plus the feature set that follows from it, listing region switching, video publishing, live streaming, likes, comments and direct messages.

The README also records a change of approach. Earlier versions required downloading a historical TikTok build and running HTTPS decryption with a MitM certificate. The current README states that is no longer needed: you install the latest TikTok from the App Store and point its traffic at a node that already unlocks TikTok. The certificate installation and URL rewriting steps are gone.

## How the rule sets route TikTok traffic

The mechanism is traffic classification, not modification. Your proxy client reads a remote rule set and decides which requests belong to TikTok, then sends those requests through a policy group you choose. Everything else follows your existing rules.

Because there is no MitM and no rewrite, the client never decrypts TikTok's TLS traffic. It only matches hostnames or IP ranges and forwards the connection. The README states this is safer and does not interfere with other apps, which is a fair description of the difference: a rewrite rule edits requests, a routing rule only chooses an exit.

The README is direct about where the actual unlock happens. Region is determined entirely by the country of the exit node IP. Want Japanese content, switch the policy to a Japanese node; American content, an American node; Taiwanese content, a Taiwanese node. The rule set decides that TikTok's traffic uses the group; the group decides which country TikTok sees.

The README names the failure condition without hedging: if the node IP is already blocked by TikTok or recognised as a datacenter IP, routing it correctly changes nothing. The project supplies the routing, not the exit.

## Adding the rule set in Quantumult X, Loon, Surge or Shadowrocket

Setup is the same shape in all four clients: add a remote rule set, point it at a policy group, make sure the group resolves to an unlock-capable node. The README gives the URL per client.

In Quantumult X, open settings, go to the resource or rule section, and add the TikTok rule set:

```bash
https://raw.githubusercontent.com/Semporia/TikTok-Unlock/master/Quantumult-X/TikTok.list
```

Once the resource is added and enabled, the README says TikTok works. There is no rewrite entry to create.

In Loon, the rule set goes under the remote rule section:

```bash
https://raw.githubusercontent.com/Semporia/TikTok-Unlock/master/Loon/TikTok.list
```

The README adds one condition after that: confirm the policy group the rule set points at has an unlock-capable node selected. Adding the rule and leaving the group on a blocked node is the most common way to end up with a black screen.

Surge takes the same remote rule set and you direct it at the matching policy group:

```bash
https://raw.githubusercontent.com/Semporia/TikTok-Unlock/master/Surge/TikTok.list
```

Shadowrocket is configured by hand rather than by pasting a subscription. Open the config you are using, tap the info button, go to rules, and add a new entry with type RULE-SET, policy PROXY or a dedicated TikTok group, and this URL as the rule set:

```bash
https://raw.githubusercontent.com/Semporia/TikTok-Unlock/master/Shadowrocket/TikTok.list
```

Save and make sure the configuration is applied. After any of these, the check is behavioural: open TikTok on the latest App Store build and see whether content loads and which region it shows.

## The node is the product, and the repository cannot fix a bad one

This is the honest limitation, and the README does not hide it. The rule lists only decide that TikTok traffic goes through your proxy. Whether TikTok accepts that connection depends on the exit IP, which this project does not provide and cannot change.

The README's first FAQ answers the symptom directly: if you still see the spinner, a black screen, or a no-network message after configuring the rules, the node does not support TikTok, and the suggested fix is to ask your provider whether it does or to switch to a native IP node. That is a real dependency on a third party you may not control.

There is a second, quieter limitation. Because region is purely a function of node location, there is no way to watch two regions at once, and no per-app override beyond switching the policy group. If you want a Japanese feed in one session and a US feed in another, you are changing the selected node each time, not toggling a setting inside TikTok.

The third case where this is the wrong tool is anyone without an existing proxy subscription. The README's prerequisites assume you already have Quantumult X, Loon, Surge or Shadowrocket and a node list. Without those, the repository gives you nothing to run.

## How this differs from the older MitM-and-rewrite approach

The alternative is not a competing project so much as the previous version of this one, and the README describes both. The old method installed a MitM certificate, trusted it, and used URL rewriting to alter TikTok's requests, which meant decrypting the app's HTTPS traffic and pinning a historical TikTok build that still responded to those rewrites.

The current method removes all of that. No certificate, no trust step, no rewrite rules, no pinned old build. The trade is that the unlock now depends on the node rather than on request manipulation, so the failure mode moved from "the rewrite broke because TikTok changed its API" to "the node's IP is blocked."

That is a genuine simplification, and it also shifts the cost. A rewrite-based setup could sometimes work on an ordinary node, because the app was being edited. A routing-only setup cannot: the README states the only prerequisite is that the node natively supports TikTok. You trade configuration complexity for a harder requirement on your subscription.

## Maintenance, licence and what to verify

The last push to the repository was on 2026-07-08, roughly two and a half months before this writing, and the repository is not archived. The README carries no version number and the repository shows no retrieved releases, so the update channel is the master branch itself. The rule lists are fetched from raw.githubusercontent.com at master, which means your client pulls whatever is currently committed. There is no tagged release to pin to and no documented rollback if a rule set change breaks your setup; the README does not describe one.

The repository states no licence. The README carries a disclaimer that the project is for learning and exchange and that users should follow local laws, but a disclaimer is not a licence grant. If you intend to redistribute the rule lists or bundle them into a product, the absence of a licence identifier is something to resolve with the author before you rely on permission that has not been given. That is a factual gap, not legal advice.

One maintenance detail worth noting: the README's third FAQ deals with a side effect rather than the main feature. Users who also watch the mainland China version of Douyin may find it stops working once TikTok traffic is proxied, and the README suggests adding a direct-connect rule set for Douyin:

```bash
https://raw.githubusercontent.com/Semporia/Quantumult-X/master/Filter/DouYin.list
```

That URL points at a different repository, Semporia/Quantumult-X, so the fix lives outside this project and will not be updated here.

## Conclusion

Adopt it if you already run Quantumult X, Loon, Surge or Shadowrocket and already hold a proxy node whose IP TikTok accepts; the four rule lists are the only thing this repository adds, and the README is explicit that a node without native support produces spinning, black screens and no-network errors. Do not adopt it if you have no proxy subscription, if you expect a standalone app or an APK, or if you need a documented licence before redistribution, because the repository states none. Before configuring anything, confirm with your provider that the node you plan to use is TikTok-capable and that it is not a datacenter IP, then add the rule set for your client from the Quantumult-X, Loon, Surge or Shadowrocket directory and switch the policy group to that node.

## FAQ

### Does Semporia/TikTok-Unlock need a MitM certificate or HTTPS decryption?

No. The README states that the current version needs neither a certificate installation nor HTTPS decryption, and that you only need the latest TikTok from the App Store plus a routing rule in your proxy client. The only remaining requirement is a node whose IP natively supports TikTok.

### Why does TikTok still spin or show a black screen after I add the Semporia/TikTok-Unlock rule set?

The README attributes this to the node, not the rules: the node's IP has been blocked by TikTok or is recognised as a datacenter IP. It suggests asking your provider whether the node supports TikTok or switching to a native IP node.

### How do I change the TikTok region with Semporia/TikTok-Unlock?

By switching the node, not a setting in the app. The README says the region you see depends directly on the country or region of the node IP, so a Japanese node gives Japanese content and a US node gives US content.

### Which proxy clients does Semporia/TikTok-Unlock support?

The repository has rule lists for Quantumult X, Loon, Surge and Shadowrocket, one directory each. The README's prerequisites assume you already have one of those clients.

## Sources

- [Issues](https://github.com/Semporia/TikTok-Unlock/issues)
- [Project website](https://semporia.github.io/iTunes.html)
- [README](https://github.com/Semporia/TikTok-Unlock/blob/master/README.md)
- [Semporia/TikTok-Unlock on GitHub](https://github.com/Semporia/TikTok-Unlock)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/semporia-tiktok-unlock
