Repository navigation
EN CLI Reference
dongle edited this page Oct 8, 2026
·
1 revision
SniShaper ships a cross-platform CLI (Windows / Linux / macOS, 12 build targets). The CLI shares the same backend and configuration files as the GUI.
- Download the CLI artifact for your platform from Releases (
build/bin/cli/<Platform>/<Arch>/) and run it — it opens the TUI panel by default. - No arguments opens the TUI; with a subcommand it executes that single command and exits.
snishaper # open the interactive panel (TUI)
snishaper <command> [args] # run a single command
- Building the headless CLI yourself (Linux example):
$env:GOOS='linux'; $env:CGO_ENABLED='0'
go build -tags "headless with_gvisor" -o build/bin/snishaper-linux ./cliImportant
The build tags MUST include with_gvisor, otherwise TUN fails with "gVisor is not included in this build". On Linux, TUN requires root.
| Command | Description |
|---|---|
snishaper start [--autoproxy] |
Start the resident service in the background (--autoproxy enables the proxy right after start) |
snishaper stop |
Stop the resident service (asynchronous; the process takes a few seconds to exit) |
snishaper tui |
Open the interactive panel (not available while the service is running) |
snishaper autostart status|on [--with-proxy]|off |
Autostart for the CLI service (separate entry, does not affect the desktop app) |
The complete catalog (identical to the snishaper help output).
| Command | Description |
|---|---|
status |
Service / proxy / system proxy / TUN status |
stats |
Upload / download traffic statistics |
ipv6 |
Check IPv6 availability |
diag |
Diagnostics (version / ports / system proxy / TUN / paths, JSON) |
selfcheck |
End-to-end self check: service, listening ports, proxied request, system proxy and TUN |
logs [N] |
Last N log lines (default 100) |
logs clear |
Clear the in-memory log buffer |
logs clean |
Delete historical log files (keeps the current one) |
logs files |
List historical log files |
logs show <file> |
Show a specific log file |
logs capture [on|off] |
View / toggle core log capture |
| Command | Description |
|---|---|
proxy on|off |
Start / stop the proxy (HTTP + SOCKS5) |
sysproxy on|off |
Enable / disable the system proxy |
mode get|set <mode> |
View / switch proxy mode (service must be running) |
port get|set <port> |
View / change the HTTP listen port |
port occupant [port] |
Show which process occupies the port |
port kill <pid> |
Kill the process occupying the port |
socks5 |
Mixed-port note (SOCKS5 shares the port with HTTP) |
migration status|on|off|server|test |
Session migration mode and migration server |
| Command | Description |
|---|---|
tun on |
Enable TUN (turns off the system proxy set by this app first) |
tun off |
Disable TUN (restores the previously disabled system proxy) |
tun status |
Show TUN status |
tun config [json] |
View / change TUN config (mtu / dns_hijack / auto_route / outbound_interface / stack) |
tun ifaces |
List network interfaces (physical / virtual, default route, auto-selection result) |
| Command | Description |
|---|---|
ca status |
Root certificate installation status |
ca install |
Install the root certificate into the system trust store (admin / root required) |
ca uninstall |
Uninstall the installed root certificate |
ca list |
List certificates installed by this app |
ca pem |
Print the CA certificate PEM |
ca export |
Export the CA certificate to ca.crt |
ca path |
Show the CA certificate file path |
ca regenerate |
Regenerate the root certificate (reinstall afterwards) |
| Command | Description |
|---|---|
config get [key] |
Read settings.json (whole file without a key) |
config set <key> <value> |
Modify settings.json |
config export [path] |
Export rules and settings |
config import <path> |
Import rules and settings |
sites list|show|add|update|delete |
Site-group rules (add / update accept JSON) |
upstreams list|show|add|update|delete |
Upstream config (add / update accept JSON) |
dns list|show|add|update|delete|priority|test |
DNS nodes |
ech list|upsert|fetch|delete |
ECH config (fetch pulls fresh config from a domain) |
nat64 list|add|update|delete|test |
NAT64 config |
cf status|config|refresh|fetch|prune|health |
Cloudflare IP pool and config |
evolution status|start|stop|apply |
Rule evolution testing (start blocks until the test finishes) |
route get|set|status |
Auto-routing config |
| Command | Description |
|---|---|
update check |
Check for a new version and list assets |
update download [index|name] |
Download an update (defaults to the asset matching the current platform) |
update install [index|name|path] |
Install an update (the process may be replaced and restarted) |
update channel [name] |
View / switch the update channel |
update source [name] [prefix] |
View / switch the download source and custom prefix |
update measure |
Measure the latency of each download source |
Most write operations accept JSON arguments:
snishaper sites add '{"name":"Example","mode":"direct","domains":["a.com"]}'
snishaper dns add '{"name":"CF","url":"https://1.1.1.1/dns-query","enabled":true}'The TUI exposes exactly the same command set as the shell (they share one dispatcher) and additionally accepts Chinese aliases (e.g. 帮助, 启动, 停止, 系统代理 开|关, 清屏, 退出). Lifecycle commands (start / stop / tui) are shell-only.