VPNonly how it works guides faq install github

Hi, I'm Kanishk and I built VPNonly.

One app on the VPN. Not your whole Mac.

I wanted CapCut on a Singapore IP while the rest of my Mac stayed home. No Mac VPN does that, so I built this.

CapCut — Singapore
everything else — untouched

Works with NordVPN · Mullvad · Proton · IVPN · AirVPN · any WireGuard config

Get it for Mac — $19 or run it from the terminal, free one-time · 2 Macs · 14-day refund · Apple Silicon
24-second demo · Chrome on the VPN, then back. Watch full walkthrough

what it does

Most VPNs are all or nothing. You connect, and your whole Mac moves to another country: browser, calls, banking, everything. NordVPN has no split tunneling on macOS at all, and the providers that do offer it only work with their own service. Here's what each one supports.

VPNonly works the other way round. Your Mac stays where it is, and you switch individual apps onto the VPN from a list in your menu bar.

An app restarts when it joins the tunnel, because macOS fixes how an app connects at the moment it opens. While it stays open, switching it in and out is instant. Quit it and open it yourself later and VPNonly relaunches it once to put it back.

how it works

It opens a WireGuard tunnel that nothing uses by default, so your normal connection is never touched. Then it uses the firewall already built into macOS to send just the apps you picked through that tunnel.

If the tunnel goes down, those apps are blocked until it's back. They never quietly fall back to your normal connection. The longer version, with the actual rules →

what it can't do yet

  • Apple Silicon Macs only.
  • Safari can't be routed. WebKit hands its connections to separate system processes, so they never carry the app's identity. Proton's macOS split tunneling has the same limit. Chrome, Firefox, Arc and Brave all work.
  • Connections are tunneled, but DNS lookups still go through your normal resolver. If you need to hide which sites you visit from your ISP, this isn't the right tool yet.
  • Moving an app in or out drops its open connections. Most apps reconnect on their own, but a large upload would start over.
  • It isn't signed by Apple yet, so you allow it once in System Settings on first launch. Here's the full setup guide.
  • One person maintains this. If it doesn't work for you, email me and I'll refund you.

why it's paid and open

From version 1.9.8 onward, the exact privileged engine shipped in each release is MIT licensed and published with a checksum manifest in GitHub's app-engine directory. You can read every privileged line before you trust it.

The $19 is for the Mac app around it: the menu bar list, safe setup and migration, the country picker, and updates.

quick answers

Do I need my VPN's own app running?

No, keep it closed. VPNonly connects to your provider's servers directly.

Which providers work?

For NordVPN, paste an access token and the app does the rest. For Mullvad, Proton, IVPN, AirVPN or your own server, download a WireGuard config and drop it in.

Why does it want my password?

Firewall rules need admin rights. It asks on first setup and when a security-sensitive engine update needs approval. The exact engine source is on GitHub.

How is this different from SplitTunnel.app?

They put your whole Mac on the VPN and then exclude apps. Here your Mac never joins at all. They charge about $49 a year, this is $19 once. More questions →

Made by @kanishkrazdan guides download your purchases changelog terms & privacy