VPNonly isn't signed with an Apple developer certificate yet, so macOS blocks it on first launch. You allow it once in System Settings, and there's a short guide here. The certificate costs $99/year and I'm funding it from the first sales rather than before them; once it's signed, the app updates itself and this goes away.
If that's a dealbreaker, don't buy it yet. The command-line version is free, does the same routing, and you can read every line of it.
NordVPN is the easiest: paste an access token once and the app fetches your WireGuard key and picks servers for you, with a country menu.
Everyone else — Mullvad, Proton, IVPN, AirVPN, or a server you run yourself — works by importing a WireGuard config. Download the .conf from your provider (one per server), import as many as you want, and switch between them from the same menu. If your provider can give you a WireGuard config, it works here.
No, keep it closed. VPNonly talks to your provider's servers directly. Running both at once makes their firewall rules fight each other.
Only the first time it joins the VPN. macOS fixes an app's network identity when it launches, so it has to be relaunched once. After that, switching it in and out is instant and the app keeps running. Its open connections do drop when the exit IP changes — most apps reconnect by themselves.
Those apps get blocked until it's back. They never silently fall back to your normal connection.
Creating a network interface and firewall rules needs admin rights. It asks once, installs a root-owned engine, and doesn't ask again. That engine is open source — you can read every privileged line before you trust it.
Two unmodified programs from the WireGuard project, run as child processes: wireguard-go (MIT) and wg from wireguard-tools (GPL-2.0-only). Full notices, versions, upstream source links and a GPL written offer are in third-party-notices.txt, also included in the download.
VPNonly's own privileged code, the part that runs as root, is MIT and on GitHub. "WireGuard" is a registered trademark of Jason A. Donenfeld; VPNonly isn't affiliated with the WireGuard project or with any VPN provider.
No. No account, no analytics in the app, no server of mine in the path. Your WireGuard key stays on your Mac. The app talks to my side exactly twice: once to activate your license, and occasionally to check whether there's a new version.
Your menu bar is full — Macs with a notch quietly hide icons that don't fit, newest first. Quit a menu bar app you're not using and the shield shows up. It was running the whole time.
They route your whole Mac through the VPN and then exclude apps; VPNonly never puts your Mac on the VPN at all — apps opt in. And they're ~$49 a year, this is $19 once. Their Network Extension approach does avoid the one-time relaunch, which is fair — that's on my list.
The Mac app, a license for 2 Macs, and all 1.x updates. The command-line engine is free and MIT licensed either way.
Email kanishk@armoury.in within 14 days and I'll refund you. No forms, no reasons needed.