VPNonly home how it works repo

FAQ

macOS says it can't verify the app. Is it safe?

VPNonly isn't signed with an Apple developer certificate yet, so macOS blocks it on first launch. You allow it once in System Settings, and there's a short guide here. The certificate costs $99/year and I'm funding it from the first sales rather than before them; once it's signed, the app updates itself and this goes away.

If that's a dealbreaker, don't buy it yet. The command-line version is free, does the same routing, and you can read every line of it.

Which VPNs work?

NordVPN is the easiest: paste an access token once and the app fetches your WireGuard key and picks servers for you, with a country menu.

Everyone else — Mullvad, Proton, IVPN, AirVPN, or a server you run yourself — works by importing a WireGuard config. Download the .conf from your provider (one per server), import as many as you want, and switch between them from the same menu. If your provider can give you a WireGuard config, it works here.

Do I need my VPN's own app running?

No, keep it closed. VPNonly talks to your provider's servers directly. Running both at once makes their firewall rules fight each other.

Does my app restart every time I toggle it?

Only the first time it joins the VPN. macOS fixes an app's network identity when it launches, so it has to be relaunched once. After that, switching it in and out is instant and the app keeps running. Its open connections do drop when the exit IP changes — most apps reconnect by themselves.

What happens if the VPN drops?

Those apps get blocked until it's back. They never silently fall back to your normal connection.

Why does it want my password?

Creating a network interface and firewall rules needs admin rights. It asks once, installs a root-owned engine, and doesn't ask again. That engine is open source — you can read every privileged line before you trust it.

What's bundled inside, and under what licence?

Two unmodified programs from the WireGuard project, run as child processes: wireguard-go (MIT) and wg from wireguard-tools (GPL-2.0-only). Full notices, versions, upstream source links and a GPL written offer are in third-party-notices.txt, also included in the download.

VPNonly's own privileged code, the part that runs as root, is MIT and on GitHub. "WireGuard" is a registered trademark of Jason A. Donenfeld; VPNonly isn't affiliated with the WireGuard project or with any VPN provider.

Do you collect anything?

No. No account, no analytics in the app, no server of mine in the path. Your WireGuard key stays on your Mac. The app talks to my side exactly twice: once to activate your license, and occasionally to check whether there's a new version.

I can't see the icon in my menu bar

Your menu bar is full — Macs with a notch quietly hide icons that don't fit, newest first. Quit a menu bar app you're not using and the shield shows up. It was running the whole time.

How is this different from SplitTunnel.app?

They route your whole Mac through the VPN and then exclude apps; VPNonly never puts your Mac on the VPN at all — apps opt in. And they're ~$49 a year, this is $19 once. Their Network Extension approach does avoid the one-time relaunch, which is fair — that's on my list.

What do I get for $19?

The Mac app, a license for 2 Macs, and all 1.x updates. The command-line engine is free and MIT licensed either way.

Refunds?

Email kanishk@armoury.in within 14 days and I'll refund you. No forms, no reasons needed.

Get it for Mac — $19