VPNonly isn't signed with an Apple developer certificate yet, so macOS blocks it on first launch and you allow it once in System Settings. There's a short guide here. The certificate costs $99 a year and I'm paying for it out of the first sales. Once it's signed, the app updates itself and this step goes away.
If that's a dealbreaker, don't buy it yet. You can still read every privileged line before deciding.
NordVPN is the easiest. Paste an access token once, and the app fetches your WireGuard key and picks servers for you, with a country menu.
Everyone else (Mullvad, Proton, IVPN, AirVPN, or a server you run yourself) works by importing a WireGuard config. Download the .conf files from your provider — one, several, or the whole zip they offer — and import them. A zip with every server in it becomes a single entry with a country picker, the way NordVPN works. Import as many providers as you want and switch between them from the menu at the bottom. If your provider gives you a WireGuard config, it works here.
Nearly. The exception is Safari, and anything else built on WebKit. Safari doesn't make its own network connections: WebKit hands them to separate system processes that macOS launches independently, so they never carry Safari's identity and the firewall can't match them. Proton VPN's macOS split tunneling has exactly the same limitation, for the same reason.
Chrome, Firefox, Arc, Brave, CapCut, Slack, Discord and ordinary apps all work. If you need a browser on the VPN, use one of those.
No. VPNonly talks to your provider's servers directly. Keep a whole-Mac VPN disconnected while using it; that changes the underlying route for everything and VPNonly will refuse a conflicting nested connection when it can detect one.
Not every time, but more than once. macOS fixes how an app connects at the moment it opens, and the firewall matches on that, so an app has to be relaunched to get into the tunnel. While it stays open, switching it in and out is instant and it keeps running. Quit it and open it again yourself and it's outside the tunnel, so VPNonly relaunches it once to put it back. In practice: a restart the first time you add it, and one more whenever you reopen the app from scratch. Open connections do drop when the exit IP changes, but most apps reconnect by themselves. Chrome and other browsers reopen without your tabs; press ⇧⌘T to bring the last window back, or set the browser to reopen tabs on launch (Chrome: Settings → On startup → Continue where you left off). With more than one Chrome profile, choose yours first, then ⇧⌘T.
Those apps get blocked until it's back. They never silently fall back to your normal connection.
Creating a network interface and firewall rules needs admin rights. It asks on first setup and when a security-sensitive engine update needs approval. The exact root-owned engine is open source, so you can read every privileged line before you trust it.
Two unmodified programs from the WireGuard project, run as child processes: wireguard-go (MIT) and wg from wireguard-tools (GPL-2.0-only). Full notices, versions, upstream source links and a GPL written offer are in third-party-notices.txt, also included in the download.
VPNonly's own privileged code, the part that runs as root, is MIT and on GitHub. The app also bundles Sparkle for updates; its licence is included in the download. "WireGuard" is a registered trademark of Jason A. Donenfeld. VPNonly isn't affiliated with the WireGuard project or with any VPN provider.
No. No account, no analytics in the app, no server of mine in the path. Your WireGuard key stays on your Mac. The app talks to my side twice: once to activate your license, and occasionally to check for a new version.
Your menu bar is full. Macs with a notch hide icons that don't fit, newest first, so the app is running even though you can't see it. Quit a menu bar app you're not using and the shield appears.
They route your whole Mac through the VPN and then exclude apps. VPNonly never puts your Mac on the VPN at all, so apps opt in instead. They charge about $49 a year, this is $19 once. Their Network Extension approach does avoid the one-time restart, which is a fair advantage, and it's on my list.
The Mac app, a license for 2 Macs, and all 1.x updates. The privileged engine source is public and MIT licensed either way.
Open your purchases page and sign in with the email you bought with. Your download and licence key are both there, and your licence doesn't expire. If that doesn't work, email me.
Click the … button in the app and choose Uninstall VPNonly. That removes the owned tunnel, VPNonly's own firewall rules, the root engine, passwordless rule and per-app groups, then puts the app in the Trash and quits. The audited recovery script is on the install page if you've already deleted the app.
Email kanishk@armoury.in within 14 days and I'll refund you. No forms, no reasons needed.