VPNonly how it works guides faq install github

Proton VPN split tunneling on Mac

Proton added split tunneling to its macOS app, but it's marked experimental and it's exclude-only: it only removes apps from a full tunnel, it doesn't work with Safari or anything else built on WebKit, and every excluded app has to be restarted after you connect.

For the opposite model — nothing on the VPN until you add one app — use a Proton WireGuard config.

Get a WireGuard config from Proton

  1. Go to account.protonvpn.com → Downloads → WireGuard configuration.
  2. Name the config, pick a server, and generate it.
  3. Download the .conf file.

Put one app on it with VPNonly

  1. Install VPNonly and open the menu → Import WireGuard config….
  2. Choose the .conf (or several at once). Pick the exit country from the menu at the bottom.
  3. Search for an app, flip its switch. It relaunches once, then it's on the VPN and nothing else is.

Documented from Proton's own setup pages. Proton issues standard WireGuard configs, which is exactly what the import takes; the exit was not separately tested on our hardware.

Get VPNonly for Mac — $19

The app’s exact privileged engine source is public and MIT licensed.

Other providers

NordVPN · Mullvad · Surfshark · IVPN · ExpressVPN · AirVPN or your own server. Or see which Mac VPNs have split tunneling, provider by provider.