VPNonly how it works guides faq install github

Installing and setting up VPNonly

VPNonly isn't signed with an Apple developer certificate yet, so macOS blocks it the first time and you have to allow it by hand. Seven steps, and the awkward one only happens once.

Already have a licence, or lost your download? Get the latest version here — your key still works, and there's nothing to buy again.

Watch the full walkthrough

2 min 24 sec · Purchase, installation, and your first connection.

1. Move it to Applications

Download VPNonly, unzip it, and drag VPNonly.app into your Applications folder.

2. Try to open it

Double-click it. macOS will refuse, with a message like "Apple could not verify VPNonly is free of malware." That's expected. Click Done.

3. Allow it in System Settings

Open System Settings → Privacy & Security, scroll to the Security section near the bottom. You'll see a line saying VPNonly was blocked. Click Open Anyway and authenticate.

(On macOS Sequoia and later, Apple removed the old Control-click shortcut, so System Settings is the only route.)

4. Open it again

Double-click VPNonly once more and click Open. The shield appears in your menu bar. You won't see any of this again.

5. Paste your licence key

Click the shield, paste the key from your purchase email, and hit Activate. One licence covers 2 Macs, so you can do this again on a second machine later. Lost the email? Your key is always in your purchases page — sign in with the email you bought with.

6. Connect your VPN

VPNonly isn't a VPN and doesn't come with one. It uses the one you already pay for.

NordVPN: go to my.nordaccount.com → Manual configuration → Access token and generate a token. Paste it into VPNonly once. It fetches your key and gives you every country Nord offers, with search. Keep NordVPN's own app disconnected while using VPNonly; a connected whole-Mac VPN changes the route underneath every app.

Mullvad, Proton, IVPN, AirVPN, or your own server: download the WireGuard configs from your provider — a single .conf or the whole zip — then open the menu and choose Import WireGuard config…. A zip becomes one entry with a country picker. Switch providers from the menu at the bottom.

7. Flip a switch

Every app on your Mac is in the list. Turn one on and it joins the VPN. Turn it off and it's back on your normal connection. Everything you didn't pick is untouched throughout.

An app has to relaunch to join the tunnel, because macOS fixes how an app connects at the moment it opens. VPNonly warns you first, so save your work. While the app stays open, switching it in and out is instant.

The admin password

The first time you put an app in the VPN, VPNonly asks for your admin password. Creating a network interface and firewall rules needs root, which is true of every VPN client. A later security-sensitive engine upgrade can ask again.

You don't have to take my word for what that engine does. From version 1.9.8 onward, the exact privileged source shipped by the app is public, MIT licensed, and published with a checksum manifest on each release.

Why isn't it signed?

An Apple developer certificate costs $99 a year. VPNonly is a one-person project that just launched, so I'm paying for it out of the first sales. Once it's signed and notarized, this page stops being necessary and the app updates itself. No reinstall, no extra cost to you.

Uninstalling

VPNonly installs a small root-owned engine, and deleting the app wouldn't remove it. So there's a proper uninstaller: click the button in the app and choose Uninstall VPNonly. It disconnects the owned tunnel, removes only VPNonly's firewall rules, removes the engine and its per-app groups, then puts the app in the Trash and quits.

Already deleted the app? Download the audited clean-sweep script, read it, then run it as your normal account. It asks for the administrator password itself:

chmod +x vpnonly-clean-sweep.sh
./vpnonly-clean-sweep.sh

Something went wrong?

Email kanishk@armoury.in. If I can't fix it quickly, you get a refund. Within 14 days, no forms.

Get it for Mac — $19