VPNonly home faq install repo

Installing VPNonly

VPNonly isn't signed with an Apple developer certificate yet, so macOS blocks it the first time and you have to allow it by hand. It's four steps, you do it once, and I'd rather tell you up front than let you hit it by surprise.

1. Move it to Applications

Unzip the download and drag VPNonly.app into your Applications folder.

2. Try to open it

Double-click it. macOS will refuse, with a message like "Apple could not verify VPNonly is free of malware." That's expected. Click Done.

3. Allow it in System Settings

Open System Settings → Privacy & Security, scroll to the Security section near the bottom. You'll see a line saying VPNonly was blocked. Click Open Anyway and authenticate.

(On macOS Sequoia and later, Apple removed the old Control-click shortcut, so System Settings is the only route.)

4. Open it again

Double-click VPNonly once more and click Open. The shield appears in your menu bar. You won't see any of this again.

Then: the admin password

The first time you put an app in the VPN, VPNonly asks for your admin password once. Creating a network interface and firewall rules needs root. That's true of every VPN client. It installs a small engine owned by root and never asks again.

You don't have to take my word for what that engine does: it's open source, about 300 lines of shell and C, and it's the same code the free command-line version uses. If you're the sort of person who reads before granting root, please do.

Why isn't it signed?

An Apple developer certificate costs $99/year. VPNonly is a one-person project that just launched, so I'm funding the certificate from the first sales rather than before them. Once it's signed and notarized, this page becomes unnecessary and the app updates itself. No reinstall, no extra cost to you.

Something went wrong?

Email kanishk@armoury.in. If I can't fix it quickly you get a refund — that's the deal. Within 14 days, no forms.

Get it for Mac — $19