Setting up a VLESS Reality VPN on a Mac is quick, but many of the guides that rank for it are out of date. They recommend clients that are no longer in the App Store. They also skip the fact that the same client comes in two different builds for macOS. This guide uses Happ, which is still listed. It covers both builds, the macOS prompts you will see, and the two Apple privacy features that overlap with a VPN.
The worked example in Step 1 is Kovra, the service that publishes this guide. Every other step applies to any VLESS subscription link.
Which build fits your Mac
Open the Apple menu and choose About This Mac to see your macOS version. Then pick a build. The versions below are the ones Happ states on its own requirements page:
| Mac App Store build | DMG build | |
|---|---|---|
| Minimum macOS | macOS 15 | macOS 13 |
| Where from | Mac App Store, same listing as iPhone | Happ's GitHub releases page |
| What it is | The iPhone and iPad app, built for Mac with Catalyst | The desktop app shared with Windows and Linux |
| First-run prompt | Add VPN configuration | Administrator password for a background service |
| Updates | Through the App Store | From inside the app or a new DMG |
On macOS 15 or later, start with the App Store build. On macOS 13 or 14, use the DMG. Current Happ builds do not support anything older than macOS 13.
Step 1: get the link for this Mac
In your Kovra dashboard, press Add device (or Connect for your first device) and pick Mac. The new card holds the subscription link with a copy button and a QR code option. The dashboard's Happ button for Mac opens the same App Store listing as the iPhone one, but the Mac still needs its own link. Kovra binds each link to the first device that opens it, and any other device gets a "One device per link" entry instead of locations. Each device uses a slot. The 3-device plan has three, and an extra slot costs $5 for 30 days. The rules are in one link, one device.
Step 2: install Happ
App Store build. Search the Mac App Store for Happ - Proxy Utility by Flyfrog LLC. The App Store also carries apps with similar names from other developers, so check the developer name before you install.
DMG build. Download Happ.macOS.universal.dmg from Happ's official GitHub releases page (Happ-proxy/happ-desktop). It runs on both Apple silicon and Intel Macs. Open the DMG and drag Happ into Applications. If macOS says it cannot verify the app, and only if the file came from that page, open System Settings, Privacy & Security, and use the Open Anyway button for Happ. Do not take the DMG from anywhere else.
Step 3: import the subscription
Copy the link from the dashboard, open Happ and add it as a subscription. In both builds, use the + button and add the link from the clipboard; in the App Store build this works the same way as on iPhone. Labels shift a little between versions. The list of locations appears, and Kovra asks Happ to refresh it every hour, so you never re-paste the link.
If the link on your card starts with kovravpn.com/p/, it is a one-tap import page rather than a plain subscription address. Open it in a browser on the Mac and let it open Happ, which then adds the subscription.
Step 4: allow the VPN configuration
App Store build: the first time you connect, macOS asks whether Happ may add VPN configurations. Choose Allow and confirm with your password or Touch ID. Happ then appears under System Settings, VPN, which also shows whether it is connected.
DMG build: Happ asks for your administrator password to install its background service. Since version 4.0.5 the whole installation runs on a single confirmation. The desktop build then offers the same Proxy, TUN and Mixed modes as on Windows. TUN covers every app, while Proxy covers apps that use the system proxy setting, mainly browsers. The Windows guide explains the difference, and it applies unchanged to the Mac.
On a work Mac managed by an organisation, a configuration profile can block new VPN configurations or background services entirely. If the prompt never appears, or is refused without asking you, that is the likely reason. Ask IT before you look for a workaround.
iCloud Private Relay and Limit IP Address Tracking
iCloud Private Relay is part of iCloud+. It sends Safari traffic, DNS lookups and unencrypted web traffic through two relays: the first run by Apple, the second by a partner network. According to an Apple engineer on Apple's developer forums, traffic that goes through a VPN configured on the device, such as the App Store build's tunnel, is not eligible for Private Relay. Traffic outside the tunnel is, and in the DMG build's Proxy mode Safari may use Private Relay instead of the proxy, so sites see a Private Relay address rather than the location you picked. To keep the result predictable, turn it off in System Settings: click your name (Apple Account), then iCloud, then Private Relay.
Limit IP Address Tracking is a per-network setting that hides your IP address from known trackers in Mail and Safari. It is much less intrusive. If a site misbehaves only on one Wi-Fi network with the VPN on, switch it off for that network under System Settings, Wi-Fi, Details next to the network name.
Other clients, and the ones that disappeared
Mac VLESS guides go stale fast because the App Store changes under them. Before you follow a recommendation, check the current listing in your own region:
- FoXray has been missing from every App Store storefront tested by applecensorship.com since April 2025, yet older guides still recommend it. An app with a similar name from a different developer has appeared since; it is not the same product.
- V2RayTun was not found in the US, UK, German or Dutch App Store when we checked the listing on 25 September 2026.
- V2Box, Streisand and Hiddify were listed in those storefronts on the same date. Whether each installs on a Mac depends on the app and your region, so check the Mac App Store listing itself. Hiddify also publishes a macOS DMG on GitHub.
- INCY reads Kovra subscriptions and is in the App Store, where its Mac version requires an Apple silicon Mac. Its separate desktop client is labelled pre-alpha by its developer.
Whatever you pick, avoid the App Store's "free VPN" results. Why is covered in are free VPNs safe.
Verify
With the VPN connected, check that your public IP belongs to the location you picked, that DNS is not answered by your internet provider, and that IPv6 does not show your real address. In Proxy mode on the DMG build, also check WebRTC in the browser. The VPN leak test covers every check in a few minutes.
When it fails
| Symptom | Cause | Fix |
|---|---|---|
| The VPN prompt never appears | Managed Mac, a stale configuration, or another VPN app holding the tunnel | Check System Settings, VPN; remove old entries, quit other VPN apps, reopen Happ |
| Connected, but Safari fails | Private Relay, a proxy extension, or a leftover proxy | Turn off Private Relay; check Wi-Fi, Details, Proxies; then see connected but no internet |
| The only entry is "One device per link - kovravpn.com" | The link is bound to another device, often the iPhone | Use the Mac's own link, or press Reset device binding and refresh on the Mac |
| The only entry is "No active plan - kovravpn.com" | The plan has ended | Renew; the list returns on the next refresh |
| App Store says the app needs a newer macOS | The App Store build needs macOS 15 | Install the DMG build (macOS 13 and newer) or update macOS |
The placeholder entries ending in "kovravpn.com" point to a dummy local address, so connecting to one gives no internet by design. Setting up the phone as well? The iPhone steps are in how to set up a VPN on iPhone.