How to Set Up a VPN on a Mac: VLESS Reality Clients in 2026

SetupUpdated September 25, 20267 min read

Setting up a VLESS Reality VPN on a Mac is quick, but many of the guides that rank for it are out of date. They recommend clients that are no longer in the App Store. They also skip the fact that the same client comes in two different builds for macOS. This guide uses Happ, which is still listed. It covers both builds, the macOS prompts you will see, and the two Apple privacy features that overlap with a VPN.

The worked example in Step 1 is Kovra, the service that publishes this guide. Every other step applies to any VLESS subscription link.

Which build fits your Mac

Open the Apple menu and choose About This Mac to see your macOS version. Then pick a build. The versions below are the ones Happ states on its own requirements page:

Mac App Store buildDMG build
Minimum macOSmacOS 15macOS 13
Where fromMac App Store, same listing as iPhoneHapp's GitHub releases page
What it isThe iPhone and iPad app, built for Mac with CatalystThe desktop app shared with Windows and Linux
First-run promptAdd VPN configurationAdministrator password for a background service
UpdatesThrough the App StoreFrom inside the app or a new DMG

On macOS 15 or later, start with the App Store build. On macOS 13 or 14, use the DMG. Current Happ builds do not support anything older than macOS 13.

Step 1: get the link for this Mac

In your Kovra dashboard, press Add device (or Connect for your first device) and pick Mac. The new card holds the subscription link with a copy button and a QR code option. The dashboard's Happ button for Mac opens the same App Store listing as the iPhone one, but the Mac still needs its own link. Kovra binds each link to the first device that opens it, and any other device gets a "One device per link" entry instead of locations. Each device uses a slot. The 3-device plan has three, and an extra slot costs $5 for 30 days. The rules are in one link, one device.

Step 2: install Happ

App Store build. Search the Mac App Store for Happ - Proxy Utility by Flyfrog LLC. The App Store also carries apps with similar names from other developers, so check the developer name before you install.

DMG build. Download Happ.macOS.universal.dmg from Happ's official GitHub releases page (Happ-proxy/happ-desktop). It runs on both Apple silicon and Intel Macs. Open the DMG and drag Happ into Applications. If macOS says it cannot verify the app, and only if the file came from that page, open System Settings, Privacy & Security, and use the Open Anyway button for Happ. Do not take the DMG from anywhere else.

Step 3: import the subscription

Copy the link from the dashboard, open Happ and add it as a subscription. In both builds, use the + button and add the link from the clipboard; in the App Store build this works the same way as on iPhone. Labels shift a little between versions. The list of locations appears, and Kovra asks Happ to refresh it every hour, so you never re-paste the link.

If the link on your card starts with kovravpn.com/p/, it is a one-tap import page rather than a plain subscription address. Open it in a browser on the Mac and let it open Happ, which then adds the subscription.

Step 4: allow the VPN configuration

App Store build: the first time you connect, macOS asks whether Happ may add VPN configurations. Choose Allow and confirm with your password or Touch ID. Happ then appears under System Settings, VPN, which also shows whether it is connected.

DMG build: Happ asks for your administrator password to install its background service. Since version 4.0.5 the whole installation runs on a single confirmation. The desktop build then offers the same Proxy, TUN and Mixed modes as on Windows. TUN covers every app, while Proxy covers apps that use the system proxy setting, mainly browsers. The Windows guide explains the difference, and it applies unchanged to the Mac.

On a work Mac managed by an organisation, a configuration profile can block new VPN configurations or background services entirely. If the prompt never appears, or is refused without asking you, that is the likely reason. Ask IT before you look for a workaround.

iCloud Private Relay and Limit IP Address Tracking

iCloud Private Relay is part of iCloud+. It sends Safari traffic, DNS lookups and unencrypted web traffic through two relays: the first run by Apple, the second by a partner network. According to an Apple engineer on Apple's developer forums, traffic that goes through a VPN configured on the device, such as the App Store build's tunnel, is not eligible for Private Relay. Traffic outside the tunnel is, and in the DMG build's Proxy mode Safari may use Private Relay instead of the proxy, so sites see a Private Relay address rather than the location you picked. To keep the result predictable, turn it off in System Settings: click your name (Apple Account), then iCloud, then Private Relay.

Limit IP Address Tracking is a per-network setting that hides your IP address from known trackers in Mail and Safari. It is much less intrusive. If a site misbehaves only on one Wi-Fi network with the VPN on, switch it off for that network under System Settings, Wi-Fi, Details next to the network name.

Other clients, and the ones that disappeared

Mac VLESS guides go stale fast because the App Store changes under them. Before you follow a recommendation, check the current listing in your own region:

  • FoXray has been missing from every App Store storefront tested by applecensorship.com since April 2025, yet older guides still recommend it. An app with a similar name from a different developer has appeared since; it is not the same product.
  • V2RayTun was not found in the US, UK, German or Dutch App Store when we checked the listing on 25 September 2026.
  • V2Box, Streisand and Hiddify were listed in those storefronts on the same date. Whether each installs on a Mac depends on the app and your region, so check the Mac App Store listing itself. Hiddify also publishes a macOS DMG on GitHub.
  • INCY reads Kovra subscriptions and is in the App Store, where its Mac version requires an Apple silicon Mac. Its separate desktop client is labelled pre-alpha by its developer.

Whatever you pick, avoid the App Store's "free VPN" results. Why is covered in are free VPNs safe.

Verify

With the VPN connected, check that your public IP belongs to the location you picked, that DNS is not answered by your internet provider, and that IPv6 does not show your real address. In Proxy mode on the DMG build, also check WebRTC in the browser. The VPN leak test covers every check in a few minutes.

When it fails

SymptomCauseFix
The VPN prompt never appearsManaged Mac, a stale configuration, or another VPN app holding the tunnelCheck System Settings, VPN; remove old entries, quit other VPN apps, reopen Happ
Connected, but Safari failsPrivate Relay, a proxy extension, or a leftover proxyTurn off Private Relay; check Wi-Fi, Details, Proxies; then see connected but no internet
The only entry is "One device per link - kovravpn.com"The link is bound to another device, often the iPhoneUse the Mac's own link, or press Reset device binding and refresh on the Mac
The only entry is "No active plan - kovravpn.com"The plan has endedRenew; the list returns on the next refresh
App Store says the app needs a newer macOSThe App Store build needs macOS 15Install the DMG build (macOS 13 and newer) or update macOS

The placeholder entries ending in "kovravpn.com" point to a dummy local address, so connecting to one gives no internet by design. Setting up the phone as well? The iPhone steps are in how to set up a VPN on iPhone.

Frequently asked questions

Can I reuse my iPhone's VPN link on my Mac?

Not on Kovra. The Mac App Store build of Happ is the same listing as the iPhone app, but each Kovra link is bound to the first device that opens it. A second device receives a single 'One device per link' entry instead of locations. Add a Mac device in the dashboard; it uses its own device slot.

Why does the App Store version of Happ need macOS 15?

Happ's requirements page says the App Store build is made with Apple's Catalyst technology and needs macOS 15 or later. The App Store page itself may show a lower number. If your Mac runs macOS 13 or 14, use the DMG build from Happ's GitHub releases, which Happ lists for macOS 13 and newer.

Is there a Linux app?

Happ publishes Linux builds, but Kovra's dashboard has no Linux device type today, and this guide does not cover Linux.

Does iCloud Private Relay conflict with a VPN?

It does not stop the VPN from connecting. An Apple engineer has stated that traffic going through a VPN configured on the device, such as the App Store build's tunnel, is not eligible for Private Relay. Traffic outside that tunnel, for example Safari in the DMG build's Proxy mode, can still use Private Relay, and sites then see a Private Relay address instead of the location you picked. Switching it off keeps the result predictable: System Settings, your Apple Account, iCloud, Private Relay.

Which Happ build should I pick if my Mac can run both?

On macOS 15 or later, the App Store build is the simpler choice: it updates through the App Store and uses the standard macOS VPN prompt. The DMG build is the desktop app shared with Windows and Linux, with a Proxy or TUN mode switch and a background service. Use it if you need those desktop options or are on macOS 13 or 14.

To the network, it's just a website

Kovra runs on VLESS + Reality, takes USDT, BTC and cards, and never asks for a phone number. Plans from $2.75 per month on the annual term, paid once; nothing renews automatically.

Popular searches