Amnezia VPN

Amnezia VPN project · An open-source VPN client for self-hosted servers and Amnezia services, with multiple protocols, obfuscation and split tunneling.

CaskNetworkingApple silicon · Intel
From homebrew/cask
30-day installs233#399 in App
1-year installs4.2KLast 365 days
Latest version5.0.3.04 days ago · Oct 7
Download size112MBarm64 / x86_64 · pkg
Release cadenceMonthly1 release in 30 days

About

Amnezia VPN can provision a VPN on your own server or connect using a trusted configuration from Amnezia services or another server owner. It suits users managing their own VPN endpoint, families sharing access and people needing protocol choice. Supported protocol families include OpenVPN, WireGuard, AmneziaWG, IKEv2, XRay and obfuscated variants, with availability dependent on platform/build. Split tunneling lets selected destinations or applications use a different route; verify its effect instead of assuming every packet is covered.

Mac installation and requirements

The official 5.0.3.0 AmneziaVPN_5.0.3.0_macos_x64.pkg asset is 111,838,127 bytes in GitHub release metadata. The release explicitly requires macOS 13+ and says versions for macOS 10.15–12 are temporarily unavailable. Earlier 5.0.0.5 notes add ARM support to the PKG version, but this exact x64-named package's complete binary architecture has not been independently inspected. Check publisher guidance for your Intel/Apple Silicon Mac rather than inferring universal support from that filename. Numeric client RAM requirements are not published in the checked release/README.

Follow the official PKG installer and authorize its system networking components when required. The release warns that old 4.8.8.2-and-earlier DMG installations must be removed before installing the newer PKG; preserve/export connection information first and follow official migration instructions. The App Store network-extension edition and PKG are different distributions. Qt, Conan, CMake and Xcode in the README are source-build prerequisites, not ordinary installed-client requirements.

Server and accounts

For self-hosting, obtain a compatible VPS with a reachable address and SSH administrator credentials. The app uses those credentials to deploy VPN containers and configure the server; it can materially change that host. Use a server you control, protect SSH keys and backups, and check current server OS/protocol requirements. A VPS is separate from the client and usually costs money. You can instead import a trusted key/configuration; it determines the endpoint and access rights. Never use random public configurations that may route traffic through an attacker's server.

The client is GPLv3-licensed and free. Amnezia Free and paid Premium/Hosting are distinct services with different scope, accounts, billing and policies; no paid subscription is required simply to use your own server. A service subscription is not included with the app. Connection access can be shared without handing out full server administration credentials, but access keys themselves are sensitive and should be revoked if exposed.

Network permissions and privacy

A functioning VPN needs network connectivity and appropriate OS authorization to alter routes/tunnels; macOS may require privileged helper or network-extension approval depending on distribution. Firewall rules, DNS, split tunneling and kill-switch settings influence leaks and connectivity. A VPN does not make a compromised device safe or guarantee anonymity. The endpoint/server operator and hosting provider remain trust boundaries, and HTTPS is still necessary for sensitive application traffic beyond the tunnel endpoint.

The publisher states that self-hosted client configuration remains on your device and is not collected by Amnezia; its hosted services collect information necessary to provide service under separate policies. Treat that as the publisher's statement, not an independently audited universal guarantee. Connection files, keys, diagnostics and server credentials can disclose sensitive information if shared. Protect local storage and inspect logs before requesting support. Choose services and server operators whose policies you understand.

Reliability and maintenance

Test the actual routes/DNS and reconnect behavior after changing protocols or server settings. Kill Switch can block network access when disconnected; split-tunnel exclusions intentionally bypass the VPN. Export a recoverable configuration and keep another way to reach your server before making network changes. Obfuscation may help with some network filtering but is not a promise of availability on every network. Keep both server software and client updated; 5.0.1.5 specifically includes a reported vulnerability fix.

Sources: Official project, Exact releases, Self-hosted service scope, Publisher privacy/service distinctions, Configuration safety, GPL license.

New What’s new in 5.0.3.0 Oct 7 · OpenNavo editorial

  • ChangesAdds TProxy support.

An open-source interface for Homebrew. Installs run through the macOS app or the brew command.

© 2026 OpenNavo