Beta Free and open source

A VPN client that tells you plainly what it's doing.

Nunya connects you through the VPN and proxy servers you already have — a link your provider sent, a subscription of hundreds, or a WireGuard config — and tests every one of them for real.

macOS · Windows · Linux  —  no account, no telemetry

Nunya connected through a server in Helsinki: the server list, the route on the map, and the status card with live traffic Nunya connected through a server in Helsinki: the server list, the route on the map, and the status card with live traffic
Screenshots show made-up example servers.

Why Nunya

Five promises, and the app keeps each of them visibly.

Safe

Never claims more than it covers. In proxy mode it tells you exactly which apps are covered, and which aren't.

Fast

Every server is tested end to end. Quick Connect takes you to the fastest, the most used or the most recent.

Reliable

A server only counts as working if traffic actually gets through. The shield turns red when nothing comes out.

Secure

No account and no telemetry. Your servers stay on your device, and the engine is a verified release.

Easy

Paste a link or a subscription, scan a QR code, and connect. That's the whole setup.

A tour of the app

Everything you need day to day, and nothing pretending to be more than it is.

Adding servers

Every kind of link, in one box.

Press + and paste whatever your provider gave you. One paste can hold several things at once, and Nunya sorts them before anything is added.

  • Share links: vless://, vmess://, trojan://, wireguard://
  • Subscriptions, including Xray, sing-box and Clash configurations
  • WireGuard configs, QR codes from a screenshot, or a server filled in by hand

Anything Nunya can't run yet is named, with the reason — never silently dropped.

The Add servers sheet, having found a subscription, a WireGuard config and a VLESS server in pasted text
Quick Connect

Choose by what matters this time.

  • Fastest — the lowest latency among servers that passed their last test, re-tested first if the result is old.
  • Most used — the server that carried the most data in the last 30 days.
  • Most recent — the one you were last connected to.

Each server is located by where its traffic really exits, not by its name. Relays and CDN-fronted servers are marked as such.

The Quick Connect prompt offering the fastest, the most used and the most recent server
In the menu bar

See the connection with the window closed.

A shield in the macOS menu bar or the Linux top bar shows the state in the status colours — green connected, amber connecting, red not working, dimmed off.

On a Mac, click it for a panel with a big on/off button, Quick Connect, a search over your configs, the Proxy / VPN switch, and the ad blocker and anti-tracker.

The menu-bar popover: Proxy running on FI-1 Helsinki with a Disconnect button, Quick Connect, and the mode and blocker switches
Usage

What each server has carried, day by day.

The last 30 days and all time, a daily chart, and for a subscription each server's share — beside what your provider reports. Counted on your device only.

The usage of a subscription: totals for 30 days and all time, a daily chart, and a breakdown by server
Sharing

Send a server to another device.

As a link or a QR code, or as a WireGuard config the official WireGuard apps can scan. A share link holds the server's credentials, so share it only with people you'd give access to.

The Share sheet with a QR code and the server's share link
Bypass rules

Keep chosen traffic off the tunnel.

A domain (with or without *.), an address, or a range such as 10.0.0.0/8 leaves on your normal connection. Your local network always does.

Bypass rules for domains, an address and a range, beside the local network ranges that are always bypassed
  • Ad blocker & anti-trackerRefuse ad networks and the tracking built into systems, devices and apps.
  • A live mapYou, your servers, and the route your connection takes — drawn locally.
  • DiagnosticsThe engine log, connection state and exact config, ready for a bug report.
  • Light and darkFollows your system, like this page does by default.

Two ways to connect

Switch any time from Settings or the menu-bar panel. Nunya says which one is covering you.

Default

Proxy mode

Opens a local SOCKS and HTTP port (2080 unless you change it). Apps you point at it go through the connection.

  • No password needed
  • Set system proxy points your desktop at it while connected (macOS, GNOME, KDE) and puts your own setting back exactly on disconnect
  • Apps that ignore the system proxy aren't covered — and Nunya tells you so
Whole device

VPN mode

Carries all of the device's traffic through the tunnel. It needs system privileges, granted once through your system's own prompt.

  • macOS: your administrator password, once (again after each update). Nunya must be in Applications.
  • Windows: Windows' own prompt restarts Nunya as administrator.
  • Linux: your password through polkit, once (again after each update), from the .deb, .rpm or Arch package.

Supported protocols

Protocols
VLESSVMessTrojanWireGuardCloudflare WARP
Transports
TCPWebSocketgRPCHTTP/2HTTPUpgradeQUICXHTTP
Security
TLSRealityuTLS fingerprintsALPN
Subscriptions
Share-link lists (plain / base64)Xray JSONsing-box JSONClashImport links
Coming
ShadowsocksHysteria2TUICSSHAmneziaWGProxy chains

Privacy, without the fine print

Nunya is free software under the GPL-3.0. You can read every line of what it does.

  • No account, no telemetry, no analytics. There is nothing to sign up for.
  • Your data stays on your device. Servers, subscriptions and usage live in a file only your user account can read.
  • A verified engine. Nunya runs a pinned release of nunya-core, checked against its published checksums, and the app and engine verify each other.
  • Honest coverage. The app only says you're protected when the whole device is in the tunnel.
  • Location lookups. To place servers on the map, Nunya asks public IP-location services where your servers' addresses are. The map itself is drawn inside the app.

Download

Builds are published on GitHub Releases, each with a SHA256SUMS to check your download against.

macOS

Apple Silicon · macOS 12 or later

Download .dmg
  • Updates itself, and never restarts on its own
  • A panel in the menu bar for day-to-day use
  • VPN mode after one administrator prompt

Not yet signed by an Apple Developer account — see the first-launch step.

Windows

x86-64 · Windows 10 or later

Download installer
  • Updates itself, and never restarts on its own
  • Keeps running in the tray when you close it
  • VPN mode through Windows' own admin prompt

Not yet code-signed — SmartScreen may ask once. Here's what to click.

Check your download

Every release lists a SHA-256 for each file. Put SHA256SUMS next to what you downloaded, then run the line for your system. On Windows, compare the hash it prints with the one in the file.

macOS / Linux
shasum -a 256 -c SHA256SUMS --ignore-missing
Windows (PowerShell)
Get-FileHash .\Nunya_<version>_x64-setup.exe -Algorithm SHA256

Install, update and remove

Pick your platform. Each step is the whole step — nothing hidden behind a link.

1Install

  1. Download Nunya_<version>_aarch64.dmg and open it.
  2. Drag Nunya into Applications. It has to live there for VPN mode to work.
  3. Open Nunya. The beta isn't signed by an Apple Developer account yet, so macOS stops it the first time.
  4. Go to System Settings → Privacy & Security, scroll down, and choose Open Anyway. You only do this once.

VPN mode: the first time you connect in VPN mode, Nunya explains why and macOS asks for your administrator password. The password goes to macOS; Nunya never sees it.

2Update

  1. Nunya looks for a new release shortly after it starts, then every hour.
  2. It downloads the update and checks its signature against the key built into the app.
  3. When it's ready, choose Restart to update. Nunya never restarts on its own, so a connection you're using isn't dropped.

Betas are offered too, unless you turn off Beta versions under Advanced → Updates. VPN mode asks for your password once more after each update. A copy older than the first self-updating version has to be replaced by hand, once.

3Remove

  1. Disconnect, then quit from the menu-bar shield → Quit (closing the window leaves it running).
  2. Drag Nunya from Applications to the Trash. VPN mode's engine lives inside the app, so it goes too.
  3. Optional — to remove your servers and settings as well:
rm -rf ~/Library/Application\ Support/com.nunyavpn.app

Nunya puts your own proxy setting back when it disconnects. If it was quit unexpectedly while connected, check System Settings → Network → (your network) → Details → Proxies.

Questions

Does Nunya sell a VPN service?

No. Nunya is a client: it connects you through servers you already have, from your provider or your own. It has no servers, accounts or subscriptions of its own.

Why does my system warn me when I open it?

The beta isn't signed with a paid Apple Developer account or a Windows code-signing certificate yet. Check your download against SHA256SUMS, then follow the first-launch step in the install guide.

Should I use proxy mode or VPN mode?

Proxy mode needs no password and covers apps that use the system proxy — Nunya tells you which aren't covered. VPN mode covers the whole device and asks for your system's permission once. When in doubt, use VPN mode.

Something doesn't connect. Where do I look?

Open Diagnostics — the pulse icon at the bottom of the left edge. It shows the engine's log, the connection's state, and the exact configuration the server runs with. Include it when you open an issue.

How can I support Nunya?

Donations are being set up through two channels only: Buy Me a Coffee and crypto wallets. They'll be listed in the README and the app's Support panel once they're open. Anyone asking for payment in Nunya's name anywhere else is not us.

Bring your servers. Nunya does the rest.