Installation

The filtering network extension must have a unique name to avoid conflicts with other software.

  • Rename the project in the Xcode project. The specified bundle name of the network extension target is used during API initialization in nf_init. Each project must use a unique name, because the extension does not allow multiple attached processes.

  • Sign the extension using the automatic signing option in Xcode for development, or manually for distribution. See the Signing the network extension section for details on signing the network extensions.

  • Install the extension by starting the installer application containing the network extension. When a popup window appears with the message ‘“installer application name” would like to use a new network extension’, click the button “Open System Settings”, enable the displayed extension, then allow adding the proxy configuration. The extension files are installed automatically in /Library/SystemExtensions. By default, the extension is loaded and enabled automatically at OS startup without any additional popups. The installer application must remain on disk.

  • To unregister the extension, call <installer application>/Contents/MacOS/<installer name> -unregister. The extension files are deleted automatically after a reboot.

It is possible to unload and restart the extension dynamically in System Settings (General | Login Items & Extensions).

To update the extension, run the installer with empty arguments.

Supported platforms:

macOS 15.6 or later, x64/ARM64