Setting Up Happ on Mac: From Installation to Traffic Routing
A complete guide to Happ for macOS: we install the client built on the Xray core, connect a key from the Telegram bot, and figure out when to enable proxy mode and when to use the system TUN with full routing.
How to connect Happ VPN on Mac
Download Happ for macOS
Install the app from the App Store or an official source.
Get a key
Open the Telegram bot and activate access.
Add the key via Import
Paste the copied subscription link into the app.
Allow the VPN config
Confirm the macOS prompt to add a VPN.
Turn on the connection
Pick a server and enable the VPN.
Installing Happ on macOS
Happ is a client built on the Xray core that on Mac works both as a regular application with a system proxy and as a full-fledged network tunnel. Download the macOS version, move the app to your Applications folder and launch it. On first launch, macOS may show a Gatekeeper warning that the program was downloaded from the internet — open System Settings → Privacy & Security and confirm the launch with the Open Anyway button.
For stable operation, macOS 12 Monterey or newer is recommended — on earlier versions some of the network APIs that Happ uses for TUN mode are unavailable. The client works equally correctly on Macs with Apple Silicon processors (M1–M4) and on models with Intel chips; there is no need to look for a separate build for each architecture, as the universal version selects the appropriate code itself.
After installation it makes sense to immediately allow Happ to launch at login and to show its icon in the menu bar. This is convenient: connecting, switching servers and changing modes stay within reach, and you do not have to open the app window every time.
Key and Subscription: How to Connect
Access to the servers is granted by the service's Telegram bot. Get a trial, official or paid key from the bot — in response you will receive either a subscription string (a link in the happ:// or https:// format) or a separate server configuration. There is no need to manually copy long configs on your Mac: the subscription pulls in the current server list itself and updates it whenever things change on the service side.
The quickest way to add a key is to copy the subscription link and tap Add from clipboard in Happ: the app recognizes the clipboard contents and imports the profile automatically. If you open a happ:// link directly in macOS, the system will offer to hand it off to Happ via deep link, and the profile will be added in one click.
After the import, the server list appears in the main window. Choose the node with the lowest ping, tap Connect and wait for the indicator to become active. The subscription only needs to be added once — when you renew the key in the bot there is no need to reinstall anything, the client pulls in updates on its own.
Proxy Mode and TUN Mode: Which to Choose
On macOS, Happ offers two fundamentally different ways to route traffic. Proxy mode brings up a local SOCKS/HTTP proxy and writes it into the system network settings. Requests from apps that respect the system proxy — browsers above all — go through it. This is a lightweight mode: it does not require administrator rights and does not affect the traffic of programs that work around the proxy.
TUN mode (also called system tunnel mode) creates a virtual utun network interface and intercepts traffic at the level of the entire system. In this case not only browsers but also messengers, desktop clients, the terminal and background services go through the tunnel. To activate TUN, Happ will ask once to install a privileged helper and to confirm the action with the administrator password — this is standard macOS behavior for apps that manage the network stack.
A practical rule: if you need the whole application to "take off" entirely, enable TUN. If the task is targeted — to open access only in the browser without touching the rest of the system — proxy mode is enough. You can switch between modes on the fly, without removing the subscription or changing the selected server.
Routing and Split Tunneling
The Xray core inside Happ supports flexible routing: you can set rules for which traffic goes through the server and which goes directly. On Mac this is most often used for split tunneling: for example, banking and local sites are sent around the tunnel, while everything else goes through the selected server. Rules are built by domains, IP subnets and geo-zones.
Ready-made routing lists spare you from manually listing hundreds of domains. By connecting such a list, you get preconfigured rule sets — for example, "local resources directly" or "block advertising and tracking domains". The lists are updated, so the rules stay current without any effort on your part.
Separately on macOS, the option to bypass local network traffic is useful: requests to printers, NAS and other devices on your home network should go directly, otherwise they will stop being discoverable. In the routing settings, keep private ranges (10.0.0.0/8, 192.168.0.0/16 and similar) outside the tunnel — this is standard and safe practice.
Optimization and Common Problems on Mac
If the internet has disappeared in all applications after enabling TUN, first check that the privileged helper was installed and that Happ has permission to change the network configuration in Privacy & Security. Revocation of this permission is the most common reason a tunnel comes up but traffic does not pass. Reinstalling the helper from the app settings usually solves the problem.
If the speed is slow, try switching to a geographically closer server and pay attention to the connection transport. Nodes with modern obfuscation protocols on the Xray core usually give a stable result on unstable channels, whereas an overloaded public node drops in speed during peak hours. The ping and server load are visible right in the list.
If the browser ignores the connection in proxy mode, check that it does not have its own proxy set or an extension intercepting the network — it overrides the system setting. And to keep Happ from disconnecting when the Mac goes to sleep, enable auto-connect on startup and tunnel persistence; then the connection will restore itself after the laptop wakes up.
Frequently asked questions
Does Happ work on a Mac with an Apple Silicon processor (M1–M4)?
Yes. The client ships as a universal build and works equally on Apple Silicon (M1, M2, M3, M4) and on Macs with Intel chips. There is no need to look for a separate version for your model — the app uses native code for your architecture on its own.
How does proxy mode differ from TUN mode on macOS?
Proxy mode brings up a system SOCKS/HTTP proxy and routes mainly browser traffic through the server without requiring administrator rights. TUN mode creates a virtual utun interface and intercepts the traffic of the entire system, including messengers and background services, but on first launch it asks to install a helper and enter the administrator password.
Where do I get a key for Happ on Mac?
The key and subscription are issued by the service's Telegram bot. Get trial, official or paid access from the bot, receive the subscription link and import it into Happ via Add from clipboard or through the direct happ:// link. There is no need to use other sources of access.
How do I set up part of the sites to bypass the tunnel?
Use split tunneling in the routing settings. Set rules by domains, IP subnets or geo-zones — or connect a ready-made routing list. Local and banking resources can be left going directly, while the rest of the traffic is sent through the selected server.
After enabling TUN the internet disappeared in all programs — what should I do?
Most often the reason is that Happ's permission to change the network configuration has been revoked or the privileged helper failed to install. Open System Settings → Privacy & Security, confirm access for Happ and reinstall the helper from the app settings, then reconnect.
Why do home network devices stop being discoverable when the tunnel is active?
In TUN mode all traffic, including requests to printers and NAS, may go into the tunnel. In the routing settings, keep private ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) outside the tunnel — then the local network will keep working directly.
Not connecting? See Happ VPN not working. Need a key — the Keys page.