Download

VPN Works comes ready-built for Linux and macOS. Each archive holds all five engines (vpnw, vpnw-scope, vpnw-lab, vpnw-ledger and vpnw-exit), plus scope-office, which makes the demo office for Scope. The license files and the README come with them.

System Download
Linux, x86-64 vpnw_linux_amd64.tar.gz
Linux, ARM64 vpnw_linux_arm64.tar.gz
macOS, Apple silicon vpnw_darwin_arm64.tar.gz
macOS, Intel vpnw_darwin_amd64.tar.gz
Checksums SHA256SUMS

These links always point to the newest release. Past releases and their notes are on the releases page.

Install

On Linux:

curl -LO https://github.com/VPNWorks/vpnw/releases/latest/download/vpnw_linux_amd64.tar.gz
curl -LO https://github.com/VPNWorks/vpnw/releases/latest/download/SHA256SUMS
sha256sum --ignore-missing -c SHA256SUMS
mkdir vpnw && tar -xzf vpnw_linux_amd64.tar.gz -C vpnw
vpnw/vpnw doctor

vpnw doctor checks whether this machine can run sealed runs, and says what’s missing if it can’t. The Linux binaries are static, so they run on any distribution with nothing else installed.

On a Mac, use the darwin archive and shasum -a 256 -c SHA256SUMS --ignore-missing to check it. The binaries aren’t signed by Apple, so macOS may stop them the first time. xattr -d com.apple.quarantine vpnw/* lets them run.

What runs where

VPN Works is Linux first. Sealed runs of the Agent, Lab, Scope’s recorder and the firewall rules all use the Linux kernel, so they need Linux.

The parts that work on files run anywhere, macOS included. That covers Ledger (seal, verify, prove) and Scope’s learn, replay and export. So a laptop can check a sealed log from a Linux server, or draft VPN rules from recorded flows.

All five engines are Alphas. They work and they’ve been tested, but nobody has used them in production yet.

How releases are made

Every release is built and checked by the project’s own pipeline on GitHub. The tests run on Linux and macOS, and each binary is run before anything is published. A release goes out only when every build and every check passes. The source code is the same as in the archives and builds with Go 1.24 alone, for anyone who’d rather compile it.