Open-source project
Tunnelblick/Tunnelblick avatar
Tunnelblick/Tunnelblick

Tunnelblick: the OpenVPN GUI for macOS and what its repository actually ships

The official Tunnelblick website is at https://tunnelblick.net; the official Tunnelblick GitHub repository is at https://github.com/Tunnelblick

3,283 stars368 forksObjective-CGPL-2.0

At a glance

What is it?
Tunnelblick is a GPL-2.0 Objective-C front end that gives macOS users control of OpenVPN client and server connections. The README is short, the website carries the detail, and the last push was on 2026-09-04.
Who is it for?
Adopt Tunnelblick if you run OpenVPN on macOS and want a graphical layer that also manages server connections, and you are willing to read tunnelblick.net because the README does not carry setup instructions. Do not adopt it if your clients are on Windows, iPad or iOS, because the project describes itself as a macOS interface and ships no client for those platforms.
Can I use it commercially?
Yes, with conditions. GPL-2.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
Is it still maintained?
Yes. The repository last received commits 1 day ago.
What is it written in?
Mainly Objective-C, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What Tunnelblick is for, and who it leaves out

Tunnelblick is a free, open source graphical user interface for OpenVPN on macOS. That sentence from the README is the whole scope statement. It provides easy control of OpenVPN client and server connections, which means it is not only a way to click connect on a profile; the same application covers the server side of an OpenVPN link as well.

The audience is therefore narrow and specific. You are on macOS, you already have OpenVPN as your tunnel protocol, and you want a window instead of a command line. If any of those three is false, the project is the wrong shape. The related searches show how often people look for Tunnelblick for Windows 11, for iPad, or for iOS. The README answers none of those: it names macOS and OpenVPN, and nothing else. Anyone hunting a cross-platform client should stop reading here rather than hope.

The licence is GPL-2.0, stated plainly in the README and in the COPYING file at the top level of the repository. That matters for anyone who wants to ship a modified build inside a product, because the terms follow the code.

How the repository is laid out and where the real documentation lives

The README opens by pointing away from itself. The official website is at tunnelblick.net, and a snapshot copy of that website sits at tunnelblick.github.io, recreated at each release and when significant changes are made to the website. So the repository is not the documentation. It is the source tree plus a pointer to the site.

The top level holds .github/, .gitignore, "Building Tunnelblick from Source Code.markdown", COPYING, README.md, SECURITY.md, third_party/ and tunnelblick/. The primary language is Objective-C, which is consistent with a native macOS application rather than a wrapper around a command line tool. third_party/ indicates bundled dependencies, and the build instructions live in their own markdown file rather than in the README, which is a deliberate split: the README is for users and contributors, the build file is for people compiling.

Two contribution rules stand out. Pull requests are welcome for everything except translations and localization; the README states that localization PRs are not accepted, and directs people to a page on tunnelblick.net instead. Bug reports are preferred on the Tunnelblick Discussion Group, with GitHub Issues accepted as well. Security vulnerabilities go through SECURITY.md rather than the public tracker. If you plan to file anything, that routing is the first thing to get right.

Installing Tunnelblick on a Mac and a first connection

The README does not contain install steps. It gives the website, and the website is where the download and the setup instructions live. Because the README is silent on the exact download flow, treat tunnelblick.net as the source of truth and do not trust a mirror or a package manager listing without checking it against that site.

One related search phrase is "tunnelblick brew". A Homebrew formula exists in the wider ecosystem, but the README and the repository files here do not document one, so the honest position is that the project itself points to tunnelblick.net for distribution. If you install through Homebrew, verify the version against the releases the project publishes.

Once installed, the working unit is a configuration file. The related searches include "Tunnelblick configuration files", and that is the right mental model: you supply an OpenVPN configuration, and the application manages the connection around it. The README does not include a sample configuration, so the file format is defined by OpenVPN rather than by Tunnelblick. What the reader should see after adding a working configuration is the connection appearing in Tunnelblick's list, ready to be started from the menu bar. The README does not describe that interface in detail, so expect to follow the website for the click-by-click path.

For building from source rather than installing a release, the repository carries "Building Tunnelblick from Source Code.markdown" at the top level. That file, not the README, is where the toolchain requirements belong.

Release cadence, the 10.0 beta line, and what maintenance looks like

The project is not archived, and the last push was on 2026-09-04. Three recent releases sit close together: v10.0beta02, labelled Tunnelblick 10.0beta02 (build 6510), on 2026-09-04; v9.0.1, labelled Tunnelblick 9.0.1 (build 6491), on the same date; and v10.0beta01, labelled Tunnelblick 10.0beta01 (build 6500), on 2026-08-27.

Read that sequence carefully, because it tells you something the README does not. The stable line and the beta line are being published in parallel, and the beta builds carry higher build numbers (6510, 6500) than the stable build (6491). If you are deploying to machines you cannot easily recover, the 9.0.1 release is the conservative choice. The 10.0 beta line is where current work is landing.

Upgrade cost is low in the ordinary case, because a Tunnelblick update replaces the application and your configuration files stay where they are. The cost that is not zero is configuration drift: OpenVPN itself continues to evolve, and a configuration that works today can need editing later. The README does not document a rollback path, so if you move a fleet to the 10.0 beta series, capture the previous installer before you do.

Where Tunnelblick is the wrong tool

The clearest limitation is platform. Tunnelblick is a macOS interface. The related searches for Windows 11, iPad and iOS reflect a demand the project does not serve, and the README gives no indication that it intends to. If your users are on Windows, you need a different client for the same OpenVPN server.

The second limitation is protocol. Tunnelblick is a GUI for OpenVPN specifically, not a general VPN client that speaks several protocols. If your organisation has standardised on WireGuard, IPsec or a commercial provider's own client, Tunnelblick is not a drop-in substitute.

The third is that the README is thin on operational detail. It does not cover uninstallation, it does not cover rollback, and it does not walk through configuration file placement. Everything of that kind is delegated to tunnelblick.net. For a project of this age that is a reasonable division of labour, but it means you cannot evaluate Tunnelblick by reading the repository alone, and any internal runbook you write will depend on an external site remaining available.

Finally, the contribution policy is a real constraint for anyone hoping to give back. Translations and localization pull requests are explicitly not accepted. If your interest in the project is translating it into your language, the README sends you to a separate page on the website rather than to the issue tracker.

Tunnelblick against OpenVPN Connect and the command line

The obvious alternative is OpenVPN Connect, the client published by the OpenVPN project itself. The difference in approach is ownership and integration. Tunnelblick is a third-party macOS interface maintained by its own project under GPL-2.0; OpenVPN Connect comes from the protocol's own vendor. That distinction shows up in how you get support, how the licence applies, and which side decides what the client looks like. The related searches include "tunnelblick vs openvpn connect", which suggests the comparison is common, but the Tunnelblick README makes no claim about the other client, so any feature-by-feature table has to come from somewhere else.

The second alternative is not a product at all: running the openvpn command directly. That approach removes the GUI layer entirely. You get scriptability and no application to update, and you give up the menu-bar control and the connection management that Tunnelblick exists to provide. For a single machine with one tunnel and a user comfortable in a terminal, the command line is genuinely sufficient. For a desktop user who needs to switch between several profiles, the graphical layer is the point.

A third path, for people who want a different protocol rather than a different client, is to leave OpenVPN behind. Tunnelblick cannot help there, because the README defines it as an OpenVPN interface and nothing broader.

Licence and what GPL-2.0 means for your build

Tunnelblick is released under the terms of the GNU General Public License, version 2. The README states this, and the COPYING file at the top level carries the licence text. This is not legal advice, and the terms themselves are the authority.

The practical consequence is that GPL-2.0 is a copyleft licence. If you modify Tunnelblick and distribute the result, the licence's obligations attach to that distribution. Using the unmodified application as a client on your own machines is a different situation from shipping a modified build inside a product, and the two should not be conflated. The repository also carries a third_party/ directory, which means some components come from elsewhere and may carry their own terms; check those separately rather than assuming the top-level licence covers everything in the tree.

If you are evaluating Tunnelblick for an organisation, the licence question is worth raising with whoever handles compliance before you build anything, not after.

Editorial conclusion

Adopt Tunnelblick if you run OpenVPN on macOS and want a graphical layer that also manages server connections, and you are willing to read tunnelblick.net because the README does not carry setup instructions. Do not adopt it if your clients are on Windows, iPad or iOS, because the project describes itself as a macOS interface and ships no client for those platforms. Before committing, open the SECURITY.md file linked from the README, check whether the 10.0 beta line is acceptable for your machines, and confirm that the GPL-2.0 terms fit how you intend to redistribute anything you build from the source.

Frequently asked questions

What is Tunnelblick used for?

It is a free, open source graphical user interface for OpenVPN on macOS, providing easy control of OpenVPN client and server connections. In practice it replaces the openvpn command line with a macOS application for people who prefer a graphical client.

Is Tunnelblick trustworthy?

The project publishes its source under GPL-2.0 and maintains a SECURITY.md file, linked from the README, that describes how to report a security vulnerability. The README itself makes no trust claims beyond pointing to that reporting process.

How do I install Tunnelblick on my Mac?

The README does not contain install steps. It directs readers to the official website at tunnelblick.net, which is where the download and setup instructions live, and notes that a snapshot copy of the site is recreated at tunnelblick.github.io.

How do I use Tunnelblick on macOS?

You supply an OpenVPN configuration file and Tunnelblick manages the connection around it. The README does not walk through the interface, so the click-by-click path comes from tunnelblick.net rather than the repository.

What is Tunnelblick on a Mac?

It is the graphical interface for OpenVPN on macOS, released under GPL-2.0. The README describes it as providing easy control of OpenVPN client and server connections.

Official sources

  1. Issues
  2. License: GPL-2.0
  3. README
  4. Releases
  5. Tunnelblick/Tunnelblick on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/tunnelblick-tunnelblick.svg)](https://hysenlabs.com/projects/tunnelblick-tunnelblick)