macOS · Per-app proxy

Give every app its own network.

Your browser on the corporate proxy, your terminal on a staging gateway, a client’s tool on their network, games and localhost direct — all at the same time, on one Mac. Pick apps by their icon; the apps themselves need no proxy settings. UDP and QUIC are really proxied, not dropped.

Free full trial · No card required · macOS 13+ · Signed & notarized by Apple · Bring your own SOCKS5 / HTTP proxy

Each app gets its own upstream, and they all run at once. Your rules, connection traces and traffic content stay on your Mac; you stay in control of every upstream.

Sound familiar?

The networks are separated. Your work doesn't have to be.

01

"I need several isolated internal networks at once"

Your server zone, operations network and customer intranet each depend on a different VPN. Keep the VPN clients connected and automatically route your IDE, terminal, browser and admin tools to their assigned local proxy ports — no more disconnecting and switching.

Explore per-app routing →

02

"Only these apps should use this route"

The macOS system proxy affects every app, while a full-tunnel VPN can also capture local services and traffic for other intranets. Assign only the apps that need this route; everything else stays direct or uses another one.

Explore VPN split routing →

03

"UDP and QUIC just don't get proxied"

Proxifier on macOS won't forward UDP over SOCKS5, and QUIC is left to luck. Here UDP ASSOCIATE is actually implemented, and QUIC has three explicit states.

How to do it →

04

"Every network change means re-configuring"

Office Wi-Fi, home cable and a phone hotspot each need their own rules. Bind a profile to a network and it switches back on its own.

Learn more →

Coming from Proxifier? See the side-by-side comparison →

More guides: How to use a SOCKS5 proxy on macOS· Proxy the terminal, git and npm· Block an app from the internet· When an app ignores the system proxy

What it does

A clear decision for every connection.

01

Per-app, multi-upstream routing

Send your IDE to the server-zone port, terminal to operations and browser to a customer intranet. Configure the rules once; every upstream works at the same time.

02

Real UDP / QUIC proxy

SOCKS5 UDP ASSOCIATE forwarding — something Proxifier simply can't do. QUIC gets three states: proxy, fall back to TCP, or direct.

03

Rule-trace explainer

Expand any connection to see exactly why it took that path. A dry-run tester tells you which rule matches — without sending a packet.

04

Auto network switching

Wi-Fi by SSID; wired by gateway MAC + subnet — so 'office cable' and 'home cable' are told apart. Bind a profile to a network and it switches back on its own.

05

CLI + MCP

proxyrouterctl on the command line, URL Scheme, App Intents — and a built-in MCP server so Claude and other LLMs manage your rules directly.

06

Cut one app off entirely

Beyond Direct and Proxy there is a third action: Block. Give an app a block rule and its connections are closed outright — not throttled, cut off. Useful for stopping a program from phoning home, or temporarily severing an app you do not trust.

07

Safe defaults, built in

fake-IP DNS, loopback protection, localhost guards — the defaults you'd only get right after being burned are already configured.

Rule-trace explainer

Every routing decision comes with an answer.

Every live connection expands into the exact chain of rules it walked — matched, skipped, and why. The dry-run tester answers the same question before a single packet leaves your machine.

  • Pure-function rule engine — the tester and the live path always agree.
  • Same logic drives the UI, the CLI and MCP — behavior never drifts.
Chrome edge.quic.example.com:443 SOCKS5 · JP
  1. rule 03app = Chrome · proto = QUICmatch
  2. actionproxy → SOCKS5 · JP (UDP ASSOCIATE)

Dry-run · no packet sent

proxyrouterctl
$ proxyrouterctl route add --app Chrome --proxy jp-socks
 rule 03  Chrome · QUIC  →  SOCKS5 · JP

$ proxyrouterctl test --app Chrome --host example.com
 match rule 03  ·  proxy SOCKS5 · JP  ·  no packet sent

# or just ask Claude, over MCP
 "route Chrome's QUIC through the Japan node"  done

CLI + MCP

Drive it from the terminal — or hand it to Claude.

proxyrouterctl ships with zero third-party dependencies. The built-in MCP server exposes the same automation surface the UI uses, so an LLM can read your connections and reshape your rules in plain language.

Honest comparison

Familiar per-app routing, with fewer blind spots.

Capability ProxyRouter Proxifier
Per-app routing (real icons)YesProcess names
SOCKS5 UDP / QUIC proxyYesNo
Rule-trace explainer + dry runYesNo
Auto network-env switchingWi-Fi + wiredLimited
CLI + MCP (LLM control)YesNo
Block an app from the networkYesSeparate firewall
fake-IP DNS + loop guardsYesManual

Good to know

The essentials, before you install.

Does ProxyRouter include proxy servers?

No. It is a traffic router, not a proxy service. Bring your own SOCKS5 or HTTP upstream.

Do I need to configure every app?

No. Choose the app and route in ProxyRouter; the target app does not need its own proxy settings.

Can I stop an app from reaching the network at all?

Yes. Give it a Block rule and its connections are closed immediately. Blocked attempts are labelled and counted in the Activity view, so you can still see where the app was trying to go.

Is my traffic sent to your servers?

No. Routing, rule evaluation and license checks happen locally. Traffic goes only to destinations you configure.

Which Macs are supported?

macOS 13 or later, on both Apple Silicon and Intel Macs.

Still unsure? Contact us or read the system requirements.

Why you can trust it

It sees your traffic. So here is exactly what that means.

Signed and notarized by Apple

Signed with an Apple Developer ID certificate (Mei Yang, Team ID MLBB37VST8) and notarized by Apple. Verify it yourself: run spctl -a -vvv -t install ProxyRouter.dmg — it should report accepted and Notarized Developer ID.

Why a system extension, and what can it see?

Routing by process has to happen at the system network layer, and macOS offers exactly one way to do that (Network Extension). It sees the destination, port and originating process of each connection — the facts needed to pick a route. Rule evaluation and connection traces stay on your Mac and are never uploaded.

How do I fully uninstall it?

Click "Remove system extension" in Settings, then drag ProxyRouter to the Trash. Your network settings return to what they were, and no background daemon is left behind.

Does it conflict with Clash, Surge, a VPN or Little Snitch?

They coexist. The most common setup is to point ProxyRouter at a local client like Clash as its upstream. Running two full transparent proxies at once will fight, so keep the other tool in "local port" mode. Little Snitch is a filtering extension and runs alongside fine.

Does any traffic go to your servers?

No. We do not provide, host or resell any proxy or VPN endpoint, and no server of ours is involved in your connections. Every upstream is one you configure yourself — a corporate proxy, a staging gateway, or a port on localhost.

Version and updates

Current release 1.0.0 (build 9), for macOS 13 or later on Apple Silicon and Intel. Updates arrive in-app through Sparkle, and every update is signature-checked before it is applied.

Pricing

Try it free first. Then own it your way.

Every plan is the full app — nothing is held back during the trial. When a trial or subscription ends, only proxying stops; your config is never touched.

Monthly

$1.99/ month

  • All features
  • Billed monthly
  • Cancel anytime
Choose monthly

Yearly

$7.99/ year

  • All features
  • About $0.67/month
  • Updates and new macOS support
Choose yearly

Every plan starts with the same free full-feature trial — no card required. Checkout is securely processed by Creem, our merchant of record.