Note: If you prefer to control the ExpressVPN Mac app with a graphical user interface (GUI), you can do so using the ExpressVPN GUI app for Mac or via the ExpressVPN browser extension for Chrome and Firefox.

You can control ExpressVPN on macOS through its command-line interface (CLI), using commands in Terminal, the built-in command-line app. If you already work at the command line, this lets you manage your VPN without having to switch to the app’s graphical interface.

ExpressVPN is compatible with macOS 11 (Big Sur) and above. To find out which macOS version you are using, refer to this guide.

Jump to…


Download the installer

  1. Go to the ExpressVPN+ setup page and log into your ExpressVPN account if prompted.
  2. Under Operating systems, select Mac and click Download Now.The ExpressVPN+ setup page, showing the Mac tab, with a highlighted "Download Now" button.
  3. If prompted, click Save to confirm saving the file to your Mac.The MacOS Save dialog.

Need help? Contact the ExpressVPN Support Team for immediate assistance.

Back to top


Install and activate the app

Install the app

  1. Find the downloaded ExpressVPN Installer file and double-click to open it.The ExpressVPN installer icon highlighted in the Downloads folder on macOS.
  2. When the “ExpressVPN Installer” is an app downloaded from the internet. Are you sure you want to open it? prompt appears, click Open.macOS security prompt asking whether to open “ExpressVPN Installer,” downloaded from the internet, with "Cancel" and "Open" buttons.
  3. When prompted to allow ExpressVPN to install a new helper tool, enter your password and click Install Helper to install the app.The ExpressVPN installer tool on macOS.

Activate the app

To use the CLI, you need to sign in to your ExpressVPN account in the macOS app.

To sign into your account in the ExpressVPN app on macOS, open it and click Sign In.The ExpressVPN app for macOS, with a highlighted "Sign in" button.

There are three ways to sign in to the app:

  • With your activation code: This is your account’s activation code, which you can find in the setup page. You can copy and paste it in the activation code field, and you will be logged into your account.
  • With an email sign-in link: Enter the email address associated with your ExpressVPN account, and you will get an email from ExpressVPN with a link you can click on to get logged in.
  • With your password: Enter the email address associated with your account and your password, and you will be signed into your account.

After you are logged in:

  1. Your Mac will ask permission to complete the configuration. Click Continue.
  2. You will be asked whether you want to allow ExpressVPN to launch on startup. Select your preference to continue.
  3. You will be asked whether you want to help improve ExpressVPN by sharing anonymous diagnostics with ExpressVPN. This helps ExpressVPN continually improve its products and services. Select your preference to continue.
  4. If advanced protection is included in your subscription, you will be asked if you want to block display ads and enable additional safeguards. Select your preference to continue.

Once done, you can use the CLI to control the ExpressVPN app.

Need help? Contact the ExpressVPN Support Team for immediate assistance.

Back to top


View all commands

To see the available ExpressVPN CLI commands and options, open Terminal and run:

expressvpnctl -h

Need help? Contact the ExpressVPN Support Team for immediate assistance.

Back to top


Connect to a VPN server location

Important: The ExpressVPN app needs to be open for the connection commands to work. If you do not want to have to keep the app open, you can enable background mode by running:

expressvpnctl background enable

To connect to the VPN, run the following command:

expressvpnctl connect

The first time you connect, ExpressVPN automatically chooses a server location using Smart Location. The selection is based on factors such as your connection speed and distance from the server.

For subsequent connections, the CLI uses the last server location you connected to.

Need help? Contact the ExpressVPN Support Team for immediate assistance.

Back to top


Disconnect from a VPN server location

To disconnect from a VPN connection, use the following command:

expressvpnctl disconnect

Need help? Contact the ExpressVPN Support Team for immediate assistance.

Back to top


Choose a different VPN server location

To view the available VPN server locations, run:

expressvpnctl get regions

Connect to a specific VPN server location

Specify the server location you want to use with:

expressvpnctl connect "LOCATION"

For example, the following command connects you to Germany – Frankfurt – 1:

expressvpnctl connect "Germany - Frankfurt - 1"

Need help? Contact the ExpressVPN Support Team for immediate assistance.

Back to top


Switch to a different VPN protocol

A VPN protocol determines how your device communicates with the VPN server. ExpressVPN recommends Automatic, which is selected by default and chooses a suitable protocol for your network. If you experience connection or speed issues, trying another protocol may help.

Important: You should disconnect from the VPN before changing the protocol.

To switch to Lightway – TCP, run:

expressvpnctl set protocol lightwaytcp

To switch to Lightway – UDP, run:

expressvpnctl set protocol lightwayudp

To switch to Lightway – TCP, run:

expressvpnctl set protocol wireguard

To switch to OpenVPN – TCP, run:

expressvpnctl set protocol openvpntcp

To switch to OpenVPN – UDP, run:

expressvpnctl set protocol openvpnudp

To switch back to Automatic, run:

expressvpnctl set protocol auto

Need help? Contact the ExpressVPN Support Team for immediate assistance.

Back to top


Use split tunneling

When you use split tunneling on macOS via the CLI, you can only set rules for apps that bypass the VPN tunnel.

Note: If you also want to add apps to always use the VPN tunnel or add a specific IP address to bypass the VPN tunnel, you must use the split tunneling option in the ExpressVPN GUI app.

To turn on split tunneling, run:

sudo expressvpnctl set splittunnel true

To add an app that bypasses the VPN, run:

sudo expressvpnctl set split-app bypass:PATH/TO/APP

For example, to have Firefox bypass the VPN, run:

sudo expressvpnctl set split-app bypass:/Applications/Firefox.app

To remove a split tunneling rule, run:

sudo expressvpnctl set split-app remove:PATH/TO/APP

Need help? Contact the ExpressVPN Support Team for immediate assistance.

Back to top


Block ads, trackers, and harmful sites

You can use ExpressVPN’s advanced protection features to block ads, trackers, malicious sites, and adult content.

Many apps and websites share information about your activity with third-party companies, including trackers. This information can be used to personalize the ads and content you see.

Advanced protection features prevent apps and websites on your Mac from communicating with third-party companies listed in ExpressVPN’s open-source blocklists.

These features are disabled by default. You can enable all of them at once or manage each feature separately.

Enable all advanced protection features

1. Open the Terminal window.

2. Connect to the VPN.

To enable all advanced protection features, run:

expressvpnctl set blockAll true

To disable all advanced protection features, run:

expressvpnctl set blockAll false

4. Press Enter.

5. Reconnect to the VPN for the changes to take effect.

Block trackers

1. Open the Terminal window.

2. Connect to the VPN.

3. To block trackers, run:

expressvpnctl set blockTrackers true

To disable tracker blocking, run:

expressvpnctl set blockTrackers false

4. Press Enter.

5. Reconnect to the VPN to apply the change.

Block malicious sites

To block malicious sites, run:

expressvpnctl set blockMalicious true

To turn off this feature, run:

expressvpnctl set blockMalicious false

Press Enter, then reconnect to the VPN for the change to take effect.

Block ads

To enable the ad blocker, run:

expressvpnctl set blockAds true

To disable it, run:

expressvpnctl set blockAds false

Press Enter, then reconnect to the VPN to apply the change.

Block adult sites

To block adult sites, run:

expressvpnctl set blockAdult true

To disable this feature, run:

expressvpnctl set blockAdult false

Press Enter, then reconnect to the VPN for the change to take effect.

Need help? Contact the ExpressVPN Support Team for immediate assistance.

Back to top


Use the Internet Kill Switch

The Internet Kill Switch blocks your internet traffic when your VPN connection drops unexpectedly to help prevent your data from being exposed outside the VPN connection. It is enabled by default, and you can only disable it via the GUI app.

That said, you can use the CLI to enable the Advanced Internet Kill Switch. It blocks all internet traffic unless the VPN is connected.

To turn this setting on, run:

sudo expressvpnctl set networklock true

To turn it off, run:

sudo expressvpnctl set networklock false

Need help? Contact the ExpressVPN Support Team for immediate assistance.

Back to top


Uninstall the app

You can only remove the ExpressVPN app from your Mac via the ExpressVPN GUI app.

  1. Open the Profile tab.The Profile tab highlighted in the ExpressVPN app for macOS.
  2. Scroll to Actions and select Uninstall ExpressVPN.The Profile tab menu, with the "Uninstall ExpressVPN" option highlighted in the ExpressVPN app for macOS.
  3. Click Uninstall to confirm.The "Are you sure" prompt in the ExrpressVPN app for macOS, showing a "Cancel" and "Uninstall" button.
  4. Enter your Mac password, then click Install Helper.The ExpressVPN installer helper tool, with the ExpressVPN app for macOS and the uninstall pop-up in the background.

ExpressVPN is now removed from your Mac.

Need help? Contact the ExpressVPN Support Team for immediate assistance.

Back to top

Was this article helpful?

We're sorry to hear that. Let us know how we can improve.

A member of our Support Team will follow up on your issue.