This guide explains how to install and use the Private Internet Access (PIA) app on your Mac.
Jump To:
- Download and Install the PIA macOS App
- Sign In and Connect to the VPN
- Use the Expanded Display
- Connect to a VPN Server Location
- Favorite a VPN Server Location
- Use a Different VPN Protocol
- Change the DNS Server
- Enable or Disable Port Forwarding
- Allow LAN Traffic
- Enable or Disable the Kill Switch
- Turn PIA MACE On or Off
- Activate a Dedicated IP
- Configure Automation Rules
- Use Split Tunneling
- Use the Multi-Hop Feature
- Change the Language
- Change the App's Appearance
- Manage Your Account
- Check Your App Version and Send Debug Logs
Download and Install the PIA macOS App
- Go to the PIA installer page. The download starts automatically. If it does not, click the link on the page to restart it.
- Open your Downloads folder, then double-click the downloaded ZIP file and double-click the Private Internet Access Installer it contains.
- When macOS asks whether you want to open the installer, click Open.
- If you experience an error that prevents you from opening the app installer, follow the troubleshooting guidance below.
- At the password prompt, enter your Mac username and password, then click Install Helper. Do not enter your PIA username and password here.
- Once the app opens to the welcome screen, click LOG IN.
Note: Before you log in, you can select the QUICK TOUR button for a brief introduction of what the app offers.
- Enter the username and password from your PIA account confirmation email, then click LOG IN.
- You can now use the PIA app on your macOS device.
Use the Expanded Display
The main window shows your connection status, selected server, and IP addresses. The expanded display adds further connection details and shortcuts without opening Settings.
-
Click the down arrow at the bottom of the main window.
-
To close it, click the up arrow in the same position.
Connect to a VPN Server Location
-
On the main window, click the VPN SERVER widget.
-
Click a location from the list. To let the app pick for you, click Choose automatically.
The list is sorted by Name by default. Click Latency to sort by the response times shown next to each location instead. You can also type a location name into the search field at the top.
Alongside standard locations, the list includes streaming-optimized servers and virtual servers. A virtual server gives you an IP address registered to that country, though the server itself is hosted elsewhere. These are marked with a globe icon.
Favorite a VPN Server Location
Click the heart icon next to a location to add it to your favorites. Click the heart icon again to remove it from favorites.
Use a Different VPN Protocol
A VPN protocol is the set of rules the app uses to route data between your Mac and PIA's servers. The macOS app offers OpenVPN and WireGuard. To change your VPN protocol:
-
Click the three-dot menu icon (⋮), then click Settings.
-
Click the Protocols tab, and click OpenVPN® or WireGuard®.
Each protocol exposes a different set of options:
- OpenVPN: Transport switches between UDP and TCP. Remote Port sets the port used for the connection. Data Encryption sets the cipher. MTU sets the packet size. Try Alternate Settings lets the app fall back to other settings automatically if the chosen transport and port do not work.
- WireGuard: Connection Timeout sets how long the app waits before abandoning a connection attempt. MTU sets the packet size.
Note: If you switch protocols while connected to a server, reconnect for the change to take effect.
Change the DNS Server
The app routes DNS lookups to PIA DNS by default, so the domains you visit are resolved by PIA rather than your internet provider. You can change this if you would rather use a different DNS provider or a specific one required by your network.
-
Click the three-dot menu icon (⋮), then click Settings.
-
Click the Network tab, then click the DNS dropdown menu and choose an option.
Enable or Disable Port Forwarding
Port forwarding opens a port on your Mac from your VPN IP address. The port is assigned automatically, and not every location supports it.
-
Click the three-dot menu icon (⋮), then click Settings.
-
Click the Network tab, then check or uncheck Request Port Forwarding.
Allow LAN Traffic
Allow LAN Traffic permits traffic between devices on your local network even while the kill switch is active. It is enabled by default. To change it:
-
Click the three-dot menu icon (⋮), then click Settings.
-
Click the Network tab, then check or uncheck Allow LAN Traffic.
Enable or Disable the Kill Switch
The kill switch blocks traffic from going outside the VPN, including during a connection loss.
-
Click the three-dot menu icon (⋮), then click Settings.
-
Click the Privacy tab, then check or uncheck VPN Kill Switch.
The app also includes Advanced Kill Switch, on the same tab, which blocks traffic from going outside the VPN even when the VPN is turned off.
Turn PIA MACE On or Off
PIA MACE blocks domains used for ads, trackers, and malware. It is disabled by default.
-
Click the three-dot menu icon (⋮), then click Settings.
-
Click the Privacy tab, then check or uncheck PIA MACE.
Activate a Dedicated IP
A Dedicated IP is a static IP address assigned to your account alone. It is a paid add-on.
-
Click the three-dot menu icon (⋮), then click Settings.
-
Click the Dedicated IP tab, and paste your token into the field, then click Activate.
If you have purchased a Dedicated IP but do not have a token, generate one from the My Account link on the same tab. To buy one, click Get Your Dedicated IP.
Configure Automation Rules
Automation rules connect or disconnect the VPN by themselves when you join a particular type of network.
-
Click the three-dot menu icon (⋮), then click Settings.
-
Click the Automation tab, then check Connection Automation and click Add Automation Rule.
-
Under Network, click Protected Wi-Fi, Open Wi-Fi, or Wired Connection. Under Action, click Connect or Disconnect, then click OK.
The rule appears under Your Automation Rules and applies whenever you join that network type.
Use Split Tunneling
Split tunneling decides which apps and IP addresses use the VPN and which connect directly.
-
Click the three-dot menu icon (⋮), then click Settings.
-
Click the Split Tunnel tab, then check Split Tunnel.
-
Click Add Application or Add IP Address, then set whether or not it uses the VPN.
The All Other Apps row sets the behavior for everything you have not written a rule for.
Note: If the app reports that Split Tunnel is not installed, macOS needs to approve the extension first. Open System Settings > General > Login Items & Extensions, click the i icon in the Network Extensions row, turn on PIA Split Tunnel, and click Done. Then click Allow on the proxy configurations prompt.
Use the Multi-Hop Feature
Multi-Hop routes your VPN traffic through a proxy before it reaches the VPN server. This adds a layer of encryption and hides the fact that you are using a VPN.
Note: Multi-Hop is only available when using the OpenVPN protocol.
-
Click the three-dot menu icon (⋮), then click Settings.
-
Click the Multi-Hop tab, then check Multi-hop and Obfuscation.
-
Under Proxy, click Shadowsocks or SOCKS5 Proxy, then click EDIT to choose a proxy location.
Because your traffic passes through an extra server, speeds may be slower than on a standard VPN connection.
Note: To use the SOCKS5 proxy, you’ll also need to generate credentials via the Client Control Panel. For more information and detailed setup steps, read our guide to using the Multi-Hop feature.
Change the Language
-
Click the three-dot menu icon (⋮), then click Settings.
-
On the General tab, click the Language dropdown menu and choose a language.
Change the App's Appearance
These settings are on the General tab, reached by clicking the three-dot menu icon (⋮) and then Settings.
- Theme: Click the Theme dropdown menu and choose Dark or Light.
- Tray Icon Style: Click the Tray Icon Style dropdown menu and choose an option.
- Dashboard Appearance: Click the Dashboard Appearance dropdown menu. Attached to Tray fixes the main window to the menu bar.
The General tab also holds Launch on System Startup and Connect on Launch, which open the app and connect the VPN automatically when your Mac starts.
Manage Your Account
The Account tab shows your PIA username and subscription status.
-
Click the three-dot menu icon (⋮), then click Settings.
-
Click the Account tab.
From here, Manage My Account opens your account page in a browser, and Log Out / Switch Account signs you out of the app.
Check Your App Version and Send Debug Logs
The Help tab shows your installed version and build number, along with troubleshooting tools.
-
Click the three-dot menu icon (⋮), then click Settings.
-
Click the Help tab.
From here you can:
- Enable Debug Logging: Records diagnostic logs. Turn this on before reproducing an issue you want to report.
- Submit Debug Logs: Sends the recorded logs to PIA's support team.
- Receive Beta Updates: Opts you into pre-release versions of the app.
- Help Improve PIA: Shares anonymous connection statistics. View shared data shows exactly what is sent.