Documentation

SwiftStealth User Manual

Installation, setup and operation: everything from a downloaded app to a fully armed stealth suite. For SwiftStealth on macOS 13 or later, Apple Silicon.

1. Welcome to SwiftStealth

SwiftStealth is a macOS-native stealth suite. It routes the apps you choose through your own proxies, assigns each browser window a unique and realistic device fingerprint, and blocks the leaks that normally give you away: DNS, WebRTC and IPv6. Everything runs locally on your Mac, and your proxies and settings never leave your machine.

What you can do with it

  • Per-app proxying: route any app's traffic through a proxy group that you build and control.
  • Stealth browser: open the bundled SwiftStealth Browser with a fresh, consistent Apple persona on every window.
  • Rotation: move through your proxy pool on a timer, randomly, manually, or automatically after each task.
  • Leak protection: a kill-switch and continuous DNS, WebRTC and IPv6 leak blocking keep your real IP hidden.
  • Proxy Tester: bulk-test proxies for speed, country, reachability and fraud risk before you rely on them.
  • Automation API: drive everything from your own scripts over a local HTTP and WebSocket API on API plans.
The status pill. A small coloured pill floats in the bottom-right of the window. Green means "Stealth Active", blue means it is starting, orange means action is required, and red means an error or disconnected engine. Click it to expand a System Status panel showing the XPC service, Network Engine, DNS Leak Protection, running browser windows and the kill-switch.

2. Before you begin

System requirements

  • A Mac running macOS 13 (Ventura) or later on Apple Silicon (M1 or newer).
  • A valid SwiftStealth license key from your purchase confirmation.
  • Your own proxies. SwiftStealth does not sell or include proxies. It routes traffic through the ones you provide.
  • Administrator access to your Mac, so you can approve the system extension and DNS filter the first time.

A note on the two one-time approvals

macOS protects networking features behind explicit user approval. The very first time you run SwiftStealth you will grant two permissions, once each and never again: the Network Extension that performs the routing and leak-blocking, and the DNS filter that seals DNS lookups so they cannot leak to your internet provider. Both are covered step by step below.

3. Installation and first-time setup

This takes you from a downloaded app to a fully armed stealth suite. Follow it in order the first time; afterwards, SwiftStealth starts up on its own.

Step 1: Install the app

Open the SwiftStealth disk image (.dmg) you downloaded, drag the SwiftStealth icon into your Applications folder, then launch it. If macOS warns that it was downloaded from the internet, click Open.

Step 2: Activate your license

On first launch you'll see the activation screen. Paste your license key and activate, and the app binds the license to this Mac. If you later move to a new machine, release it from Settings using Deactivate This Mac.

Keep your key safe. Your license key is tied to your account and device count. Store it somewhere you can find it again, because you'll need it to activate a new Mac.

Step 3: Start the protection engine

After activation, SwiftStealth shows a "Starting Up" screen while it launches the protection engine. On a first launch, this is where macOS asks for the two approvals below. The ring around the app icon turns green and reads "Protection Ready" once everything is active.

Step 4: Approve and enable the Network Extension

If the screen shows an orange "Authorization Required" state, the Network Extension is waiting for you. Use the Open System Settings button, then:

  1. Go to General → Login Items & Extensions.
  2. Scroll to Network Extensions near the bottom and find SwiftStealth.
  3. Enable the switch next to SwiftStealth.
  4. If macOS shows a "System Extension Blocked" prompt, click Allow and approve it.
  5. Return to SwiftStealth and click Retry.
It's Login Items & Extensions, not Privacy & Security. On macOS 13 and later, the Network Extension is approved under General → Login Items & Extensions → Network Extensions. It does not appear in Privacy & Security. If you can't find it, make sure SwiftStealth has tried to start at least once so macOS has registered the extension.

Step 5: Enable the DNS filter

The DNS filter stops your DNS lookups from leaking to your internet provider. SwiftStealth creates it automatically the first time you activate a proxy group, but macOS installs it switched off, so you enable it once by hand:

  1. Open System Settings → Network.
  2. Click Filters in the Network list.
  3. Find the profile named SwiftStealth DNS Settings and turn its switch on.
  4. If macOS asks "Allow SwiftStealth to configure DNS settings?", click Allow.

Once enabled, DNS Leak Protection reads "Active" in the status pill whenever a group is running. You won't need to touch this again.

Step 6: Install the SwiftStealth Browser

If you plan to browse with built-in personas (and most people do), install the bundled browser. The first time the main window opens, SwiftStealth detects the browser is missing and offers to download and install it, so just click through. You can also install or update it any time from Settings → SwiftStealth Browser → Install Browser.

You're set up. When the status pill reads "Stealth Active" in green, the engine, DNS protection and, if installed, the browser are all ready.

4. Proxy Manager: your first proxy group

A proxy group bundles a pool of proxies, the apps that should use them, a rotation schedule, a fingerprint persona and a kill-switch. You can run several groups at once.

Proxy Manager
SwiftStealth Proxy Manager

4.1: Create the group

Open the Proxy Manager tab, click Add Group (the "+" button) or press ⌘N, then type a name that means something to you, such as "US Residential", and press Return.

4.2: Add your proxies

Open Paste Proxies under the Proxy Pool section, paste your proxies one per line, then click Parse & Add. Lines starting with # are treated as comments. SOCKS5 proxies must include the socks5:// scheme; all shorthand formats are treated as HTTP.

4.3: Set the proxy type

Under Proxy Type, choose Residential, ISP or Datacenter. This tunes connection retries and timeouts: residential gets more retries and a longer timeout, while ISP and datacenter connect immediately.

4.4: Assign apps

In Assigned Apps, click Add App to open the picker. Search or scroll, click Add next to each app, or use Enter Bundle ID Manually for anything unlisted.

Add the SwiftStealth Browser to browse with a group. It sits at the top of the picker (bundle ID com.swiftstealth.browser) and unlocks the Launch Browser button and persona controls. Chrome and Firefox are detected automatically; for Firefox, the internal plugin-container helper is routed too, so WebRTC can't leak your real IP.

4.5: Choose a persona

A persona is the device fingerprint a browser window presents to websites: user-agent, resolution, locale, timezone and more, drawn from a real Apple device cluster. Pick a region and city, then use Choose Persona to lock one in. Every window runs a fully isolated profile; if you don't choose a persona, each window gets a fresh random one.

4.6: Anti-Detect Mode

The Anti-Detect Mode switch changes how your canvas and audio fingerprints are presented, per group. Leave it off for general stealth browsing, because blending in with real Chrome is harder to detect. Turn it on when profiles must be clearly distinguishable, such as long-lived accounts that must never share a fingerprint.

4.7: Set rotation

Under Rotation, choose Sequential, Random or Manual. For timed modes, set the interval in seconds (minimum 10; under 30 shows a "Very fast" warning). Extension-driven rotation rotates automatically after each task delivery.

4.8: Arm the kill-switch

Turn on Kill-Switch so that if the active proxy ever drops, all traffic for the group is blocked until it reconnects, so nothing leaks unproxied. When engaged, the group shows an orange shield in the sidebar.

4.9: Activate and launch

Click Activate (the green play button). If you added the SwiftStealth Browser, click Launch Browser to open a stealth window using the group's proxy and persona. Click again for more windows, each with its own proxy and fingerprint. Click Deactivate to stop the group.

5. Instance Data: live monitoring

The Instance Data tab shows what's happening right now across every active group: the proxy in use, upload and download throughput, a countdown to the next rotation, the number of proxies in the pool and which one is active, plus the kill-switch state. It updates roughly once a second, so you can confirm a group is live, watch rotations happen, and spot a stalled proxy at a glance.

Instance Data
SwiftStealth Instance Data tab

6. Proxy Tester

Before you trust a batch of proxies, test them here. The Proxy Tester checks each proxy's speed, the country and IP it exits from, whether it can reach the destinations you care about, and optionally how risky its exit IP looks to fraud-detection services. Everything runs in parallel.

Proxy Tester
SwiftStealth Proxy Tester

6.1: Testing a batch

Paste your proxies into the Proxy Input box (same formats as the Proxy Manager). Optionally choose target destinations (Geo Check, Google, Cloudflare, or your own domain, IP or URL), adjust the Concurrent Threads slider (1 to 50, default 10), and switch on Auto-Delete Failed Proxies. Click Start Test; results stream in live. Use Copy Working or Export .txt when done.

6.2: Reading the results

Columns cover Proxy, Status, Speed, Country, IP and Targets (plus Risk when fraud scoring is on). Speed is colour-coded: green below 300 ms, yellow 300 to 799 ms, red at 800 ms and above. Summary pills tally working, partial, failed and pending.

6.3: Fraud scoring

Fraud scoring rates how suspicious each proxy's exit IP looks to fraud-detection services. Switch on Fraud Score (proxycheck.io) before starting; a Risk column appears and each proxy is placed in one of four brackets. Each lookup is sent through the proxy it's scoring, so your own IP is never used. Switch on Copy / Export: Low risk only to restrict both actions to proxies that scored Low.

Scores describe reputation, not certainty. A risk score reflects the reputation of the address and its network range, not your own traffic. A Low score is a good signal but not a guarantee, so treat it as one factor alongside speed and reachability.

7. Settings

The Settings tab is organized into five sections.

Settings
SwiftStealth Settings tab showing license, app, browser and API sections
  • License: your current plan and status, plan limits for Instances, Devices and API entitlement. Manage Subscription opens your account page; Deactivate This Mac releases the license so you can activate another computer.
  • SwiftStealth App: installed version and update status. SwiftStealth updates itself when a new release is available.
  • SwiftStealth Browser: whether the browser is installed and up to date, with Install / Update controls.
  • Automation API: on an API plan, shows "API Server Running" with the local address, your rate limit and your API key. Change the port and save (a restart applies it). The default port is 51820.
  • Diagnostics: the Rotation Event Log records every rotation for the session (capped at 200 entries, cleared on restart). Export CSV or clear the log.

8. The SwiftStealth Automation API

On API plans, SwiftStealth runs a local HTTP and WebSocket API so you can launch browser instances, rotate proxies, generate personas and stream live stats from your own scripts. The server is bound to localhost only and is never reachable from outside your Mac.

8.1: Base URL and authentication

The base URL is http://127.0.0.1:51820. Every endpoint except the health check needs your key as a Bearer token:

Authorization: Bearer <your_api_key>

Rate limits depend on your plan (for example, 60 requests per minute on API Starter). Reveal and copy your key from Settings → Automation API.

8.2: Quick start (Python)

import requests

BASE = "http://127.0.0.1:51820"
AUTH = {"Authorization": "Bearer your_api_key_here"}

# Check the server is up
print(requests.get(f"{BASE}/v1/health").json())

# Launch an instance
inst = requests.post(f"{BASE}/v1/instances", headers=AUTH, json={
    "proxyUrl": "socks5://user:pass@1.2.3.4:1080",
    "country":  "US",
}).json()
print("Launched:", inst["instanceId"])

# Read live stats
for g in requests.get(f"{BASE}/v1/stats", headers=AUTH).json():
    print(g["groupName"], g["bytesDownloaded"])

# Terminate it
requests.delete(f"{BASE}/v1/instances/{inst['instanceId']}", headers=AUTH)

8.3: Live event stream (WebSocket)

Connect to ws://127.0.0.1:51820/v1/events with your Bearer token to receive connected, stats, instance.launched and instance.terminated events as JSON. Stats arrive roughly once a second. It's a one-way push stream, so the server doesn't read what you send.

wscat -H 'Authorization: Bearer <key>' \
      -c ws://127.0.0.1:51820/v1/events

The same command, with your live key already filled in, can be copied from Settings → Automation API.

9. Troubleshooting & getting help

If something isn't working, the status pill is your first stop. Click it for the full System Status panel, which points straight to whichever component needs attention, whether that's the XPC service, the Network Engine, DNS Leak Protection or the kill-switch.

Still stuck? Note what the status pill says, then reach out to support@swiftstealth.net with that detail so we can point you to the right fix.
Contact Support