Install ocbar.
Make your first connection.
ocbar is an AnyConnect-compatible client for a VPN gateway you already have access to. It does not include a VPN subscription or servers. Ask your VPN administrator for the gateway address, group, networks and DNS settings.
Compatibility: minimum macOS 13. The author’s verified setup is macOS 26 on Apple Silicon with an AnyConnect gateway and Keycloak SSO. Older supported macOS versions and Intel Macs have not yet been verified. Your gateway’s sign-in and device policies may differ.
1. Prepare your Mac
You need Homebrew and Apple Command Line Tools. A full Xcode installation is not required. To request Command Line Tools, run:
xcode-select --install
Finish the Apple installation dialog before continuing. If the tools are already installed, macOS will tell you. Use an administrator account for the system-helper installation.
2. Install with Homebrew
The application and its Homebrew tap are public. You do not need a GitHub account, an SSH key or gh auth. Review the tap before trusting it.
brew tap ValeraGin/ocbar
brew trust ValeraGin/ocbar
brew install ocbar
Homebrew builds the application on your Mac. This is a source build, not a signed and notarized installer; build time depends on your machine and installed dependencies.
3. Set up the helper and open the app
sudo ocbar install
ocbar app start
The first command asks for your Mac administrator password in Terminal. Tunnel mode installs a root-owned helper and copy of OpenConnect, a reconnect LaunchAgent, and /etc/sudoers.d/ocbar. The rule lets members of the admin group run the helper without a password on subsequent connections. It does not grant passwordless access to every command. The menu bar app runs as your normal user. Read the security model and its limitations.
To inspect the planned installation steps without applying them, run ocbar install --dry-run as your normal user.
4. Add a profile and sign in
- Find ocbar in the Mac menu bar and use the setup wizard to add a profile.
- Enter the gateway and authentication group supplied by your administrator.
- Add the networks and DNS zones you need through the VPN. They are your explicit selection; do not guess them from an example.
- Connect and complete your organization’s sign-in. Saving a password or configuring TOTP is optional.
- Check a work resource and an ordinary public website. You can change selected networks or pause the connection from the menu.
If the connection fails
ocbar doctor
ocbar status
The app also has a diagnostics and logs window. Start with any failed checks; confirm your gateway, group and authentication requirements with your administrator. Detailed troubleshooting (Russian) covers common failures. Before opening a public issue, remove gateway details, account names, cookies and tokens from any logs you share.
Update
brew upgrade ocbar
ocbar app stop
ocbar app start
ocbar doctor
If the release notes or diagnostics report an outdated helper, run sudo ocbar install again. Updates are not installed automatically.
Share a configured profile with a teammate
One .ocbar file brings together the gateway, networks, DNS zones and SSO form rules. New teammates can start with settings you have already checked.
ocbar export main team.ocbar
Here, main is the name of your configured profile. Before sharing, open the file: replace your personal User value, review KeePassXC and CSD wrapper paths, and check any custom commands. Export does not retrieve passwords or TOTP secrets from your credential store; you must review the contents of your own commands and rules. Share work settings within your team.
Your teammate installs ocbar, imports the file and configures their own account and credential sources:
ocbar import team.ocbar
They then sign in as themselves. A CSD script referenced by the profile must be shared and set up separately: export includes its path, not the script file.
Remove the app and system helper
Keep this order: ocbar must still be installed to remove its system components.
sudo ocbar uninstall
brew uninstall ocbar
The first command disconnects ocbar, removes its routes and DNS settings, stops its agents, and removes the helper and its sudoers rule. The second removes the Homebrew package.
Profiles, local logs and state, saved WebKit sign-in data and Keychain credentials remain. These commands are not a full personal-data wipe. Review the full cleanup instructions (Russian) before deleting remaining data. KeePassXC entries are managed separately.