A lightweight native macOS menu bar utility for managing Cloudflare WARP domain exclusions.
WARP Excluder is an independent project and is not affiliated with or endorsed by Cloudflare, Inc.
![]() |
![]() |
| Menu bar popover and options | Popup size and language settings |
- Add and remove Cloudflare WARP domain exclusions.
- Automatically convert zone names such as
by,ru, orprointo wildcard rules such as*.by,*.ru, or*.pro. - Search the current exclusion list.
- Restart WARP manually from the menu bar.
- Run built-in
warp-clidiagnostics. - Choose between compact, standard, and large popup sizes.
- Switch between English and Russian.
- Persist application preferences between launches.
- Use a compact native macOS interface without a permanent Dock icon.
- macOS 14 or later.
- Cloudflare WARP installed on the Mac.
- The WARP CLI available at:
/usr/local/bin/warp-cli
Verify the path with:
which warp-cli- Open the repository's Releases page.
- Download the latest
WARP-Excluder.dmg. - Open the disk image.
- Drag WARP Excluder.app into Applications.
- Launch the application. Its shield icon will appear in the macOS menu bar.
If Gatekeeper blocks an unsigned test build, Control-click the application, select Open, and confirm the prompt. Public releases should be signed with a Developer ID certificate and notarized by Apple.
Enter a complete domain name:
onliner.by
Enter a short zone name:
by
WARP Excluder automatically converts it to:
*.by
The equivalent WARP CLI command is:
warp-cli tunnel host add '*.by'Domain-based WARP exclusions depend on DNS resolution. The macOS DNS cache, browser Secure DNS, or DNS over HTTPS may affect when a rule takes effect.
- Clone the repository:
git clone https://github.com/YOUR_USERNAME/warp-excluder-macos.git
cd warp-excluder-macos- Open the Xcode project:
open WarpExcluder.xcodeproj- Select the WarpExcluder target.
- Configure code signing for your Apple Developer team or use local signing.
- Build and run the project on My Mac.
To create a release build, use:
Product → Archive → Distribute App
WARP Excluder launches the installed warp-cli executable directly through Process and uses the following commands:
warp-cli tunnel host list
warp-cli tunnel host add <host>
warp-cli tunnel host remove <host>
warp-cli disconnect
warp-cli connectCommands run as the current user. The application does not request an administrator password and does not modify system files.
warp-excluder-macos/
├── .github/workflows/build.yml
├── docs/images/
│ ├── main-window.png
│ └── settings-window.png
├── CHANGELOG.md
├── LICENSE
├── README.md
├── RELEASE_CHECKLIST.md
├── WarpExcluder.xcodeproj/
└── WarpExcluder/
├── AppSettings.swift
├── AboutWindow.swift
├── SettingsWindow.swift
├── ContentView.swift
├── WarpExcluderApp.swift
└── Assets.xcassets/
- Cloudflare WARP must be installed separately.
- The expected CLI path is
/usr/local/bin/warp-cli. - Wildcard rules are intended for the desktop WARP client on macOS.
- The application manages host exclusions created through the CLI.
- DNS caching and Secure DNS settings may affect domain-based exclusions.
Attach release binaries to a GitHub Release instead of committing them to the repository. A release should normally include:
WARP-Excluder.dmg
WARP-Excluder.dmg.sha256
Generate a SHA-256 checksum with:
shasum -a 256 WARP-Excluder.dmg > WARP-Excluder.dmg.sha256Denis Vasilyevich
Distributed under the MIT License.
Cloudflare and WARP are trademarks of Cloudflare, Inc. This project is an independent utility and is not maintained or supported by Cloudflare.

