404PrivacyDocs

macOS installation

On macOS, run STATIC directly from its packaged operator bundle. The bundle includes the binary, a sample config, and the public profile catalog. It does not use Rose or the Linux eBPF packet path.

1. Choose the right download

Run uname -m in Terminal. Download the matching bundle from the latest release:

ResultDownload
arm64404-macos-aarch64.zip
x86_64404-macos-x64.zip

Save the zip to Downloads. The commands below assume it is extracted to $HOME/404-runtime.

2. Extract the bundle

For Apple Silicon:

ditto -x -k "$HOME/Downloads/404-macos-aarch64.zip" "$HOME"
chmod +x "$HOME/404-runtime/static_proxy"
ls "$HOME/404-runtime/config/static.example.toml" "$HOME/404-runtime/profiles/manifest.json"

On Intel, change the zip filename to 404-macos-x64.zip. Keep the binary, config, and profiles inside the same 404-runtime folder. The sample config resolves the profile path relative to that folder.

3. Select a profile and start STATIC

List the profiles first:

cd "$HOME/404-runtime"
./static_proxy --config ./config/static.example.toml --list-profiles

Start with the profile for your browser family:

./static_proxy --config ./config/static.example.toml --profile firefox-windows

Use chrome-windows for Chrome or edge-windows for Edge. Leave this Terminal session open. The bundle’s config listens at 127.0.0.1:4040; its control endpoint is at 127.0.0.1:4042.

4. Trust the local CA

In another Terminal window, ask STATIC for its CA status:

curl -s http://127.0.0.1:4042/ca/status

Find the static-ca.crt path reported by the response and replace the example path below. Only trust the certificate generated by your own running instance:

sudo security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain /path/to/static-ca.crt

Firefox may need that certificate imported into Settings → Privacy & Security → Certificates → View Certificates → Authorities. Keep the CA private key on your machine.

5. Route the browser and verify

Open a normal HTTPS page in that browser. If it fails, confirm STATIC is still running, the browser points to port 4040, and you trusted the CA reported by this instance. Disable the proxy settings when you stop STATIC.