Skip to content
Ward

Download Ward 1.1.1

Pick your operating system

No licence key and no administrator. Every build below carries its size and its SHA-256, so you can check what you got before you run it.

  • Windows

    64-bit Intel or AMD

    Inno Setup installer (.exe)

    Ward-Setup-1.1.1.exe

    Download for Windows

    57.5 MB · released 21 August 2026

    SHA-256

    c0a5652ad28602a33717aa99fe9f7b845fa1f0386bb2169ce9f82a19d8e93c0b

  • macOS on Apple silicon

    M1, M2, M3, M4 and later

    Compressed archive (.tar.gz)

    Ward-1.1.1-macos-arm64.tar.gz

    Download for Apple silicon

    21.5 MB · released 29 August 2026

    SHA-256

    100c97e80d3eab0ae675942fabfc07e65e305308b847945e7475aff5b2d6fdd5

  • macOS on Intel

    Macs sold before late 2020

    Compressed archive (.tar.gz)

    Ward-1.1.1-macos-x64.tar.gz

    Download for Intel

    21.6 MB · released 29 August 2026

    SHA-256

    4e37785fd6b3b356644cabe9285bdfd268f9215728cc29c9f1adb4462fd49576

  • Debian, Ubuntu and Mint

    64-bit Intel or AMD

    Debian package (.deb)

    ward_1.1.1_amd64.deb

    Download the .deb

    21.4 MB · released 29 August 2026

    SHA-256

    9017916beebf1ff894d014cf9a7fc191be502ce2e014959a2cba52782895361c

  • Fedora, Arch and every other Linux

    64-bit Intel or AMD

    Compressed archive (.tar.gz)

    ward-1.1.1-linux-x86_64.tar.gz

    Download the .tar.gz

    21.4 MB · released 29 August 2026

    SHA-256

    f5968c4ee0049272ebf939965ced5bd0d8acf7cfec500d2a5b9013a2933f8a43

Free plan, free account, no cardNothing phones homeOr build it from sourceWhat is in 1.1.1

Platform by platform

Where each of the three actually stands

Ward is written and used on Windows. The other two run the whole test suite and have never had the program itself opened on them, which is a different thing from a passing build and worth reading before you spend an evening here.

Windows

Built, tested and used here

Ward is written, run and measured on Windows. Browser detection reads the registry, port ownership is resolved through netstat, and the install paths are Windows paths. This is the platform every note in the repository was written against, and the only one where the application itself has been launched, used and uninstalled.

Downloads
One file
Requires
Windows 10 or newer, 64-bit
  • 64-bit Intel or AMD ARM64 devices run it under emulation, which is untested.

Windows

Inno Setup installer (.exe)

Ward-Setup-1.1.1.exe

Installs for your Windows account only, into your own user folder, and asks for no administrator. It is not signed with a code-signing certificate, so Windows SmartScreen shows a blue “Windows protected your PC” panel on the first run: choose More info, then Run anyway. That is what an unsigned installer from a small publisher looks like, and the SHA-256 above is how you check it is the file this page describes.

How it was built. Built by jpackage and Inno Setup 6 on the machine Ward is developed on, then installed and uninstalled there.

Check it before you run it - the digest beside the button at the top of this page should come back identical. PowerShell prints it in uppercase; the comparison is case-insensitive, so either form is fine.

PowerShell, in the folder you downloaded to
Get-FileHash -Algorithm SHA256 .\Ward-Setup-1.1.1.exe

macOS

Suite passes, never launched here

The whole suite passes on macOS, and that is not the same as the program working. Nobody has opened Ward’s window on a Mac. The mechanisms most likely to be wrong there are the ones a unit test cannot reach: launching a browser you already have, adopting the process that ends up holding the DevTools port, working out who owns a local port. Both chips have a build now, so the question a Mac user faces is whether Ward works rather than whether there is a file.

Downloads
2 files, listed below
Requires
macOS 11 or newer, and Java 21. Not measured - that is the toolkit’s floor, not a tested one
  • Apple silicon M1 and later. Apple menu, then About This Mac, shows the chip.
  • Intel Macs sold before late 2020. There is a separate build for this chip.

macOS on Apple silicon

Compressed archive (.tar.gz)

Ward-1.1.1-macos-arm64.tar.gz

Unpack it in Terminal with tar, then drag Ward.app to Applications. Unpacking that way matters: files the tar command extracts carry no quarantine flag, so macOS opens Ward without a warning, while double-clicking the archive in Finder marks it and macOS then refuses the first launch, saying Ward is damaged. It is not damaged, it is unsigned - an Apple Developer ID is a paid certificate this project does not have. README.txt inside the archive has both routes and the one-line fix.

How it was built. Built from the same source as the Windows installer, on Windows, with the Apple-silicon JavaFX libraries. The packager reads the CPU type out of every native library in it and refuses to write the archive if one is for the other chip.

Check it before you run it - the digest beside the button at the top of this page should come back identical. The comparison is case-insensitive, so the case your shell prints does not matter.

A terminal, in the folder you downloaded to
shasum -a 256 ./Ward-1.1.1-macos-arm64.tar.gz

macOS on Intel

Compressed archive (.tar.gz)

Ward-1.1.1-macos-x64.tar.gz

The same archive as the Apple-silicon build, with the Intel libraries inside it. Unpack it in Terminal with tar, then drag Ward.app to Applications - and if you are not sure which Mac you have, the Apple menu, then About This Mac, names the chip. An Apple menu that says M1 or later wants the other file.

How it was built. Built from the same source, on Windows, with the Intel JavaFX libraries. The first attempt at this file was rejected by the packager’s own check for carrying Apple-silicon natives, which is what that check is for.

Check it before you run it - the digest beside the button at the top of this page should come back identical. The comparison is case-insensitive, so the case your shell prints does not matter.

A terminal, in the folder you downloaded to
shasum -a 256 ./Ward-1.1.1-macos-x64.tar.gz

Linux

Suite passes, never launched here

The suite passes on Linux and there are two packages to install, and what has still never happened is somebody installing one and opening the window. The Windows-only mechanisms are the reason to expect trouble: registry lookups for installed browsers, netstat for port ownership, Windows install paths. None of them has an implementation here yet, so a browser you already have will not be found - a profile pointed at an explicit binary path is the part most likely to work.

Downloads
2 files, listed below
Requires
GTK 3 and Java 21, on 64-bit Intel or AMD. Not measured - those are the toolkit’s requirements, not tested ones
  • 64-bit Intel or AMD The only architecture built. There is no ARM Linux package.

Debian, Ubuntu and Mint

Debian package (.deb)

ward_1.1.1_amd64.deb

Open it with your desktop’s software installer, or install it with your package manager. It depends on your distribution’s own Java 21 rather than bundling one, which is what a Debian package is supposed to do and means your Java gets security updates from your distribution. There is no .rpm; the archive beside this one covers Fedora and everything else.

How it was built. Assembled on Windows, without a Linux machine. A .deb is an ar archive holding three members and neither of them needs Linux to write - but running the result does, and that has not happened.

Check it before you run it - the digest beside the button at the top of this page should come back identical. The comparison is case-insensitive, so the case your shell prints does not matter.

A terminal, in the folder you downloaded to
shasum -a 256 ./ward_1.1.1_amd64.deb

Fedora, Arch and every other Linux

Compressed archive (.tar.gz)

ward-1.1.1-linux-x86_64.tar.gz

Unpack it and run ./install.sh. Everything goes under your home directory - the program, a launcher on your PATH, an applications-menu entry and an icon - so it never asks for a password and writes nothing outside $HOME. ./uninstall.sh removes exactly those four things and keeps your profiles. You need Java 21 and GTK 3 from your own distribution.

How it was built. Assembled on Windows. The install and uninstall scripts were run against a throwaway home directory and checked file by file; what could not be checked from here is the part that needs Linux, which is the program itself.

Check it before you run it - the digest beside the button at the top of this page should come back identical. The comparison is case-insensitive, so the case your shell prints does not matter.

A terminal, in the folder you downloaded to
shasum -a 256 ./ward-1.1.1-linux-x86_64.tar.gz

Test evidence

Where those badges come from

Every push builds and tests on all three operating systems. These are the numbers the most recent run reported. The repository is private, so this is the one part of the page you cannot check for yourself - which is worth knowing before you weigh it.

PlatformTests runFailingPackaging job
Windows2,1510Produced an installer
macOS2,1510Produced an installer
Linux2,1510Produced an installer
Windows
All 2 151 tests ran and passed, with nothing skipped - which matters, because the two live tests that start a real browser skip themselves when there is none, and a skip is not a pass. This runner has Chrome and Edge on it, so they ran.
macOS
All 2 151 tests ran on macOS, none failed, and five skipped themselves - the live tests that start a real browser, which the runner does not have installed. That run also produced a 1.0.0 disk image, which is not the file offered above: the archives on this page were built later, and by hand, because this workflow has not been able to run since August.
Linux
All 2 151 tests ran under a virtual display, none failed, and five skipped themselves for want of an installed browser. That run also produced a 1.0.0 Debian package, which is not the file offered above: the two Linux downloads on this page were built later, and by hand.

Read on 12 August 2026 from run 31619775529, on main - the first run on which every job finished green. These are test numbers and nothing else: the files above did not come out of this run, and each card in the section above says where its own file did come from. The repository is private, so there is no link here that would open for you. That makes these four numbers our word. The one number on this page that is not our word is the installer’s SHA-256, which the build writes and no person types - and it is the one you should actually check.

A green suite on three operating systems is not three working programs. All 2 151 tests pass on Windows, macOS and Linux, and that only means nothing in the suite reaches the parts that are Windows-only - finding a browser you already have, adopting the process that ends up holding the debugging port, reading the machine’s install layout. Those are most of the parts that touch the computer. Ward has never opened a browser profile on a Mac or on Linux, in this workflow or anywhere else. The four builds for those two systems are published so they can be tried at all, and the row above says which platform is which.

What is inside

What you are being asked to run

Ward launches browsers, holds proxy credentials and keeps a database of what you do with them. That is a lot of trust for one button to ask for, so here is the contents of the thing.

The application
One Java program and its JavaFX window. Roughly 2 000 unit tests cover it, and the numbers from the last run are in the table above.
A Java runtime
Bundled by jpackage and used only by Ward. Nothing is installed system-wide and no existing Java installation is touched or required.
Two libraries, and no more
JavaFX for the window and the SQLite driver for the database. JSON parsing, the QR encoder, TOTP and the extension reader are written in-repository rather than pulled in, because every dependency is a supply-chain surface on your machine.
No browser
Ward launches a browser you already have, or downloads a portable build against a pinned checksum when you ask it to. It does not ship one and it does not fork one.
No telemetry, and nothing uploaded
There is no analytics, no licence check and no phone-home. The window opens with the network unplugged.
Your data, on your disk
Profiles, folders, proxies and fingerprints live in a SQLite database in your user folder, and each browser profile is an ordinary directory beside it. Uninstalling leaves both where they are.

Before you run it

Windows will warn you, and it should

Ward is not code-signed. Windows treats every unsigned installer the same way, and you should treat this one with the same suspicion you would give any other.

Microsoft Defender SmartScreen: “Windows protected your PC”

This appears because the installer carries no code-signing certificate, not because anything was detected in it. A certificate that clears SmartScreen outright is an EV certificate, and reputation on a standard one is earned over months of downloads.

What to do

  1. 1Verify the checksum first. This is the step that actually protects you, and it is the one people skip. If the digest does not match the one above, stop.
  2. 2Right-click the downloaded file, choose Properties, and tick Unblock at the bottom of the General tab if it is there. That clears the mark-of-the-web your browser attached.
  3. 3Run the installer. If SmartScreen still appears, choose More info, confirm the publisher line reads Unknown publisher and the file name matches, then choose Run anyway.

Do not use these instructions on a file you got from anywhere but this page. “Click More info, then Run anyway” is exactly what a malicious installer wants you to have practised.

Already have 1.0.0

Uninstall it first, once

Only for people who installed 1.0.0. Every release after this one upgrades in place, and your profiles are untouched either way.

1.0.0 installed itself for the whole machine, and this one does not

1.0.0 went into C:\Program Files and asked for administrator rights. This build installs into your own user profile and asks for nothing, which is why there is no longer a second prompt after the SmartScreen one. Windows Installer cannot replace an all-users install with a per-user one, so it leaves the old one alone rather than removing it.

Remove Ward from Add or remove programs before installing this, or you will have two entries. Uninstalling 1.0.0 does not touch your profiles, proxies or device identities: those live in your own data folder and nothing in Ward deletes them.

System requirements

What the machine has to be

For the Windows build, which is the one these numbers were measured on. The macOS and Linux archives are a different shape - they carry no Java runtime and need one installed - and each says so on its own card above.

Operating system
Windows 10 or newer, 64-bitWindows 11 included. ARM64 runs under emulation and is untested. macOS and Linux have their own downloads and their own floors, which are the toolkit’s rather than measured ones.
Memory
8 GB, 16 GB recommendedEach running profile is a full browser process tree. Ten at once is a lot of RAM.
Disk
187 MB for Ward, plus room for profilesMeasured from a silent install of the Inno Setup build: 386 files and 186.9 MB of program files, most of it the bundled Java runtime. The published .msi carries the same application and has not been measured the same way.
Java
Not required on WindowsA Java runtime is bundled inside the Windows installer and nothing is installed system-wide. The macOS and Linux downloads are the exception: they need Java 21 or newer from Adoptium or from your own distribution, and each says so before you download it.
Administrator
Not neededThe download installs for your Windows account only, into %LOCALAPPDATA%\Programs\Ward, and adds a Start-menu entry and an Add/Remove Programs row with a working uninstaller. Uninstalling removes the program and leaves your profiles where they are; it asks before deleting them and the answer defaults to keeping them. This was measured by installing it. Ward 1.0.0 shipped an .msi that installed for the whole machine and did ask for an administrator; the .msi is still published beside this file for anyone pushing Ward to a fleet, and it is not what the button above downloads.
A browser
Camoufox, Ungoogled Chromium, Brave, Chromium, Chrome, Edge or FirefoxWard launches a browser you already have, or downloads a portable build of one against a pinned checksum. It does not ship one.
An account
Not requiredYour profiles never leave the machine. Signing in records a plan, not your work.

From source

Building it yourself

Java 21 and JavaFX, packaged by jpackage. The JavaFX profile for your operating system and CPU activates from the build itself, so there is no flag to remember.

The repository is private

These are the real commands and the clone will not work for you yet: Ward’s source is not public, so the first line asks for credentials that only the project has. They are here because they are what produces the file this page will one day hand over, and because a build path nobody can describe is a build path worth doubting - not because you can run them today.

Windows, with a JDK 21 and Inno Setup 6

This is the route that has actually been built, installed and uninstalled on the developer’s own machine: a setup .exe, with the “install for me only” option, no administrator anywhere. Pass -Type msi instead for the Group Policy build - that one needs WiX Toolset 3.14, does need an administrator, and has never been run.

Windows, from anywhere you keep source
git clone https://github.com/Destroyerg0d/ward.git
cd ward\services\native-host
.\mvnw.cmd -B clean package
powershell -ExecutionPolicy Bypass -File packaging\build-installer.ps1 -Type inno

macOS or Linux, as an experiment

The suite passes on both, and this builds the same shaded jar the four downloads above contain. Those four were not made by jpackage, which only ever emits the format of the machine it is running on: they were assembled by the scripts in packaging/, on Windows, because the build that would have produced them on their own operating systems has not been able to run since August. What has still never happened is somebody opening Ward’s window on either platform, so the Windows-only paths described above will be missing rather than merely untested.

macOS or Linux, from anywhere you keep source
git clone https://github.com/Destroyerg0d/ward.git
cd ward/services/native-host
chmod +x mvnw
./mvnw -B clean package