The macOS WARP client is finally GA!
Hey everyone, it's Shiichan! Today I want to share an update to the app that keeps your work Macs safe.
Cloudflare ChangelogWhat was announced?
From the Cloudflare Changelog: the macOS Cloudflare One Client (the WARP client), version 2026.6.822.0, has reached GA. You can grab it from the downloads page now.
The story so far
This client is the app that connects your company Macs to Cloudflare's Zero Trust network. It gets updated regularly, but this one is a milestone GA release that rolls up a big batch of new features and bug fixes.
What changes
Security and manageability both take a nice step up. IT admins in particular get safer device registration and new ways to push settings. Even for everyday users, small wins like fixing the broken captive-portal screen on airline Wi-Fi make this a handy update.
Dive Deep
Here are the main changes I could pull from the post.
- Hardware-backed device registration using the Secure Enclave keeps registration keys better protected.
- DNS search suffixes from device profiles and network policies now apply to single-label queries.
- The local DNS proxy now supports DNSSEC passthrough.
- New
warp-clidebug commands make it easier to diagnose connections and grab extra debug logging. - A new MDM format for org-wide settings, plus client version assignments managed from the dashboard.
- All API requests are unified under the api.devices.cloudflare.com SNI, and Path MTU Discovery is now on by default.
- The captive-portal rendering bug on airline Wi-Fi is fixed.
There is one known issue: registration can hang at "Checking your organization configuration". A reboot resolves it.
Wrap-up
- macOS Cloudflare One Client 2026.6.822.0 is now GA
- Stronger security with Secure Enclave hardware-backed registration and DNSSEC passthrough
- Easier management via a new MDM format and dashboard-driven deployments
- Lots of smaller fixes, including the airline Wi-Fi rendering bug
If you manage Macs with Zero Trust, this is the update to check first!