SparkBox / Guides / Surfshark VPN setup

How to set up Surfshark to protect your SparkBox downloads

SparkBox builds a VPN right into its media stack, so your download apps stay private behind a kill-switch. You don't install a VPN separately — you just give the media stack your Surfshark details once. This takes about five minutes, and there's no terminal involved.

SparkBox Settings page
SparkBox Settings page

1. Why the media stack uses a VPN

The download apps in SparkBox's media stack (Sonarr, Radarr, Prowlarr, qBittorrent) run all of their traffic through a VPN tunnel. The point is privacy: your home internet connection isn't doing the talking, and there's a kill-switch — if the VPN ever drops, those apps simply can't connect, so nothing leaks back onto your normal connection.

qBittorrent web UI behind the SparkBox VPN
qBittorrent web UI behind the SparkBox VPN

A few things worth knowing up front:

  • The VPN is part of the media stack, not a separate app you turn on. There's nothing to install — you just enter your VPN details in the media settings.
  • It only matters for the download apps. The rest of SparkBox — Jellyfin streaming, your photos, files, password manager — doesn't use it and doesn't need it.
  • You bring your own VPN subscription. We recommend Surfshark because it works with SparkBox's setup out of the box and the wizard is pre-filled for it.

2. Get Surfshark

If you don't already have it, grab Surfshark here:

Get Surfshark — 87% off + 4 months free →

Affiliate link — it supports SparkBox at no extra cost to you. Any VPN that supports WireGuard works; Surfshark is just the one we build and test against.

3. Get your WireGuard details from Surfshark

Surfshark connects to SparkBox using WireGuard. You need two things from your Surfshark account: a private key and an address. Here's how to get them:

  1. Sign in at my.surfshark.com.
  2. Go to VPN → Manual setup → WireGuard. (Surfshark occasionally moves things around — look for "Manual setup" and choose WireGuard.)
  3. Pick a server location near you and let it generate a configuration. Surfshark will show you a private key and an address (it may be labelled "Address" or "Allowed IPs").
  4. Keep that page open — you'll copy those two values in the next step.

Your private key is a secret — treat it like a password. SparkBox stores it on your own server and never sends it anywhere.

4. Put them into SparkBox

In your SparkBox dashboard, open Apps → Media (or the VPN settings on the media tile) and enter:

  • VPN Provider: Surfshark (it's the default).
  • WireGuard Private Key: paste the private key from Surfshark.
  • Address: paste the address Surfshark gave you — this is the internal IP that starts with 10. (usually 10.14.0.2/16 for Surfshark), labelled "Address" or "Allowed IPs" in your WireGuard config. It is NOT the "Endpoint" / public server IP — that's a different value on the same page, and pasting it here is the single most common reason the VPN connects but then times out. Copy yours exactly, including the /16 on the end.
  • OpenVPN username / password: leave these blank. WireGuard doesn't use them.

Save. SparkBox restarts the media stack with the VPN in front of it. This takes a minute or two.

If the dashboard warns that your key doesn't look right, double-check you copied the private key (a 44-character value ending in =) — not the public key, the server address, or a whole config file.

5. Check it's protecting you

Back on the dashboard home screen, the VPN status shows as connected once the tunnel is up — SparkBox even confirms your download apps are using a different IP than your home connection, so you can see the protection is real, not just a label.

If it stays disconnected, open Apps → Media and re-check the private key and address. The most common slip is pasting the public key or the wrong address line. Surfshark's WireGuard page has both values side by side, so it's easy to grab the wrong one.

Next steps

That's your downloads behind a VPN, the easy way.

Now your media stack runs privately, with a kill-switch so it can't leak. If something doesn't match what you see, post in d/sparkbox or hit us up on YouTube. Every SparkBox bug gets patched; every UX-stumble in this guide gets rewritten.

Get SparkBox → More guides →

Questions, or did this not match your box?

Every guide here came from a real problem someone hit. If yours behaves differently, say so — that is how these get corrected, and how the fix gets prioritised.

Ask in the community →

We answer there rather than in a comment box, because that is where the people who have already solved it are.

About this guide: Written against a live SparkBox install and Surfshark's WireGuard manual-setup flow. Provider sites change their layouts from time to time — if a step doesn't match what you see, tell us in d/sparkbox and we'll update it.