SparkBox / Guides / Surfshark VPN setup

How to set up Surfshark to protect your SparkBox downloads

SparkBox builds a VPN right into its media stack, so your download apps stay private behind a kill-switch. You don't install a VPN separately — you just give the media stack your Surfshark details once. This takes about five minutes, and there's no terminal involved.

SparkBox Settings page
SparkBox Settings page

1. Why the media stack uses a VPN

The download apps in SparkBox's media stack (Sonarr, Radarr, Prowlarr, qBittorrent) run all of their traffic through a VPN tunnel. The point is privacy: your home internet connection isn't doing the talking, and there's a kill-switch — if the VPN ever drops, those apps simply can't connect, so nothing leaks back onto your normal connection.

qBittorrent web UI behind the SparkBox VPN
qBittorrent web UI behind the SparkBox VPN

A few things worth knowing up front:

2. Get Surfshark

If you don't already have it, grab Surfshark here:

Get Surfshark — 87% off + 4 months free →

Affiliate link — it supports SparkBox at no extra cost to you. Any VPN that supports WireGuard works; Surfshark is just the one we build and test against.

3. Get your WireGuard details from Surfshark

Surfshark connects to SparkBox using WireGuard. You need two things from your Surfshark account: a private key and an address. Here's how to get them:

  1. Sign in at my.surfshark.com.
  2. Go to VPN → Manual setup → WireGuard. (Surfshark occasionally moves things around — look for "Manual setup" and choose WireGuard.)
  3. Pick a server location near you and let it generate a configuration. Surfshark will show you a private key and an address (it may be labelled "Address" or "Allowed IPs").
  4. Keep that page open — you'll copy those two values in the next step.

Your private key is a secret — treat it like a password. SparkBox stores it on your own server and never sends it anywhere.

4. Put them into SparkBox

In your SparkBox dashboard, open Apps → Media (or the VPN settings on the media tile) and enter:

Save. SparkBox restarts the media stack with the VPN in front of it. This takes a minute or two.

If the dashboard warns that your key doesn't look right, double-check you copied the private key (a 44-character value ending in =) — not the public key, the server address, or a whole config file.

5. Check it's protecting you

Back on the dashboard home screen, the VPN status shows as connected once the tunnel is up — SparkBox even confirms your download apps are using a different IP than your home connection, so you can see the protection is real, not just a label.

If it stays disconnected, open Apps → Media and re-check the private key and address. The most common slip is pasting the public key or the wrong address line. Surfshark's WireGuard page has both values side by side, so it's easy to grab the wrong one.

Next steps

That's your downloads behind a VPN, the easy way.

Now your media stack runs privately, with a kill-switch so it can't leak. If something doesn't match what you see, post in d/sparkbox or hit us up on YouTube. Every SparkBox bug gets patched; every UX-stumble in this guide gets rewritten.

Get SparkBox → More guides →

About this guide: Written against a live SparkBox install and Surfshark's WireGuard manual-setup flow. Provider sites change their layouts from time to time — if a step doesn't match what you see, tell us in d/sparkbox and we'll update it.