How to set up Surfshark to protect your SparkBox downloads
SparkBox builds a VPN right into its media stack, so your download apps stay private behind a kill-switch. You don't install a VPN separately — you just give the media stack your Surfshark details once. This takes about five minutes, and there's no terminal involved.
1. Why the media stack uses a VPN
The download apps in SparkBox's media stack (Sonarr, Radarr, Prowlarr, qBittorrent) run all of their traffic through a VPN tunnel. The point is privacy: your home internet connection isn't doing the talking, and there's a kill-switch — if the VPN ever drops, those apps simply can't connect, so nothing leaks back onto your normal connection.
A few things worth knowing up front:
- The VPN is part of the media stack, not a separate app you turn on. There's nothing to install — you just enter your VPN details in the media settings.
- It only matters for the download apps. The rest of SparkBox — Jellyfin streaming, your photos, files, password manager — doesn't use it and doesn't need it.
- You bring your own VPN subscription. We recommend Surfshark because it works with SparkBox's setup out of the box and the wizard is pre-filled for it.
2. Get Surfshark
If you don't already have it, grab Surfshark here:
Get Surfshark — 87% off + 4 months free →
Affiliate link — it supports SparkBox at no extra cost to you. Any VPN that supports WireGuard works; Surfshark is just the one we build and test against.
3. Get your WireGuard details from Surfshark
Surfshark connects to SparkBox using WireGuard. You need two things from your Surfshark account: a private key and an address. Here's how to get them:
- Sign in at my.surfshark.com.
- Go to VPN → Manual setup → WireGuard. (Surfshark occasionally moves things around — look for "Manual setup" and choose WireGuard.)
- Pick a server location near you and let it generate a configuration. Surfshark will show you a private key and an address (it may be labelled "Address" or "Allowed IPs").
- Keep that page open — you'll copy those two values in the next step.
Your private key is a secret — treat it like a password. SparkBox stores it on your own server and never sends it anywhere.
4. Put them into SparkBox
In your SparkBox dashboard, open Apps → Media (or the VPN settings on the media tile) and enter:
- VPN Provider: Surfshark (it's the default).
- WireGuard Private Key: paste the private key from Surfshark.
- Address: paste the address Surfshark gave you — this is the internal IP that starts with
10.(usually10.14.0.2/16for Surfshark), labelled "Address" or "Allowed IPs" in your WireGuard config. It is NOT the "Endpoint" / public server IP — that's a different value on the same page, and pasting it here is the single most common reason the VPN connects but then times out. Copy yours exactly, including the/16on the end. - OpenVPN username / password: leave these blank. WireGuard doesn't use them.
Save. SparkBox restarts the media stack with the VPN in front of it. This takes a minute or two.
If the dashboard warns that your key doesn't look right, double-check you copied the private key (a 44-character value ending in =) — not the public key, the server address, or a whole config file.
5. Check it's protecting you
Back on the dashboard home screen, the VPN status shows as connected once the tunnel is up — SparkBox even confirms your download apps are using a different IP than your home connection, so you can see the protection is real, not just a label.
If it stays disconnected, open Apps → Media and re-check the private key and address. The most common slip is pasting the public key or the wrong address line. Surfshark's WireGuard page has both values side by side, so it's easy to grab the wrong one.
Next steps
That's your downloads behind a VPN, the easy way.
Now your media stack runs privately, with a kill-switch so it can't leak. If something doesn't match what you see, post in d/sparkbox or hit us up on YouTube. Every SparkBox bug gets patched; every UX-stumble in this guide gets rewritten.