Skip to content Skip to sidebar Skip to footer

How to Set Up a VPN on a Chromebook in 2026

Disclosure: This post contains affiliate links; we may earn a commission at no extra cost to you.

Chromebooks aren’t Windows or Mac laptops wearing a different skin — ChromeOS handles VPNs differently, and which method works for you depends on whether your Chromebook supports Android apps and whether it’s a personal device or a school/work-managed one. There are three real paths, and picking the wrong one for your situation is the most common reason people give up and assume “VPNs don’t work on Chromebooks.”

Path 1: The Android app (easiest, for personal Chromebooks)

Most Chromebooks sold since around 2017 support Android apps through Google Play, which means a full VPN app — not a stripped-down version — runs the same way it would on an Android phone.

  1. Open the Google Play Store app from your shelf.
  2. Search for Surfshark, select “Surfshark VPN – Secure VPN for Privacy & Security,” and tap Install.
  3. Launch the app, log in with your Surfshark account, and either tap Connect for the fastest available server or open Locations to pick a specific country.
  4. Confirm it’s active from the status icon in your system tray.

This path gets you the full feature set — CleanWeb ad/tracker blocking, kill switch, Bypasser (split tunneling), unlimited simultaneous devices — because you’re running the real app, not a workaround.

The catch: if your Chromebook doesn’t support Android apps, or Play Store access has been disabled by a school or employer’s device policy, this option isn’t available at all. Check under Settings > Apps > Google Play Store — if there’s no toggle to turn it on, your device doesn’t support it, full stop.

Path 2: The Chrome browser extension (fast, but partial)

Surfshark’s Chrome extension installs like any other extension and encrypts traffic inside the Chrome browser window. It’s genuinely useful for a quick location switch while browsing, and it’s the only option that works on a Chromebook where Play Store is blocked but extension installs aren’t.

The honest limitation: it’s a browser proxy, not a system VPN. It does nothing for Android apps running outside Chrome, for ChromeOS system traffic, or for a Linux (Crostini) container if you have one enabled. Don’t rely on it if you need protection for anything other than what happens inside the Chrome window itself.

Path 3: The built-in native VPN client (managed devices, self-hosted, or advanced setups)

Every Chromebook has a built-in VPN client under Settings > Network > Add connection > Add built-in VPN, and as of ChromeOS’s current release this natively supports four protocols: IKEv2, L2TP/IPsec, OpenVPN, and WireGuard (WireGuard support is rolling out on select Chromebook models rather than universally). That’s actually a broader native protocol list than Windows 11 ships with — Windows’ built-in client skips WireGuard and OpenVPN entirely, while ChromeOS supports both.

This path exists mainly for corporate/self-hosted VPNs, but you can point it at a consumer provider too. To use it with Surfshark:

  1. Log into your account at surfshark.com in the browser (not the app).
  2. Go to VPN > Manual Setup, choose Desktop or mobile, then OpenVPN or WireGuard.
  3. For OpenVPN: open the Credentials tab and click Generate credentials — this creates a service-specific username/password, separate from your normal login. Then go to Locations, pick a server, and download its UDP or TCP config to get the exact hostname.
  4. For WireGuard: generate a key pair if you don’t have one, then download the configuration file for your chosen server location.
  5. Back on the Chromebook, fill in Add built-in VPN with the provider type (L2TP/IPsec, OpenVPN, or WireGuard), the server hostname from step 3/4, and the generated credentials.

Certificate note: if your setup calls for a client certificate rather than a password, Chromebooks only accept RSA client certificates for VPN authentication — ECC certificates aren’t supported, and you install them via chrome://settings/certificates. On a school- or work-managed Chromebook, your IT administrator usually needs to push the certificate and connection details directly; a personal manual setup won’t apply to a device under their policy.

Which path should you actually use?

Method Setup difficulty Protects Kill switch / extras Works if Play Store is blocked
Play Store app (Surfshark) Easy Whole device Yes — CleanWeb, kill switch, Bypasser No
Chrome extension Easiest Chrome browser only No Yes
Built-in client (manual OpenVPN/WireGuard) Moderate–advanced Whole device No Yes

For a personal Chromebook that supports Android apps, the Play Store app is simply the better choice — full protection, real kill switch, no manual config to get wrong. The built-in client is worth the extra setup only when Play Store genuinely isn’t an option, and the extension is a fallback for browser-only use, not a substitute for either.

Real problems people actually hit

“There’s no Play Store option in Settings at all.” That means your specific model doesn’t support Android apps (older or lower-end Chromebook hardware), or a device policy has hidden it — not that something’s broken. Check your model against Google’s official supported-devices list before troubleshooting further.

“The built-in VPN connects, then drops within seconds.” Almost always mismatched credentials — OpenVPN credentials generated for manual setup are not your Surfshark account email/password, and mixing them up is the single most common failure. Regenerate them from the Manual Setup > Credentials tab and re-enter carefully.

“I set it up but a leak-test site still shows my real location.” Run the test with the extension fully disabled — if you have both the extension and the Play Store app active at once, they can conflict, and traffic can leak outside whichever one didn’t grab the connection first.

“My school/work Chromebook won’t let me add any connection.” That’s an enterprise policy choice by design, not a workaround-able bug — the device is managed on purpose, and forcing a personal VPN onto it is worth reconsidering rather than fighting.

Editor’s pick: Surfshark is our recommended pick for this setup path. Our affiliate partnership with Surfshark is pending — check their official site directly for current plans and pricing.

FAQ

Do all Chromebooks support VPN apps?
Only Chromebooks with Android app support (Google Play access) can run a full VPN app like Surfshark’s. Every Chromebook has the built-in native client as a fallback, but it doesn’t include app-level features like a kill switch.

Is the Chrome extension enough on its own?
Only if all you need is browser-level protection. It doesn’t cover Android apps, ChromeOS system traffic, or a Linux container — for full-device coverage you need the Play Store app or the built-in client.

Does ChromeOS support WireGuard?
Yes, on select Chromebook models as part of the native built-in VPN client — alongside IKEv2, L2TP/IPsec, and OpenVPN. Availability depends on your specific device and ChromeOS version.

Can I use my Surfshark login directly in the built-in VPN client?
No — the built-in client needs OpenVPN or WireGuard credentials generated separately from the Manual Setup section of your Surfshark account, not your regular account email and password.