Overview

Live WireGuard state for wg0

Add a client

A key pair is generated on the server and the peer is applied live.

The address is fixed once the client is created.
25 keeps NAT mappings open. Use 0 to disable.
Use 0.0.0.0/0 to send all of the device's traffic through the VPN.
Leave blank for permanent access. Expired clients are revoked automatically.

Client configuration

Hand this to the device now. The private key is not stored and cannot be shown again.

QR code containing the tunnel configuration

Scan from the WireGuard app on a phone.

Client

Add a person

They sign in with these details and choose a new password immediately.

Change your password

Pick something you have not used on this server before.

Confirm

Import clients from CSV

Each row becomes a new client with its own freshly generated keys.

Choose a CSV file, or drop one here Name is the only required column
Accepted columns: Name (required), VPN IP, Device, Tag, SSH user, SSH port, DNS, Allowed IPs, Keepalive, Expires, Notes. Blank addresses are allocated automatically. An exported client CSV can be fed straight back in.

Import a portal export

Restores clients, accounts and settings from another server.

Choose the export file, or drop it here A .json file produced by Download portal export