Free Tool

WireGuard config generator

Create a key pair and a client config in a minute. Paste your server's public key and endpoint, pick an AllowedIPs mode, and get wg0.conf, a QR code for the app, and a [Peer] snippet for the server. Keys are generated in the browser and never sent anywhere.

Client config (wg0.conf)


        

QR code for the WireGuard app

Server-side snippet


      

How to use it

Press Generate, paste the server's public key and endpoint, enter the client address the server assigned (for example 10.0.0.2/32). Download wg0.conf or scan the QR code with the WireGuard app. Add the [Peer] snippet on the server. What every line means is in how to set up WireGuard.

Key privacy

Keys are created by the TweetNaCl library inside your browser and are not sent to any server. The client's private key must stay with you; the server only needs the public one.

If WireGuard does not get through

Check whether the network blocks UDP with the UDP block test. If it does, you need a TCP protocol such as VLESS.

Rather not run a server?

404 VPN hands you ready-made VLESS keys for any device, with DNS inside the tunnel and a Kill Switch.

How to connect 404 VPN →

Frequently asked questions

guest@404vpn:~$ cat wireguard-config-generator-faq.md
[01] $ How is PresharedKey different from the key pair? ▸
> It is an extra symmetric secret on top of the key exchange, adding protection against future attacks on the cryptography. The same key goes on both the client and the server.
[02] $ Which MTU should I use? ▸
> The default is 1420. If pages through the tunnel start loading and then stall, set 1280 and raise it in steps.
[03] $ Are the keys compatible with the official apps? ▸
> Yes: they are standard X25519 keys in base64, the same as wg genkey produces.