wg-easy

WireGuard VPN with a web admin interface

Security & Privacy MIT beginner ★ 27,038 stars

What is wg-easy?

wg-easy wraps WireGuard in a small web panel where you create clients, see who is connected and download configs or QR codes, instead of editing peer files by hand on the server. It brings the whole setup down to a single container, which is why it is often the first VPN people get running at home. Traffic itself is handled by WireGuard in the kernel, so performance is not sacrificed for the convenience.

Best for

Getting a private VPN into your home network running in a few minutes

Why choose wg-easy

wg-easy takes WireGuard, which is fast and excellent and configured entirely through text files, and puts a web interface in front of it. You create a client, get a QR code, scan it on your phone, and you are on your VPN. It shows connected peers and traffic in real time, revokes access with a click, and runs as a single container with no external database. For anyone who wants a private tunnel home without becoming a networking administrator, this is the practical shortcut.

Replaces

  • Tailscale
  • OpenVPN
  • NordVPN

Key features

  • Create and revoke WireGuard clients from a browser
  • QR code and file download for each client config
  • Live view of connected peers and traffic
  • One container with no external database

What to watch out for

Convenience always hides something, and here it is the networking underneath: you need to understand port forwarding, the difference between routing all traffic and only your home subnet, and how DNS behaves inside the tunnel — get those wrong and the VPN will connect and then not work in confusing ways. WireGuard itself is a protocol without a lot of built-in client management, so this container is a wrapper rather than a full-featured VPN server. Under NAT or with a dynamic IP, the whole thing needs extra pieces.

How to deploy

  • Docker

Getting started

Run it on a host with a static address or a dynamic DNS name, and forward the chosen UDP port on your router before creating clients. Decide upfront whether you need split tunnelling — only your home network — or a full tunnel for all traffic, because the client configuration differs and getting it wrong is the most common complaint. Set the interface's DNS deliberately and check what clients can resolve once connected. Keep the admin interface off the public internet; the web UI is convenient, and it is also the door to your network.

Typical setup

It runs on a machine with a public address or a dynamic DNS name, usually a small VPS or a home server with a port forwarded, and clients are phones and laptops that scan a QR code to join. Most people then configure split tunnelling so only home-network traffic goes through the tunnel, while a minority route everything for privacy on untrusted networks. The admin interface is almost always kept off the public internet.

Who should look elsewhere

Not the right tool if you need enterprise features: there is no directory integration, no certificate-based device posture, no central policy engine. It is also a mismatch for anyone without a publicly reachable host or willing to learn the underlying networking — port forwarding, DNS inside the tunnel and routing rules are not optional knowledge here, and the interface only hides them until something breaks.

Project health

  • GitHub stars: 27,038
  • Last code push: 2026-09-30
  • Open issues: 47
  • Status: actively developed

Figures pulled from the GitHub API and refreshed periodically.

wg-easy as an alternative

More in Security & Privacy