Self-hosted WireGuard VPN management,
without the operational overhead
A web-based admin panel for WireGuard with zero-touch provisioning and OIDC/SSO integration — no manual configs, no support tickets, no SSH sessions to add users.
Zero-Touch Provisioning
Users authenticate once through your existing identity provider and get a working VPN config automatically — keys, IP address, and access policy included. No tickets, no manual files.
OIDC & SSO Identity Integration
Works with Google, Azure AD, Okta, Keycloak, Authentik, LinkedIn, and any OIDC-compliant provider. Group membership drives access policy automatically.
Dynamic Firewall Rules
Group-based access policies are compiled into nftables rules and enforced at the network layer, kept in sync automatically as peers and groups change.
Built on WireGuard's Speed
Wiretastix manages the control plane while your traffic flows through WireGuard's lightweight kernel implementation at full line speed — sub-millisecond handshakes, minimal overhead.
Integrated DNS Resolver
Every peer gets a resolvable name with automatic PTR records, so services can find each other by hostname without extra configuration.
API, CLI & Metrics
A full REST API and CLI for automation, plus Prometheus metrics out of the box — scales from ten users to ten thousand without added complexity.
Ready to get started?
Install Wiretastix from a Debian package, Docker Compose, Kubernetes, or from source.
Installation Guide