A WireGuard VPN config file is really just a text document with about ten lines in it, yet those few lines control everything from which device you trust to which websites can see your real location. Most guides either hand you a finished file and say "just use this" or drown you in cryptography jargon. Neither approach helps when something stops working at 11pm and you need to know what each line actually does.
This article walks through a real WireGuard VPN config file, line by line, with a safe example you can study without plugging in anyone's real keys. You'll also learn why downloading a config file from a stranger online is one of the riskier things you can do to your own network.
Key Takeaways
- A WireGuard config file is a plain text file, usually ending in .conf, with an
[Interface]section and one or more[Peer]sections. PrivateKeyidentifies your device and should never be shared, copied into forums, or sent to anyone.AllowedIPsdecides which traffic goes through the VPN tunnel, and getting it wrong either breaks your connection or leaks data outside it.DNSsettings in the config stop DNS leaks, which can reveal which sites you visit even when the VPN itself is working.- A WireGuard VPN config generator (built into most server-side apps) can create client files automatically, so you rarely need to write one from scratch.
- Never use a .conf file shared by a stranger online, since it may route your traffic through their server and let them see everything.
- The file extension matters: WireGuard expects .conf, and most apps will refuse or misread anything else.
What a WireGuard Config File Actually Is
A WireGuard VPN config file is a short text file that tells the WireGuard app how to behave. It has two main jobs: describe your own device (the [Interface] section) and describe the server or peer you're connecting to (the [Peer] section).
You can open one in Notepad, TextEdit, or any plain text editor. There's no hidden binary data and no installer involved. That simplicity is part of why WireGuard has become popular for home labs and remote access setups, including the kind of self-hosting projects covered in our beginner's guide to self-hosting at home.
The File Extension
WireGuard VPN config files almost always use the .conf extension, for example client1.conf or home-vpn.conf. Some apps will accept a .zip containing a .conf file, or let you scan a QR code generated from one, but underneath it's still the same plain text format. If you rename a config file to .txt it will usually still work when re-imported, but stick with .conf to avoid confusion with your own backups.
A Safe WireGuard VPN Config Example
Here's a de-identified example you can study safely. None of these keys are real, and this file won't connect to anything:
``` [Interface] PrivateKey = YOUR_PRIVATE_KEY_HERE== Address = 10.0.0.2/32 DNS = 1.1.1.1, 1.0.0.1
[Peer] PublicKey = SERVER_PUBLIC_KEY_HERE== Endpoint = vpn.example.com:51820 AllowedIPs = 0.0.0.0/0, ::/0 PersistentKeepalive = 25 ```
This is a typical WireGuard VPN client configuration for connecting a laptop or phone to a home VPN server. Let's break down what each line does.
Breaking Down the Interface Section
PrivateKey
This is the secret half of your device's key pair. WireGuard uses public key cryptography, so your device has a private key (kept secret) and a matching public key (shared with the server). Never paste your PrivateKey into a forum post, a support ticket, or a screenshot. Treat it the way you'd treat a password.
Address
This is the IP address your device uses inside the VPN's private network, not your normal home or mobile IP. In the example, 10.0.0.2/32 means this device is "client number 2" on a small private network the server manages. Every device connecting to the same server needs a different address here, usually 10.0.0.3, 10.0.0.4, and so on.
DNS
This line tells your device which DNS server to use once the tunnel is up. We'll cover this properly in the next section, because getting it wrong is one of the most common WireGuard mistakes.
Getting DNS Right in a WireGuard Config
DNS is the system that turns a website name like example.com into an IP address. Even with a perfectly working VPN tunnel, if your device keeps using your regular internet provider's DNS server, that provider can still see every site you visit. This is called a DNS leak.
A correctly set up WireGuard VPN DNS config fixes this by pointing your device at a DNS server reachable through the tunnel, such as:
`` DNS = 1.1.1.1, 1.0.0.1 ``
or, if you're running your own DNS resolver on your home network:
`` DNS = 10.0.0.1 ``
If you leave the DNS line out entirely, most operating systems will fall back to whatever DNS server they were already using, which often defeats part of the point of running a VPN. If you're running a home lab with services like Pi-hole, pairing it with your VPN's DNS line keeps ad blocking working even while you're away from home, a setup worth considering alongside other projects in our self-hosting guide.
Understanding AllowedIPs
AllowedIPs is the line that confuses people most, and it does two jobs at once depending on which side of the connection you're looking at.
On the client side (your laptop or phone), AllowedIPs decides which traffic gets sent through the VPN tunnel at all. On the server side, the same setting (in the server's own config) decides which IP addresses it will accept traffic from for that particular peer.
Routing Everything Through the VPN
`` AllowedIPs = 0.0.0.0/0, ::/0 ``
This tells your device to send all traffic, every website, every app, through the tunnel. It's the setting you want if your goal is full privacy or if you're trying to appear as though you're browsing from home while out and about.
Routing Only Specific Traffic
`` AllowedIPs = 10.0.0.0/24 ``
This narrower setting only sends traffic meant for your home network's private range through the tunnel. Everything else, like normal web browsing, uses your regular internet connection directly. This is the setting most people want for a simple remote access VPN, where the goal is reaching home devices like a NAS, security cameras, or a self-hosted website or secure remote access rather than hiding general browsing.
Getting AllowedIPs wrong is the single most common cause of "my VPN connects but nothing works" problems. If it's too broad, you might lose internet access entirely. If it's too narrow, you won't be able to reach the home devices you wanted to access.
Breaking Down the Peer Section
PublicKey
This is the server's public key, the counterpart to its own private key, which stays on the server and is never shared. Unlike your PrivateKey, this one is safe to share, since it's designed to be public.
Endpoint
This is the address and port where your device will try to reach the server, written as address:port. It might be a domain name like vpn.example.com:51820 or a raw IP address like 203.0.113.5:51820. If you're hosting your own VPN server at home, this needs to point at your home connection's public IP or a dynamic DNS hostname, something that comes up a lot alongside projects in our guide to hosting a website from home.
PersistentKeepalive
`` PersistentKeepalive = 25 ``
This tells your device to send a small "still here" packet every 25 seconds, even when idle. It's mostly needed on mobile devices or anywhere behind strict firewalls or carrier-grade NAT, since without it the connection can silently drop and take a while to reconnect. Leaving it out entirely is fine on networks that don't aggressively close idle connections, but it rarely causes harm to include it. See our guide to setting up WireGuard on iPhone, Android and Mac for platform-specific configuration tips.
Using a WireGuard VPN Config Generator
You'll rarely need to write a full config file by hand. Most WireGuard server tools, including popular router firmware, NAS apps, and dedicated projects like wg-easy, include a WireGuard VPN config generator. You add a new client through the web interface, and it produces a finished .conf file (or a QR code) with the keys already filled in correctly.
This is genuinely the easier and safer path, since it avoids typos in long key strings and ensures the Address field doesn't clash with another device. If you're setting up remote access as part of a broader home lab, it pairs naturally with the kind of hardening steps in our home network security checklist.
Never Use a Stranger's Config File
Search around and you'll eventually stumble on WireGuard config files shared publicly, sometimes offered as "free VPN access." Please don't use these.
A WireGuard config file contains an Endpoint controlled by whoever created it, and depending on the AllowedIPs setting, it can route all your internet traffic through their server. That means they can potentially see every site you visit, every login page you load, and every file you download, in the same way an untrustworthy ISP could. There's no way to verify who's actually running the other end, and the whole point of a config file is that it hands over trust automatically.
If you want a VPN you didn't build yourself, use a reputable paid or well-reviewed provider with a published privacy policy, not a random .conf file found in a comment section or file-sharing site. If your goal is simply reaching your own home devices remotely, running your own WireGuard server (on a spare Raspberry Pi, router, or NAS) means the only "stranger" in the setup is nobody at all.
Troubleshooting a Config That Won't Connect
A few checks cover most problems:
- Confirm the
Endpointaddress and port match what the server is actually listening on, and that the port is open on your router. Our guide to diagnosing home network problems covers general connectivity checks that apply here too. - Check that
Addresson the client doesn't duplicate another device's address on the same server. - If the tunnel connects but nothing loads, revisit
AllowedIPsandDNSfirst, since these cause the vast majority of "connected but broken" situations. - Make sure the client's
PublicKeyhas actually been added to the server's peer list; WireGuard won't complain loudly if it's missing, it will just silently refuse the connection.
Conclusion
A WireGuard VPN config file looks intimidating at first glance, but it really only has a handful of settings worth understanding: your private key, your address, your DNS, and the all-important AllowedIPs line. Once you know what each one does, reading or editing a config file stops feeling like guesswork. As a next step, open any WireGuard config file you already have, whether from your router, a generator, or an app, and check each line against what you've just read here before trusting it with your traffic.
FAQ
What file extension does WireGuard use?
WireGuard config files use the .conf extension, such as client.conf. Some apps also support importing them via QR code or a zipped file, but the underlying format is always the same plain text.
Can I write a WireGuard config file by hand?
Yes, but it's rarely necessary. Most server tools include a built-in config generator that creates the file for you with correctly matched keys, which avoids typing errors in long key strings.
Why does my VPN connect but I have no internet?
This almost always comes down to AllowedIPs or DNS being set incorrectly. Check whether AllowedIPs is routing more or less traffic than intended, and confirm a working DNS server is listed.
Is it safe to share my WireGuard config file?
No, not if it contains your PrivateKey. Anyone with that file can connect to the server as if they were you, so treat it the same way you'd treat a password.
Why shouldn't I use a free config file found online?
Because whoever created it controls the Endpoint your traffic routes through, and with broad AllowedIPs settings they could potentially see everything you do online. There's no reliable way to verify who's actually running that server.
What does PersistentKeepalive actually do?
It sends a small packet at a set interval, often every 25 seconds, to keep the connection alive through firewalls and mobile networks. It's mainly useful on phones and restrictive networks, and does little harm elsewhere.
Do I need separate config files for each device?
Yes. Each device should have its own PrivateKey, its own Address on the VPN network, and ideally its own entry in the server's peer list, so you can see what's connected and revoke access individually if needed.