The official Windows client for the WireGuard protocol
WireGuard is a modern VPN protocol built on the Noise framework, using a small fixed set of well-reviewed primitives: Curve25519 for key exchange, ChaCha20-Poly1305 for authenticated encryption, BLAKE2s for hashing and SipHash for hashtable keys.
What the Windows client is
The Windows program is the project's own client. It is not a VPN service and it does not sell subscriptions; it is the software that speaks the protocol, so a configuration file from a server you run or a provider you pay for is what makes it useful. The client is free, released under the MIT licence, and maintained by the same developers as the protocol and the other platform clients.
Importing a tunnel and getting connected
A tunnel is described by a small text configuration: an interface section with the private key, the addresses assigned to this machine and optionally a DNS server, plus one or more peer sections with the peer's public key, its endpoint and the address ranges routed through it. In the Windows client, that file can be imported from disk or pasted in as text, and the resulting tunnel is listed by name. Selecting it and pressing Activate brings the tunnel up; the window then shows the peer, the latest handshake, and byte counters in both directions, which is the quickest way to tell whether traffic is actually flowing. Tunnels can be set to start automatically at login, and several can exist side by side as long as only one is active at a time.
Settings, expectations and limits
The security of a tunnel depends entirely on the configuration that was handed to you. A peer with AllowedIPs set to 0.0.0.0/0 routes everything through the tunnel, which is what most people want; a narrower range produces a split tunnel that sends only some traffic through it. The client also offers an option to block untunneled traffic, which stops packets from escaping outside the tunnel when the full address range is routed, at the cost of losing connectivity if the tunnel is down. Keys are generated in the client and should be treated like passwords, because anyone holding the private key can impersonate the connection. Configuration files are plain text and often end up in shared folders or chat messages, so they are worth protecting. The client does not provide a server, does not include an account system, and does not hide the fact that you are using a VPN from a network that blocks the protocol by port or fingerprint.
Choosing between this and a commercial VPN app
If you want an app to install and a subscription to buy, a commercial provider's client bundles the server list, the account, the kill switch and the reconnect logic in one place, and that convenience is part of what you pay for. WireGuard is the better fit when you already have a server with a WireGuard interface, when you run your own endpoint on a VPS or home router, or when a provider publishes raw WireGuard configurations and you prefer a small, auditable client over a heavier one. It is also the pragmatic choice for site-to-site links and for keeping a laptop connected to a home network, where the tunnel is a tool rather than a product.
- Best for
- Users who already have WireGuard configurations from their own server or a provider, and want a small, free, official client that imports them and shows live handshake and transfer status.
- Good to know
- WireGuard is a client, not a VPN service: without a server and a configuration file it has nothing to connect to. Treat private keys and configuration files as secrets, since the configuration alone is enough to use the tunnel.
WireGuard is the official Windows client for the WireGuard VPN protocol, not a subscription service.
How to get started
- Install the MSI, or use the bundle installer if you prefer the guided setup.
- Get a tunnel configuration from your server or provider: a text file with an interface section and at least one peer.
- Import the file, or paste its contents, and give the tunnel a name you will recognise.
- Select the tunnel and press Activate, then check that a handshake appears and the transfer counters move.
- Turn on automatic start at login if this machine should always be connected.
- Enable the block-untunneled-traffic option only when the whole address range is routed and you can afford to lose connectivity if the tunnel drops.
Questions & answers
Does WireGuard include a VPN service?
No. It is the client software. You need a server you run yourself or a provider that supplies a configuration file.
What is in the configuration file?
A private key, the addresses for this machine, an optional DNS server, and the peer's public key, endpoint and allowed address ranges. Keep it private.
Can I run more than one tunnel?
Yes, several configurations can be imported and switched between, but only one is active at a time.