Manual setup and what is in the file
For anything else that speaks WireGuard, and for people who want to know what they are running.
Sign in to download your configuration file, or see plans.
Your configuration file is plain text and works with any WireGuard client on any platform. If your device is not covered by the other guides and it speaks WireGuard, this is all you need.
What the file contains
``` [Interface] PrivateKey = <your private key> Address = <the address you are given inside the tunnel> DNS = <our resolver>
[Peer] PublicKey = <the server's public key> AllowedIPs = 0.0.0.0/0, ::/0 Endpoint = <server address>:<port> PersistentKeepalive = 25 ```
Line by line:
PrivateKey — yours, and the reason this file is a credential. Anyone holding it can use your account.
Address — the address your device has inside the tunnel. Not your public address.
DNS — our resolver. It matters: a tunnel that carries your traffic but leaves DNS with your internet provider still hands them the list of every site you visit. See what DNS is.
AllowedIPs = 0.0.0.0/0, ::/0 — send everything through the tunnel. Narrow this if you want split tunnelling, and know that anything you exclude travels in the open.
Endpoint — the server you chose. To change country, download a fresh configuration rather than editing this by hand.
PersistentKeepalive = 25 — a small packet every 25 seconds so routers and mobile networks do not quietly drop the connection.
Using it anywhere
Every WireGuard client takes the same file. Official clients exist for Windows, macOS, Linux, iOS, Android, FreeBSD and OpenBSD, and most router firmware will import it.
If a client asks for the fields individually rather than a file, open the config in any text editor and copy them across.
Keeping it safe
- Treat it like a password. Delete it from your Downloads folder once imported; the client keeps
its own copy.
- Do not email it to yourself if you can avoid it, and delete the message if you did.
- One config per device is tidier — if you lose a device you can retire just that one.
- If you think it has been exposed, generate a new configuration and reset your VPN password from
your account. The old key stops working.
Changing country
Download a new configuration from your account with a different location. Import it as a second tunnel and switch between them — most clients handle several, with only one active at a time.
Checking it works
Open veystrix.net/tools/ip. It tells you the address the internet currently sees and whether it belongs to our network.
If it reports your own address while the client says connected, the tunnel is up but traffic is not being routed through it — usually AllowedIPs has been narrowed, or another VPN is active.