← Back to Articles
January 5, 2026

Persistent, Zero-Config Tunnels with WireGuard

Since day one, Serveo has been about repurposing the battle-tested tools you already have. We started with SSH because it is ubiquitous. By using remote port forwarding, we let you expose local services without installing a single proprietary binary.

Why WireGuard?

We love SSH, but it has a weakness: it is a stateful TCP connection. If you close your laptop lid, change Wi-Fi networks, or hit a spotty LTE patch, the pipe breaks.

WireGuard changes the game. It is a modern, high-performance, stateless protocol.

  • It Roams: Switch from coffee shop Wi-Fi to a mobile hotspot instantly. Your tunnel URL stays live.
  • It's Fast: Running in the kernel, it handles high-throughput streams that choke user-space SSH clients.
  • It's Standard: Just like our SSH support, you do not need a Serveo client. Use the standard WireGuard tools you already trust.

Ergonomics First

Setting up a VPN usually involves complex key management and config files. We automated that. You can generate a complete, ephemeral WireGuard configuration directly below. Run it with wg-quick, and you are online in seconds.

Step 01

Add this configuration to your WireGuard client:

Generating...
Step 02

Connect, then access your device at this URL (replace 3000 with your local port):

Generating...
Security Warning:The generated URL can be modified to access any port on your device. Only share this URL with people you trust implicitly.

Note: Anonymous and free tunnels include an interstitial warning page. To get nicer, reserved URLs and interstitial-free endpoints, please upgrade to a paid account.

Your local service must accept IPv6 connections. See the WireGuard setup guide for binding and troubleshooting.

Registered User Benefits

Anonymous tunnels are fully supported (and free), but the Pro plan unlocks the infrastructure for production use with yearly ($60/yr) or lifetime ($120) pricing:

  • Custom Subdomains: Claim your-app.serveousercontent.com permanently.
  • No Interstitial: Remove the browser warning page for client demos.
  • Key Management: Store your public keys in the console so your config files work across reboots.

Try it out

If you have wireguard-tools installed, generate a config above and give it a shot. Your app must listen on IPv6, not only on 0.0.0.0. The WireGuard setup guide covers the full configuration and troubleshooting steps.

Questions? Found a bug? Email me directly at trevor@serveo.net.