Documentation

WireGuard

Keep a tunnel available through network changes using a standard WireGuard client. Serveo can publish an HTTP service at an HTTPS hostname, or a raw TCP or UDP service on a public port for paid accounts.

Sections

Quick start

You can try an anonymous HTTP tunnel without an account. Install WireGuard orwg-quick on the machine running your app, then:

  1. Start your local web server on an IPv6 listener, such as [::]:3000. An IPv4-only listener at 127.0.0.1 or 0.0.0.0 cannot receive this tunnel's traffic.
  2. Generate the peer configuration below and load it into WireGuard on the same machine. Keep the private key private.
  3. Activate the peer, then open the generated HTTPS URL. Replace 3000 in the URL with your app's port if needed.

For a quick IPv6-capable test service:

python3 -m http.server 3000 --bind ::

Leave this process running while you test. On a system with wg-quick, save the generated configuration as serveo.conf and activate it with:

sudo wg-quick up ./serveo.conf

Generate an anonymous peer

Step 01

Add this configuration to your WireGuard client:

Generating...
Step 02

Connect, then access your device at this URL (replace 3000 with your local port):

Generating...
Security Warning:The generated URL can be modified to access any port on your device. Only share this URL with people you trust implicitly.

Note: Anonymous and free tunnels include an interstitial warning page. To get nicer, reserved URLs and interstitial-free endpoints, please upgrade to a paid account.

Your local service must accept IPv6 connections. See the WireGuard setup guide for binding and troubleshooting.

What the configuration does

The generator and Serveo Console produce a standard WireGuard configuration. Your peer's IPv6 address is derived from its public key. The private key belongs only on the device running that peer.

Address

Your peer's fd1d:84e3:8aca:1::/64 address, installed as a single /128 interface address.

PublicKey

Serveo's server key. Keep the generated value unchanged.

AllowedIPs

fd1d:84e3:8aca::/48 routes only Serveo's private IPv6 range through the peer. It does not route all your Internet traffic through Serveo.

Endpoint

wg.serveo.net:51820 is the public UDP endpoint used to connect to Serveo.

PersistentKeepalive

Sends a packet every 25 seconds to keep common NAT mappings open while idle.

Public visitors use the HTTPS hostname or public Serveo port. They do not need IPv6; IPv6 is used for the private hop from Serveo to your app.

Make your app reachable on IPv6

Serveo connects to your peer's WireGuard IPv6 address and the port you choose. Your app must listen on that address or on the IPv6 wildcard ::. Binding only to 0.0.0.0 opens IPv4 sockets and is not enough. A dual-stack listener works if it accepts connections to the peer's IPv6 address.

python3 -m http.server 3000 --bind ::

With the tunnel active, check the app from the peer machine using theAddress value in your configuration, without/128. Replace the example address below with yours:

curl -g -6 'http://[fd1d:84e3:8aca:1:1234:5678:9abc:def0]:3000/'

A successful curl http://localhost:3000 may test IPv4 only and does not prove Serveo can reach the service. Check local firewalls and container port publishing if the peer-address test fails. Apps that validate HTTP Host headers may also need to accept your public hostname.

Use a registered domain

  1. In the Console's WireGuard keys, create a peer. Save its private key when shown; Serveo stores the public key.
  2. In Domains, add or select a hostname, choose WireGuard, select that peer, and enter the HTTP port your app listens on.
  3. Load the peer configuration into wg-quick or an official WireGuard app, activate it, then open the hostname over HTTPS.

The console can show the configuration again, but it cannot recover a lost private key. If you lose it, remove the peer and create another. Anonymous and free HTTP tunnels show Serveo's browser warning; paid HTTP tunnels do not.

Public TCP and UDP

Paid accounts can forward a raw TCP or UDP port through a WireGuard peer. InConsole > Keys > WireGuard, add a public port rule. Choose the peer, protocol, public port, and port your app listens on. The public port must be available and at least 1024. Connect toserveo.net:PUBLIC_PORT while the peer is active.

The target service still needs an IPv6 listener on its WireGuard peer. AListening status confirms that Serveo opened the public port, not that the peer or app is reachable. UDP source flows expire after 30 seconds without traffic and reopen on the next packet.

Plaintext HTTP served on a raw public TCP port receives Serveo's browser warning. Use a WireGuard HTTP hostname when you want an HTTPS web URL.

Troubleshooting

Inspect the peer with wg show or your WireGuard app. A recent handshake confirms the peers can communicate; it does not prove your app is listening.

No recent handshake

Confirm the tunnel is active, the key pair matches the configured peer, and your network permits outbound UDP to wg.serveo.net:51820. Try the official WireGuard app if wg-quick is unavailable.

Handshake, but HTTP 502 or a refused connection

Check the port in the URL or Console rule, then test http://[YOUR_PEER_IPV6]:PORT/ on the peer machine. If it fails, bind your app to :: or the peer's IPv6 address and check the firewall.

The app rejects the public hostname

Some development servers restrict the HTTP Host header. Allow your Serveo hostname in that app's host settings; keep the restriction narrow.

A browser warning appears

This is expected for anonymous and free HTTP tunnels, and for plaintext HTTP on a raw public TCP port. It is separate from WireGuard connectivity.

Keys and exposure

Store serveo.conf so only your account can read it: it contains the WireGuard private key. Do not post the configuration or private key. Anyone with a working public URL can reach the published service, subject to the browser warning and any authentication your app provides.

An anonymous WireGuard URL encodes your peer address and port. Changing its port suffix can target another listening port on the same peer. Avoid running sensitive services on a publicly reachable peer, keep application authentication enabled, and use the Console to remove an unused registered peer or forwarding rule.