Black Friday Our biggest deal of the year is coming soon Get notified →

Creating and Managing WireGuard Users

Updated 4 Oct 2026 4 min read

Each device you connect to your dedicated WireGuard® server needs its own WireGuard user. This guide shows you how to create users, download and import their config files, check which devices are online and remove users you no longer need.

Create a user

  1. In the portal sidebar, click WireGuard, then Manage Server on your server.
  2. In Create WireGuard User, enter a name for the device, such as laptop, phone or gaming-pc.
  3. Click Create User.

The portal connects to your server, generates a new key pair and preshared key, and gives the user the next free internal IP address. It takes a few seconds. The new user then appears in the list.

Naming rules

  • Letters, numbers, hyphens (-) and underscores (_) only. No spaces.
  • Up to 50 characters.
  • Each name can only be used once on a server. If a name is taken, you'll see "That name is not available. Please choose another."
You can create up to five users a minute from the portal. If you see "Too many attempts. Please wait a minute.", wait a moment and try again.

Download the config file

Click the .conf button next to a user. You'll get a file named after the user, for example laptop.conf. It contains everything the WireGuard app needs: the device's private key, the server's public key, a preshared key, the server's IP address and port, and DNS settings.

Treat the file like a password. Anyone who has it can connect as that device.

Import the config into WireGuard

Use the official WireGuard app on each device.

Windows

  1. Install WireGuard from wireguard.com/install.
  2. Open WireGuard and click Import tunnel(s) from file.
  3. Choose the .conf file.
  4. Click Activate.

macOS

  1. Install WireGuard from the Mac App Store.
  2. Open WireGuard and choose Import Tunnel(s) from File.
  3. Choose the .conf file and allow the VPN configuration when macOS asks.
  4. Click Activate.

iPhone and iPad

  1. Install WireGuard from the App Store.
  2. Save the .conf file to the Files app (for example, download it in Safari).
  3. Open WireGuard, tap +, then Create from file or archive, and choose the file.
  4. Allow the VPN configuration, then turn the tunnel on.

Android

  1. Install WireGuard from Google Play.
  2. Open WireGuard, tap +, then Import from file or archive, and choose the file.
  3. Turn the tunnel on and accept the VPN connection request.

Linux

  1. Install WireGuard. On Ubuntu or Debian:
    sudo apt install wireguard
  2. Copy the config into place. The file name (without .conf) becomes the interface name, so keep it short:
    sudo cp laptop.conf /etc/wireguard/wg-client.conf
    sudo chmod 600 /etc/wireguard/wg-client.conf
  3. Connect:
    sudo wg-quick up wg-client
  4. Disconnect:
    sudo wg-quick down wg-client

To connect automatically at start-up, run sudo systemctl enable --now wg-quick@wg-client.

View keys or build a custom config

Click Keys next to a user to see its Client Public Key, Client Private Key (click Show or Copy), Preshared Key, Server Public Key and Endpoint. Use these if your router or device needs the values typed in rather than a file.

Under the keys, open Custom Config Builder to download a config with different settings:

  • DNS Servers: choose Cloudflare, Google, Quad9, OpenDNS or keep the current setting.
  • Endpoint Format: connect by the server's IP address, or choose FQDN (hostname) and enter your own hostname in Custom Hostname.

Click Download Custom Config. If you use a hostname, create a DNS A record for it that points to your server's IP address first. The WireGuard port is added for you.

Check which devices are online

Each user shows Online or Offline and when it was last seen. A device counts as online if it has completed a handshake with the server in the last 3 minutes. Once a device has used the tunnel, you'll also see how much data it has received and sent. Refresh the page to update the figures.

Let devices talk to each other

The Peer-to-Peer Blocking box on the server page controls whether your devices can reach each other on their internal IP addresses.

  • Blocked: each device can reach the internet but not your other devices.
  • Allowed: devices can reach each other like a local network, for example a laptop opening files on a home NAS.

The button shows the current setting. Click it to switch. If you see a note saying peer-to-peer is managed by our team, open a support ticket to ask for a change.

Remove a user

Click Remove next to the user and confirm. This:

  • removes the device from the server straight away, so its config file stops working
  • removes all port forwards for that user
  • deletes the user from your account

This can't be undone. The name and internal IP address become free to use again.

FAQs

How many users can I create?

Up to 253 per server. That's the number of internal IP addresses available in the server's subnet.

Can I rename a user?

No. Create a new user with the name you want, import its config, then remove the old one.

Can I use one config on two devices?

Not reliably. Two devices sharing the same keys keep knocking each other off. Create a user for each device.

My config file shows IMPORTED_NO_KEY as the private key. Why?

That user was imported from an existing server set-up, so the portal never had its private key. Keep using the original config file on that device, or create a new user and import its config instead.

Still stuck? Open a support ticket and tell us your device, app version and what you've tried.

Something out of date or unclear? Let us know.

Stay Ahead of Online Threats

Get VPN tips, security insights, and exclusive offers delivered straight to your inbox. No spam — just the essentials.

Unsubscribe at any time. We respect your privacy.

PremierVPN Support