This article shows how to list, add and remove port forwards with the WireGuard REST API. A port forward sends traffic from your server's public IP to one of your WireGuard users, so you can host a website, game server or other service behind your dedicated server.
For example, forward the server's port 8080 to port 80 on a device, and anyone visiting server-ip:8080 reaches the web server on that device. You'll need an API key: see WireGuard REST API: Getting Started.
List a user's port forwards
GET /api/wg/users/{user_id}/port-forwards
curl -s \
-H "Authorization: Bearer wg_YOUR_KEY" \
-H "Accept: application/json" \
https://portal.premiervpn.net/api/wg/users/12/port-forwards
Response:
{
"user": "web-server",
"port_forwards": [
{
"id": 5,
"external_port": 8080,
"internal_port": 80,
"protocol": "tcp",
"status": "active",
"comment": "pf_12_8080_tcp_1791100000",
"created_at": "2026-10-01T10:00:00+00:00"
}
]
}
The list includes forwards you've removed, with status set to removed. Only active forwards are in use. If you didn't set a comment, comment holds an internal reference.
Add a port forward
POST /api/wg/users/{user_id}/port-forwards
The forward is applied on the server straight away and stays in place after a restart.
curl -s -X POST \
-H "Authorization: Bearer wg_YOUR_KEY" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-d '{"external_port": 8080, "internal_port": 80, "protocol": "tcp"}' \
https://portal.premiervpn.net/api/wg/users/12/port-forwards
Parameters
| Field | Required | Description |
|---|---|---|
external_port | Yes | Port on the server's public IP, 1 to 65535 |
internal_port | Yes | Port on the device, 1 to 65535 |
protocol | Yes | tcp, udp or both |
comment | No | A label for your reference, up to 100 characters |
Each forward covers a single port. For several ports, send one request per port.
Response (201)
{
"message": "Port forward 8080 → 80/tcp created.",
"port_forward": {
"id": 5,
"external_port": 8080,
"internal_port": 80,
"protocol": "tcp",
"status": "active",
"comment": "pf_12_8080_tcp_1791100000",
"server_ip": "203.0.113.10"
}
}
Keep the id. You need it to remove the forward.
Reserved ports
These external ports can't be forwarded:
- 22: server management
- 51820, and your server's WireGuard port if different (
wg_portinGET /api/wg/servers) - 56561: internal management
Port 25 is also blocked on our servers to prevent spam, so traffic to a mail server on port 25 won't get through.
Errors
| Status | Code | Meaning |
|---|---|---|
| 422 | port_reserved | The external port is reserved |
| 409 | port_unavailable | That port and protocol are already forwarded on this server |
| 422 | (validation) | A field is missing or invalid. See the errors object. |
| 403 | forbidden | The user isn't on your account |
| 500 | creation_failed | The server couldn't apply the forward. The error message says why, for example a port already forwarded as both. |
Remove a port forward
DELETE /api/wg/port-forwards/{port_forward_id}
curl -s -X DELETE \
-H "Authorization: Bearer wg_YOUR_KEY" \
-H "Accept: application/json" \
https://portal.premiervpn.net/api/wg/port-forwards/5
Response:
{
"message": "Port forward 8080/tcp removed."
}
Removing a user also removes all of its port forwards.
Things to know
- The device must be connected to the server for a forward to work.
- Connections reach your device from the server's internal address (the
.1address in your subnet), not the visitor's real IP. - Internal ports can repeat across users, because each user has its own internal IP.
- Test from outside, for example a phone on mobile data, not from a device connected to the same server.
Common uses
- Web server: forward
80and443(TCP) to the device running your site. - Game server: forward the game's port, for example
25565(TCP) for Minecraft Java Edition. - Remote desktop: forward a custom external port to
3389(TCP) for RDP, or to5900for VNC. - Your own app or API: forward any free port to the port your app listens on.
Prefer the portal? See Setting Up Port Forwarding.