Skip to content

wg-easy-mcpYour WireGuard VPN, spoken to

An MCP server for wg-easy v15: list, create and revoke VPN clients, pull configs and QR codes, and read server status — from Claude, Codex or any MCP client.

wg-easy-mcp architectureAn MCP client speaks stdio to wg-easy-mcp, which calls the wg-easy REST API over HTTPS with Basic Authentication; wg-easy configures the WireGuard interface.MCP clientClaude, Codex, Inspectorwg-easy-mcp11 tools, zod-validatedwg-easy v15REST API :51821WireGuardwg0 interfacestdioHTTPSBasic Authasks a person · redaction · response budget
The server holds no state beyond short-lived approvals; wg-easy remains the source of truth.

Listing the tools, narrowing them to the essential preset, and the startup abort a mistyped tool name produces

Running it elsewhere ​

A client that cannot spawn a local process — ChatGPT connectors, Claude on the web, Cursor, LibreChat — cannot start wg-easy-mcp the way Claude Code does. mcp-hub is the bridge: one container serves many stdio MCP servers over Streamable HTTP, with an OAuth 2.1 login behind a single password and long-lived tokens for the clients that cannot do OAuth. Its /hub endpoint puts every server behind six meta-tools, so one connector reaches all of them without N×tool schemas in the model's context, and it speaks both protocol revisions — a question this server asks travels through it to the person at the far end instead of ending at the gateway.

Its configuration is Claude Code's mcpServers format, so the entry you already have is the entry it takes: Through mcp-hub.

Released under the MIT License.