WireGuard® Management Platform

Secure, central WireGuard® management.

One secure place to manage your company’s VPN access — deploy tunnels, control who connects, and see what’s happening, all self-hosted. Your people just click — or tap in the mobile app — to connect: no admin rights, no config files, no support tickets.

Windows · Linux · macOS · Android · iOS clients  ·  Self-hosted backend  ·  Open-source core (AGPLv3)  ·  EU data sovereignty

WireGuard® is a registered trademark of Jason A. Donenfeld. Valenius is not affiliated with or endorsed by Jason A. Donenfeld.

Valenius
Office VPN Connected ✓ verified
Datacenter Ready
Customer site Ready
Installed once by IT — zero admin rights needed after that
The problem

WireGuard® is brilliant. Managing it across a fleet isn’t.

The protocol is fast and secure — but on its own it gives you no central way to deploy tunnels, control who connects, or see what’s happening. Each of those gaps lands on IT.

🔒

Tunnels need admin rights

Installing a WireGuard® tunnel on Windows requires elevation. Either you grant users admin rights, or IT connects every laptop by hand.

📄

Config files everywhere

Keys and configs get emailed around, copied to USB sticks, and forgotten on desktops. Nobody knows which device holds which key.

👁️

Zero visibility

Who is online? Which client runs an outdated version? Plain WireGuard® gives you no central view of your fleet — Valenius does.

How it works

Install once. Connect forever.

A central admin panel is your control plane; a privileged background service does the heavy lifting; users only ever talk to a friendly tray app.

1

Deploy the control plane

One Docker Compose stack on your own server. Manage clients, push configs, and watch presence from a central admin panel.

2

Install the client — once

IT rolls out the Windows, Linux, or macOS installer with admin rights a single time. The service runs privileged; your users never need to. On mobile, there’s no admin step at all — install the app and scan a pairing QR code.

3

Users click — and connect

One click in the tray icon brings the tunnel up. Valenius even probes through the tunnel and shows a green checkmark when the connection is verified end-to-end.

See it in action

A real admin panel, not a mockup

The control plane your IT team actually uses — live client counts, presence, and fleet traffic at a glance.

Valenius admin panel Overview page: client counts, presence, and a fleet-wide traffic dashboard
The actual admin panel — click to view full size
Who it’s for

One platform, three ways to run it

For IT teams

Give your colleagues VPN access — keep the admin rights

Self-host the free Community edition on your own infrastructure. Upload your existing WireGuard® configs and let everyone connect with one click.

  • Free forever, AGPLv3 open source
  • Works with your existing WireGuard® server
  • OIDC single sign-on and TOTP for the admin panel
  • Clients auto-update from your backend
  • Windows, Linux, macOS, Android & iOS clients
Download Community
For MSPs & service providers

Manage every customer’s VPN from one panel

Valenius Pro adds zero-touch peer provisioning, per-customer isolation, and a plug-in Raspberry Pi appliance for customers without their own IT.

  • Automated peer provisioning — no manual configs
  • mTLS-secured server management
  • Per-customer licensing and isolation
  • Appliance updates with health checks and auto-rollback
  • Opt-in cross-customer profile sharing for shared infrastructure
  • Automatic UDP 443 fallback — customers stay connected on locked-down networks
See Pro pricing
Managed cloud

Or let us run it for you

No ops capacity? Stranto hosts and operates Valenius as a managed cloud service — with the same guarantees: hosted in the EU, GDPR-friendly, and your VPN stays yours.

  • Hosted & operated by Stranto in the EU
  • All Pro features included
  • Updates & backups handled for you
  • From €3.00 per endpoint / month
See cloud pricing
Flag of the European Union

Your data never leaves your company

Valenius is developed by Stranto Business Solutions GmbH, a company based in the EU. The platform is self-hosted by design: VPN keys, configs, device data, and audit logs live on your servers — not in a third-country cloud. That makes GDPR compliance a property of the architecture, not a promise in a privacy policy. And if you prefer our managed cloud instead, it runs in the EU with the same guarantees.

  • Self-hosted — all data stays on your infrastructure
  • EU-based company, EU cloud option
  • GDPR-friendly by architecture, not by promise
  • No mandatory cloud account, no phone-home
Open core

Community & Pro

The core is open source under AGPLv3 — no client limits, no time bombs. Pro adds the automation layer for providers.

Community

Free & open source. Self-hosted.

  • Full admin panel with client management
  • Manual config upload & push to clients
  • OIDC login & TOTP two-factor
  • Client auto-update
  • Audit log
  • Config encryption at rest on every client
  • Windows, Linux, macOS, Android & iOS clients
Get Community
Automation

Pro

Everything in Community, plus:

  • Automated peer provisioning via the server sidecar
  • mTLS between backend and WireGuard® server
  • Traffic statistics & dashboards per client, customer, and fleet
  • Server-enforced MFA for VPN access
  • Per-customer licensing
  • Raspberry Pi appliance with managed updates
  • Available self-hosted or hosted by Stranto
  • Server-side liveness detection & remote Kill Tunnel
  • Automatic fallback on UDP 443 — a resilience layer other WireGuard® tools don’t have
  • One-click connectivity self-test, confirmed with a real WireGuard® handshake
  • Management REST API and a built-in MCP server — automate from your own tooling, or from an AI assistant
Compare plans
New — Automation & AI

Ask your AI assistant to run the VPN

Valenius exposes its entire admin surface as a modern REST API — and as an MCP server, the protocol AI assistants use to call tools. Connect Claude, Gemini, OpenAI or Mistral and manage your fleet in plain language.

🤖

Talk to your fleet

“Which clients haven’t checked in this week?”  “Disconnect the laptop that was just reported stolen.”  “Onboard a new customer called Acme.” Your assistant calls exactly the same API your admins use — there is no second, weaker way in.

⚙️

A REST API for everything else

Clients, customers, provisioning, MFA policy, traffic and audit data — all scriptable. The OpenAPI 3.1 spec is published openly, so Visual Studio, Postman, n8n or your own RMM can import it straight from the URL and generate a typed client.

🔐

You decide what it may touch

Every token carries only the permissions you tick — a read-only “triage” assistant can look but never act. Bind a token to a single customer, and it can never see the rest of your fleet. Every call is audit-logged, and revoking takes effect instantly.

No other WireGuard® panel ships an MCP server

Several WireGuard® tools offer some kind of REST API. None of them let an AI assistant operate the VPN directly — that part is ours alone today. It’s included in every Pro licence at no extra cost, with no AI-specific credential, no cloud account, and no data leaving your backend beyond the request the assistant makes.

See how it works →
Security

Built like infrastructure, not like a gadget

Every layer assumes the network is hostile — from the client’s file permissions to the management plane.

🔬

Built on genuine, unmodified WireGuard®

Valenius uses the official upstream WireGuard® protocol exactly as published — no forks, no custom cryptography, no protocol changes. You get the security of the audited original and full compatibility with standard WireGuard® tooling, in this release and every future one.

🛡️

mTLS management plane

Pro servers enroll against an internal certificate authority. Every management call requires a mutually authenticated TLS connection.

🔐

Configs encrypted at rest

Every VPN profile is encrypted on the device — DPAPI on Windows, AES-256-GCM on Linux, and the platform keystore on macOS, Android, and iOS — whether pushed by an admin or uploaded manually. Included in both editions.

🪪

OIDC & TOTP

Sign in to the admin panel with your existing identity provider, with TOTP two-factor on top — included in the free edition.

📲

MFA for VPN access

Pro enforces multi-factor authentication on the VPN session itself: a user’s tunnel only carries traffic after a verified second factor — not just at the admin panel.

📜

Audit log

Every connect, config push, and admin action is recorded. Know who did what, when — also in the free edition.

🏛️

EU company, GDPR-friendly

Built by Stranto Business Solutions GmbH in the EU. Self-host everything, or choose EU hosting by Stranto — your data is never subject to third-country cloud access.

⚖️

Open source core

The Community edition is AGPLv3-licensed and publicly auditable. No hidden phone-home, no vendor lock-in on the protocol.

🔄

Credentials you can rotate

Rotate the client API key across your entire fleet from the panel. And when a device needs debugging, diagnostic logs are redacted on the device itself — keys and secrets never leave it.

Platforms

Every piece of the puzzle

Windows client

Windows Service plus tray app. x64 and ARM64. Signed installer, silent rollout.

Linux client

Systemd daemon plus GTK tray app. Distributed as a .deb package, stdlib only.

macOS client

Background daemon plus menu bar app. Apple Silicon & Intel, one-click connect.

Android app

QR pairing, TOTP & push-to-approve MFA, encrypted profile storage.

iOS app

Same one-tap experience as Android, on the same shared codebase.

🐳

Backend

Self-hosted Docker Compose stack. One container, your hardware, your data.

🍓

Pi appliance

Pre-configured Raspberry Pi box for sites without IT. Plug it in — done.

Roll out WireGuard® to your whole team this week

Start with the free Community edition — no client limit, no trial clock, no credit card.