One secure place to manage your company’s VPN access — deploy tunnels, control who connects, and see what’s happening, all self-hosted. Your people just click — or tap in the mobile app — to connect: no admin rights, no config files, no support tickets.
WireGuard® is a registered trademark of Jason A. Donenfeld. Valenius is not affiliated with or endorsed by Jason A. Donenfeld.
The protocol is fast and secure — but on its own it gives you no central way to deploy tunnels, control who connects, or see what’s happening. Each of those gaps lands on IT.
Installing a WireGuard® tunnel on Windows requires elevation. Either you grant users admin rights, or IT connects every laptop by hand.
Keys and configs get emailed around, copied to USB sticks, and forgotten on desktops. Nobody knows which device holds which key.
Who is online? Which client runs an outdated version? Plain WireGuard® gives you no central view of your fleet — Valenius does.
A central admin panel is your control plane; a privileged background service does the heavy lifting; users only ever talk to a friendly tray app.
One Docker Compose stack on your own server. Manage clients, push configs, and watch presence from a central admin panel.
IT rolls out the Windows, Linux, or macOS installer with admin rights a single time. The service runs privileged; your users never need to. On mobile, there’s no admin step at all — install the app and scan a pairing QR code.
One click in the tray icon brings the tunnel up. Valenius even probes through the tunnel and shows a green checkmark when the connection is verified end-to-end.
Self-host the free Community edition on your own infrastructure. Upload your existing WireGuard® configs and let everyone connect with one click.
Valenius Pro adds zero-touch peer provisioning, per-customer isolation, and a plug-in Raspberry Pi appliance for customers without their own IT.
No ops capacity? Stranto hosts and operates Valenius as a managed cloud service — with the same guarantees: hosted in the EU, GDPR-friendly, and your VPN stays yours.
Valenius is developed by Stranto Business Solutions GmbH, a company based in the EU. The platform is self-hosted by design: VPN keys, configs, device data, and audit logs live on your servers — not in a third-country cloud. That makes GDPR compliance a property of the architecture, not a promise in a privacy policy. And if you prefer our managed cloud instead, it runs in the EU with the same guarantees.
The core is open source under AGPLv3 — no client limits, no time bombs. Pro adds the automation layer for providers.
Free & open source. Self-hosted.
Everything in Community, plus:
Valenius exposes its entire admin surface as a modern REST API — and as an MCP server, the protocol AI assistants use to call tools. Connect Claude, Gemini, OpenAI or Mistral and manage your fleet in plain language.
“Which clients haven’t checked in this week?” “Disconnect the laptop that was just reported stolen.” “Onboard a new customer called Acme.” Your assistant calls exactly the same API your admins use — there is no second, weaker way in.
Clients, customers, provisioning, MFA policy, traffic and audit data — all scriptable. The OpenAPI 3.1 spec is published openly, so Visual Studio, Postman, n8n or your own RMM can import it straight from the URL and generate a typed client.
Every token carries only the permissions you tick — a read-only “triage” assistant can look but never act. Bind a token to a single customer, and it can never see the rest of your fleet. Every call is audit-logged, and revoking takes effect instantly.
Several WireGuard® tools offer some kind of REST API. None of them let an AI assistant operate the VPN directly — that part is ours alone today. It’s included in every Pro licence at no extra cost, with no AI-specific credential, no cloud account, and no data leaving your backend beyond the request the assistant makes.
See how it works →Every layer assumes the network is hostile — from the client’s file permissions to the management plane.
Valenius uses the official upstream WireGuard® protocol exactly as published — no forks, no custom cryptography, no protocol changes. You get the security of the audited original and full compatibility with standard WireGuard® tooling, in this release and every future one.
Pro servers enroll against an internal certificate authority. Every management call requires a mutually authenticated TLS connection.
Every VPN profile is encrypted on the device — DPAPI on Windows, AES-256-GCM on Linux, and the platform keystore on macOS, Android, and iOS — whether pushed by an admin or uploaded manually. Included in both editions.
Sign in to the admin panel with your existing identity provider, with TOTP two-factor on top — included in the free edition.
Pro enforces multi-factor authentication on the VPN session itself: a user’s tunnel only carries traffic after a verified second factor — not just at the admin panel.
Every connect, config push, and admin action is recorded. Know who did what, when — also in the free edition.
Built by Stranto Business Solutions GmbH in the EU. Self-host everything, or choose EU hosting by Stranto — your data is never subject to third-country cloud access.
The Community edition is AGPLv3-licensed and publicly auditable. No hidden phone-home, no vendor lock-in on the protocol.
Rotate the client API key across your entire fleet from the panel. And when a device needs debugging, diagnostic logs are redacted on the device itself — keys and secrets never leave it.
Windows Service plus tray app. x64 and ARM64. Signed installer, silent rollout.
Systemd daemon plus GTK tray app. Distributed as a .deb package, stdlib only.
Background daemon plus menu bar app. Apple Silicon & Intel, one-click connect.
QR pairing, TOTP & push-to-approve MFA, encrypted profile storage.
Same one-tap experience as Android, on the same shared codebase.
Self-hosted Docker Compose stack. One container, your hardware, your data.
Pre-configured Raspberry Pi box for sites without IT. Plug it in — done.
Start with the free Community edition — no client limit, no trial clock, no credit card.