…
…
…
32 CSPRNG bytes, clamped per Curve25519 · public key = private scalar × base point 9 · generated locally, never sent · keys are deliberately not encoded in the share URL.
(Dokumentaatio englanniksi)
What it does
The WireGuard Key Generator creates the cryptographic keys a WireGuard tunnel needs, entirely in your browser. It draws 32 bytes from your device’s CSPRNG, clamps them per the Curve25519 rules (key[0] &= 248; key[31] &= 127; key[31] |= 64), and derives the matching public key by multiplying the curve’s base point — a pure-BigInt implementation of the RFC 7748 Montgomery ladder over GF(2²⁵⁵ − 19). You can also generate an optional pre-shared key (PSK) and copy a ready-to-edit wg-quick config template.
Both keys are emitted as standard
Base64Base64An encoding representing binary data as 64 safe ASCII characters, so it survives transport through text-only channels. It encodes — it does not encrypt.
with padding — 44 characters — the exact formatwg setconf, wg-quick, and every WireGuard manager expects. Nothing is uploaded: generation, derivation, and copying are all local, and keys are deliberately never encoded into the page URL.
How to use it
- Press Generate (or Regenerate) to create a fresh key pair.
- Copy the Private key into the
[Interface]section of your device’s config — never share it. - Copy the Public key and give it to the peer or server administrator — it is safe to share.
- Flip the Pre-shared key switch for an optional 32-byte PSK; put the same value in both sides’ configs for extra symmetry protection.
- Copy the Config template, then replace
<PEER_PUBLIC_KEY>,Address, andEndpointwith your server’s values.
Examples
A known key pair (RFC 7748 §6.1 “Alice” test vector)
Private key: dwdtCnMYpX08FsFyUbJmRd9ML4frwJkqsXf7pR25LCo=
Public key: hSDwCYkwp1R0i33ctD73Wg2/Og0mOBr066SpjqqbTmo=
Feed the private key into any X25519 implementation and you get exactly this public key — the derivation this tool performs is verified against vectors like this one in its unit tests. A freshly generated pair is random output in the same 44-character format.
Config template with a pre-shared key
[Interface]
PrivateKey = dwdtCnMYpX08FsFyUbJmRd9ML4frwJkqsXf7pR25LCo=
PublicKey = hSDwCYkwp1R0i33ctD73Wg2/Og0mOBr066SpjqqbTmo=
Address = 10.0.0.2/32
[Peer]
PublicKey = <PEER_PUBLIC_KEY>
PresharedKey = 7Xk2Pq9wLmY4vRtNz8sB1cHf6Gj3Kd0eA5uOi2WxSbE=
AllowedIPs = 0.0.0.0/0, ::/0
Endpoint = vpn.example.com:51820
PersistentKeepalive = 25
Rotating a key
Regenerate → replace only the PrivateKey line in your config →
send the new Public key to the peer admin → restart the tunnel.
Good to know
- Why clamping? The low 3 bits and the top bit are cleared and bit 254 is forced, so every private key is a valid scalar that works with any Curve25519 implementation and protects against small-subgroup attacks.
- Pre-shared keys add a 256-bit symmetric secret on top of the Diffie-Hellman exchange — useful against future quantum attacks on recorded traffic. The same PSK must appear in both peers’ configs, and it is never clamped (it is used as raw key material).
- Private: runs 100% client-side; the CSPRNG and curve math never touch the network, and keys are not written to the URL or storage.
- Related tools: Password Generator, Secure Token Generator,
HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
Generator.