A terminal UI for managing WireGuard VPN profiles. Create, edit, toggle, import, export, and monitor connections — all from a single interface.
Requires sudo because WireGuard configuration lives in /etc/wireguard/ and interface control needs root.
- Profile list with up/down status, peer counts, and quick toggle
- Creation wizard with auto key generation and smart defaults
- Profile editor with inline field editing and peer management
- Live status view with auto-refreshing transfer stats, handshake times, and keepalive
- Import from
.conffiles with preview before saving - Export as config text or QR code, with save-to-file
- Delete with confirmation dialog
- Amplifi Teleport — create and refresh VPN profiles for Ubiquiti Amplifi routers via WebRTC signaling
- Go 1.25+
wgandwg-quick(wireguard-tools)- Linux (uses
/etc/wireguard/andipcommands)
go build -o wireguard-tui .sudo ./wireguard-tuiCopy the binary somewhere on your PATH:
sudo cp wireguard-tui /usr/local/bin/| Key | Action |
|---|---|
j / k |
Move cursor up/down |
enter |
Open profile detail |
n |
New profile (wizard) |
a |
Amplifi Teleport setup |
t |
Toggle selected profile |
i |
Import profile |
q |
Quit |
| Key | Action |
|---|---|
e |
Edit profile |
s |
Live status |
t |
Toggle up/down |
r |
Reconnect Teleport |
x |
Export profile |
d |
Delete profile |
esc |
Back to list |
r only appears for profiles with a saved Teleport token.
Native support for Ubiquiti Amplifi Teleport VPN. Create WireGuard profiles that connect through your Amplifi router without manually configuring anything.
- Open the AmpliFi app on your phone
- Go to Teleport → Add Device to get a PIN
- In wireguard-tui, press
afrom the list view - Enter a profile name and the PIN, then press Enter
- The TUI connects via WebRTC signaling, negotiates an ICE endpoint, and generates a WireGuard config automatically
Teleport endpoints change when your network conditions change. To refresh:
- Select the Teleport profile and press Enter to open it
- Press
rto reconnect — a new endpoint is negotiated using the saved device token (no PIN needed)
Tokens are stored in /etc/wireguard/.teleport/.
A status script is included for showing WireGuard connection state in Waybar. It uses ip link show type wireguard (no root needed) to detect active tunnels.
- Copy the status script:
cp examples/waybar-wireguard ~/.local/bin/waybar-wireguard
chmod +x ~/.local/bin/waybar-wireguard- Add the module to your
~/.config/waybar/config.jsonc:
- Add styles to your
~/.config/waybar/style.css:
#custom-wireguard {
background-color: @background;
color: @foreground;
padding: 0 10px;
margin: 5px 0;
}
#custom-wireguard.connected {
color: #8bc34a;
}
#custom-wireguard.disconnected {
color: #888;
}- Restart Waybar to apply changes (
omarchy-restart-waybaron Omarchy).
If you want the on-click to open the TUI as a floating terminal window, create ~/.local/bin/wireguard-tui-launch:
#!/bin/bash
# Launch wireguard-tui as a floating dialog with sudo for privilege escalation
exec setsid uwsm-app -- xdg-terminal-exec --app-id=org.omarchy.wireguard-tui -e sudo wireguard-tuiThis works with Hyprland window rules to float and center the terminal. Add to your Hyprland config:
windowrule = tag +floating-window, match:class org.omarchy.wireguard-tui
.
├── main.go Entry point (root check, binary check, tea.Program)
├── internal/
│ ├── wg/ WireGuard backend
│ │ ├── config.go Config parsing and serialization
│ │ ├── keys.go Key generation (wg genkey/pubkey/genpsk)
│ │ ├── interface.go Interface control (up/down/toggle/status)
│ │ ├── status.go Status parsing (wg show output)
│ │ ├── qr.go QR code generation
│ │ └── *_test.go Tests for each module
│ ├── teleport/ Amplifi Teleport backend
│ │ ├── credentials.go Token and UUID persistence
│ │ ├── client.go Amplifi API client
│ │ ├── sdp.go SDP attribute injection/parsing
│ │ ├── connect.go WebRTC orchestration and config generation
│ │ └── *_test.go Tests for each module
│ └── tui/ Terminal UI (Bubbletea)
│ ├── app.go Root model, view routing, shared messages
│ ├── styles.go Lipgloss styles and colors
│ ├── list.go Profile list view
│ ├── detail.go Profile detail view
│ ├── wizard.go Creation wizard (6-step)
│ ├── editor.go Profile editor with peer management
│ ├── status.go Live status with auto-refresh
│ ├── importview.go Import from .conf file
│ ├── export.go Export as text/QR with save
│ ├── confirm.go Confirmation dialog
│ └── teleportview.go Amplifi Teleport setup/reconnect
└── examples/
└── waybar-wireguard Waybar status script
- bubbletea — Terminal UI framework
- bubbles — Text input components
- lipgloss — Terminal styling
- go-qrcode — QR code generation
- pion/webrtc — WebRTC for Amplifi Teleport