Skip to content
← Back to journal

2026-09-08 · 2 min read

Getting started with WireGuard device keys

A practical explanation of the key pair that identifies a WireGuard device.

WireGuard uses a public and private key pair for each peer. The private key stays with the device. The public key is the value a server needs to identify that peer. The official quick start shows the command-line flow, and the protocol description explains why the public key is part of the handshake.

The safe sequence

  1. Generate the key pair on the device or in a reviewed client.
  2. Keep the private key in the device’s protected storage. Do not paste it into a support ticket or send it to a service.
  3. Register only the public key with the VPN server.
  4. Receive the peer configuration and import it into the standard WireGuard client.
  5. If the private key is lost or exposed, create a replacement key pair and revoke the old peer.

The server needs a unique public key for each live device. A second device should have its own pair, even when both devices belong to the same person. This gives the server a precise peer to remove or replace.

What to check

Before connecting, check that the configuration names the intended server and that the device keeps the private key local. After connecting, verify that the tunnel has a recent handshake and that the routes match the access you expect. Client screens differ, so use the documentation for the specific WireGuard client you install.

This setup explains the key boundary; it does not promise a universal kill switch, leak protection, or client behavior. Those are separate features that need platform-specific testing.