Open-source project
WireGuard/wireguard-windows avatar
WireGuard/wireguard-windows

WireGuard for Windows: the official client, its installer and its enterprise shape

Download WireGuard for Windows at https://www.wireguard.com/install . This repo is a mirror only. Official repository is at https://git.zx2c4.com/wireguard-windows

2,833 stars684 forksGoMIT

At a glance

What is it?
WireGuard for Windows is the official Windows client built on WireGuardNT, distributed as an installer or standalone MSIs. It is a system-level tunnel client with a documented admin registry, not a consumer VPN app.
Who is it for?
Adopt it if you are a Windows user or a system administrator who wants the official WireGuardNT-based client and can deploy the MSI or the installer, and if you are willing to read docs/adminregistry.md before rolling it out. Do not adopt it if you need a consumer VPN app with server selection and a subscription, or if you expect the repository to be the place you file issues, since it is a mirror and the official repository is at git.zx2c4.com.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 5 days ago.
What is it written in?
Mainly Go, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What WireGuard for Windows actually is, and who it is for

This repository holds a fully-featured WireGuard client for Windows that uses WireGuardNT, the kernel-level WireGuard implementation for Windows. The README states plainly that it is the only official and recommended way of using WireGuard on Windows. That sentence does most of the positioning work: this is not a third-party wrapper around a userspace tunnel, and it is not a consumer VPN product with a server list. It is the reference client.

The audience follows from that. There are two groups. The first is a Windows user who already has a WireGuard configuration (a .conf file with an interface and one or more peers) and wants the tunnel to run on the machine. The second is a system administrator who has to put the client on many machines, which is why the download page offers standalone MSIs separately from the ordinary installer. The README says the MSIs exist for system admins who wish to deploy them directly, while most end users let the installer fetch them.

If you are looking for a hosted VPN service, this is the wrong repository. There is no account, no subscription and no server selection here. The client connects to peers you configure.

WireGuardNT underneath: where the tunnel and the UI separate

The architecture visible in the repository layout splits into a driver layer and a user-facing layer. The driver/ directory and the WireGuardNT dependency point to the tunnel itself running below the application, while ui/, manager/, services/ and tunnel/ hold the Windows-side management code. The Makefile confirms the dependency explicitly: the build downloads wireguard-nt-1.1.zip and verifies it against a SHA-256 hash before unpacking, and the build tags include load_wgnt_from_rsrc, meaning the WireGuardNT binary is loaded from a resource rather than fetched at runtime.

The language mix matters for anyone planning to build. The module path is golang.zx2c4.com/wireguard/windows, the primary language is Go, and go.mod pins github.com/lxn/walk and github.com/lxn/win, with replace directives pointing both at the project's own module. In other words, the GUI toolkit is vendored through the project rather than taken from upstream. The repository also carries an embeddable-dll-service/ directory, which is the piece that lets other software drive the tunnel without reimplementing the Windows plumbing.

There is a security design document, docs/attacksurface.md, described as a discussion of the components from a security perspective so that future auditors have a head start. That is an unusual artifact for a client application and it is worth reading before you decide how much you trust the elevated parts.

Installing WireGuard for Windows and bringing up a first tunnel

The README points at the main download page rather than giving install steps itself. From there, the WireGuard Installer selects the most recent version for your architecture, downloads it, checks signatures and hashes, and installs it. Standalone MSIs are also published for administrators who want to deploy them directly.

If you prefer to drive the installer from a shell, the repository ships a quickinstall.bat at the top level. It is a batch file, so run it from a Windows command prompt in the repository directory:

bash
quickinstall.bat

The README does not document what quickinstall.bat does beyond its name and its presence in the repository root, so treat it as a convenience wrapper and read it before running it on a machine you care about.

For a first real tunnel, the workflow is the standard one: create or obtain a .conf file describing the interface and its peers, then import it into the client. The repository has a conf/ directory, which is where the project keeps its own configuration-related code rather than a place for your tunnels. The README does not walk through the import dialog, so the reliable path is to follow the client's own interface once it is installed.

If you are building from source rather than installing, docs/buildrun.md is the document the README names for building, localizing, running and developing against this repository. The Makefile targets amd64/wireguard.exe, x86/wireguard.exe and arm64/wireguard.exe, so all three architectures are buildable from the same tree.

The admin registry and the kill-switch semantics are the real documentation

Two documents carry most of the operational weight. docs/adminregistry.md is a list of registry keys settable by the system administrator for changing the behavior of the application. That is the supported customization surface for managed fleets: instead of asking users to click through the UI, an administrator sets policy in the registry and the client follows it. If you are deploying this across an organization, that file is the one to read first, and docs/enterprise.md is described as a summary of features and tips for making the application usable in enterprise settings.

The second is docs/netquirk.md, described as a description of various networking quirks and kill-switch semantics. The phrase kill-switch semantics is doing a lot of work. Whether traffic is blocked when the tunnel drops, and under exactly which conditions, is the difference between a client that silently leaks and one that fails closed. The README does not restate those semantics inline; it points at the document. Anyone who assumes the behavior instead of reading it is guessing.

This is where the project is honest about itself. It ships an attack surface discussion, a networking quirks document and an enterprise guide, and it does not pretend the Windows networking stack is simple. The cost is that the README alone will not tell you how the client behaves at the edges.

Where WireGuard for Windows is the wrong tool

The repository is a mirror. The README says so directly: the official repository is at git.zx2c4.com/wireguard-windows. If your workflow is to open an issue, send a pull request or track a branch here, you are working against a copy. That is a genuine limitation and not a small one for anyone who wants to contribute or to follow development closely.

Second, this is a Windows-only client. The go.mod sets GOOS to windows in the Makefile and the build targets are all .exe files. If your fleet is mixed, this repository solves the Windows half only, and you will be pairing it with a different implementation elsewhere. The search question about WireGuard on Windows versus Linux is a fair one to ask, and the honest answer from what the README and repository files state is that this repository is not the Linux side of that comparison.

Third, the README gives no release notes and no changelog. There is a version/ directory and the Makefile extracts a version number from version/version.go, so versioning exists in the tree, but the README does not document an upgrade path, rollback behavior or a compatibility policy for configuration files across versions. If you need a documented rollback story before you deploy, that story is not in the README, and you should look for it in the documents the README does name before assuming it exists.

How it compares with a userspace tunnel client

The meaningful alternative to this client is a userspace WireGuard implementation on Windows, of which the most commonly cited is the WireGuard Go userspace implementation bundled into other clients. The difference is architectural rather than cosmetic. This project runs the tunnel through WireGuardNT, the kernel-level implementation, and the Makefile shows the NT binary being downloaded, hash-verified and loaded from a resource at build time. A userspace client runs the same protocol but moves packets through a user-mode process.

The practical consequences are the ones you would expect. A kernel-level implementation avoids the context switches of a userspace data path, and it integrates with the Windows networking stack in the way the operating system expects. A userspace client is generally easier to port and easier to run in constrained environments, but it pays for that in the data path. The README does not offer benchmarks or performance numbers, and it does not need to: the architectural split is stated, and the rest is a design consequence.

There is also the embeddable-dll-service/ directory, which is the route for software that wants to use this tunnel without shipping the full client UI. That is a third option between adopting the client and writing your own Windows tunnel code.

Licence and the cost of keeping it current

The repository is MIT-licensed, and the README includes the full licence text with a copyright line covering 2018 through 2026, WireGuard LLC. MIT is permissive: it allows use, copying, modification, merging, publication, distribution, sublicensing and sale, provided the copyright notice and permission notice are included. The licence text also carries the standard warranty disclaimer, so the software is provided as is.

That permissiveness has a practical consequence for anyone embedding the client or the DLL service in a commercial product: the licence itself does not impose copyleft obligations on your code. It does not follow that the WireGuardNT component has identical terms, and the README does not state its licence. If you are shipping the NT driver as part of your product, that is the thing to confirm separately, and this article is not legal advice.

Upgrade cost is harder to pin down. The Makefile pins specific dependency versions, including go 1.26.0 in go.mod and a specific Go toolchain tarball with a SHA-256 hash in the Makefile, and it pins wireguard-nt-1.1.zip the same way. That is a reproducible build, which is good, but it also means building from source requires fetching those pinned artifacts. End users who install from the official installer avoid this entirely, because the installer handles downloading and verifying the current version for their architecture. For administrators deploying MSIs, the upgrade path is whatever your software distribution tooling does with MSI packages; the README does not describe one.

Editorial conclusion

Adopt it if you are a Windows user or a system administrator who wants the official WireGuardNT-based client and can deploy the MSI or the installer, and if you are willing to read docs/adminregistry.md before rolling it out. Do not adopt it if you need a consumer VPN app with server selection and a subscription, or if you expect the repository to be the place you file issues, since it is a mirror and the official repository is at git.zx2c4.com. Before deploying, verify the signature and hash checks the installer performs, confirm which MSI matches your architecture, and read docs/netquirk.md for the kill-switch semantics, because those are the two things that decide whether a rollout behaves the way you expect.

Frequently asked questions

Is WireGuard for Windows completely free?

The repository is MIT-licensed, and the README includes the full licence text permitting use, copying, modification and distribution. The download page linked from the README is where the installer and standalone MSIs are published.

Can I use WireGuard on Windows 11?

The README describes this as a fully-featured WireGuard client for Windows that uses WireGuardNT, and the only official and recommended way of using WireGuard on Windows. It does not list specific Windows versions, so the README is silent on a Windows 11 compatibility matrix.

How do I install WireGuard on Windows?

The README points to the main download page, where the WireGuard Installer selects the most recent version for your architecture, downloads it, checks signatures and hashes, and installs it. Standalone MSIs are also published for administrators who want to deploy them directly.

How do I set up WireGuard on Windows?

You supply a configuration describing the interface and its peers, then bring the tunnel up in the client. The repository has a conf/ directory for its own configuration code, but the README does not walk through the import workflow step by step.

What is WireGuard for Windows?

It is the official Windows client for WireGuard, built on WireGuardNT, the kernel-level implementation for Windows. The README states it is the only official and recommended way of using WireGuard on Windows.

Official sources

  1. Issues
  2. License: MIT
  3. Project website
  4. README
  5. WireGuard/wireguard-windows on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/wireguard-wireguard-windows.svg)](https://hysenlabs.com/projects/wireguard-wireguard-windows)