WireHQ
Enterprise management for WireGuard®
A management plane for WireGuard: identity, access policies, deployment and a tamper-evident audit trail. Available as a managed service, or self-hosted in full under AGPLv3.
- Single sign-on over OIDC and SAML 2.0, SCIM 2.0 provisioning and LDAP / Active Directory sync — Entra ID, Okta, Google Workspace.
- Access policies declared by user, team or role, compiled straight to per-peer AllowedIPs and deployed for you.
- Hash-chained, tamper-evident audit log with OCSF / CEF export for your SIEM.
- Deploys over SSH, or through an outbound-only mTLS agent that needs no inbound ports at all.
WireGuardOIDC / SAMLSCIM Postgres RLSDockerSelf-hostable
wirehq.net Live