Every VPN configuration, generated in your browser
WireGuard, OpenVPN, IKEv2/IPsec, SSL VPN, site-to-site, mesh, cloud and obfuscated proxy configs — 34 VPN types, 9 generators, zero sign-up.
- 34
- VPN types covered
- 9
- Config generators
- No server round-trip
- No sign-up
- No cookies or tracking
What people actually use in 2026
Ranked by real-world deployment across consumer apps, enterprises and cloud platforms.
- 1WireGuard Most used
The most used VPN protocol today — in the Linux kernel and the default in most consumer apps and mesh products.
98/100 - 2Remote-Access VPN Most used
The single most deployed VPN shape in the world — almost every organisation runs one.
96/100 - 3Consumer VPN Most used
Hundreds of millions of installs — nearly all of them now run WireGuard by default.
94/100 - 4IPsec VPN Most used
Universal for site-to-site and cloud tunnels — every firewall vendor speaks it.
92/100 - 5Client-to-Site VPN Most used
The standard corporate pattern, though ZTNA is steadily taking its place at large enterprises.
90/100
Growing fastest
Pick a generator
Each one produces real, downloadable files — not screenshots or examples you have to retype.
WireGuard
Generates real Curve25519 keypairs and complete peer sets — a single client, a site-to-site pair, a hub with spokes, a full mesh, or a multi-hop chain.
OpenVPN
Builds single-file .ovpn client profiles with inline certificates, matching server configs, and static-key site-to-site links.
IKEv2 / IPsec
Produces Apple .mobileconfig profiles, strongSwan configs, Windows PowerShell setup scripts, site-to-site tunnels, GRE over IPsec and DMVPN templates.
Certificates (PKI)
Creates a certificate authority and issues server and client certificates from it — real X.509 PEM files, signed in your browser with the Web Crypto API. This is the PKI that OpenVPN, IPsec and SSL VPN configs need.
Shadowsocks & V2Ray
Creates ss://, vmess://, vless:// and trojan:// links plus client JSON, with a scannable QR code for mobile apps.
SSL VPN (ocserv)
Generates ocserv gateway configs, OpenConnect client profiles and clientless portal rules for TLS-based access over port 443.
Cloud VPN
Builds the on-premises side of a managed cloud tunnel, with matching IKE/IPsec parameters and a Terraform snippet for the cloud side.
Browse by what you need
Remote access
One device reaching into a private network — laptops, phones, contractors.
Site to site
Whole networks joined together — offices, data centres, clouds.
Protocols
The tunnelling technology itself, independent of topology.
Overlay & managed
Mesh fabrics, SD-WAN and provider-managed private networks.
Legacy
Still found in the wild, but superseded — handle with care.
Nothing leaves your device
Keys, passwords and certificates are generated with the Web Crypto API inside your tab. There is no API call carrying them anywhere.
No accounts, no storage
No backend, no database, no cookies, no analytics. Reload the page and everything you typed is gone.
Fast by construction
Each generator ships as its own route chunk, icons are bundled locally, and no third-party script is ever loaded.