# wg-easy (io.github.ni-c/wg-easy-mcp@0.5.0)

> Source: <https://mcpindex.ai/server/io-github-ni-c-wg-easy-mcp>
> Published: 2026-09-03 14:35:55+00:00

[← Index](/leaderboard)

# wg-easy

Administer wg-easy (WireGuard Easy) v15: manage VPN clients, configs, QR codes and server status

The current version, v0.5.0, was published to the official MCP registry on 2026-09-03. It is distributed as wg-easy-mcp on npm and as the Docker image ghcr.io/ni-c/wg-easy-mcp:0.5.0, filed under Other by this index, and declares 7 environment variables. Removals and unreachable sources are measured across every server this index tracks, contract drift across the servers that answer in consecutive snapshots; [the index's current counts](/stats) put this record in context.

## Using wg-easy in Claude, Cursor, Gemini CLI, Cline, or Zed?

MCP tool contracts can change remotely with no version bump. The mcpindex gate pins each contract and **HOLDs the call** when it drifts-before your agent acts. Zero credentials. This is not the package install for this server itself (use **Install this server** for that).

Rewrites your MCP host config so each server launches behind the gate. Inspect first: curl -fsSL https://mcpindex.ai/install.sh | less

```
uv tool install mcpindex-gate && mcpindex-config-wire
```

[method](/methodology)

Semantic screen found no manipulation pattern in the description. Conformance probe not yet run.

`mcpindex.integrity.description`

passINFOevidence“No malicious instructions found”via static_description

- - Semantic screen only - the deterministic conformance probe has not run on this server
- - Confidence is reported but not yet calibrated (v1)
- - Screen reads the tool description, not the live behavior
- - advisory
- - registry description only no input schema
- - screen model 8b
- - The registry listing (version, packages, links) changed after this screen ran - the description we assessed did not

Semantic screen: an LLM judge reads the tool description for hidden instructions (status PARTIAL). A pass means the description is not lying, not that the tool is safe: a high-capability tool with an honest description still warrants caution. The deterministic conformance probe has not been run on this server yet, so the screen here is semantic-only. Posture: advisory. Confidences are reported but not yet calibrated (calibrated=false at v1). Full verdict history is not shown on this page.

Own this server? [Screen its description →](/screen)

## That verdict was true at screening time (snapshot 2026-09-03).

Contracts can change after screening, with no version bump. The gate pins wg-easy’s tool contracts on first sight and holds any silent change before your agent acts - the check that keeps being true on Tuesday.

[See your first HOLD in 2 minutes →](/guides/install-the-gate-first-hold)

Related: [how to trust an MCP server](/guides/how-to-trust-an-mcp-server) · [screen before install](/guides/screen-mcp-server-before-install) · [silent contract drift](/guides/mcp-silent-contract-drift)

People vet a server before wiring it in. One line on your project site or docs answers that with an independent record: screening verdict, registry provenance, contract drift history. It stays current as new screens and drift events land.

```
[Independent trust record for wg-easy](https://mcpindex.ai/server/io-github-ni-c-wg-easy-mcp) - screening verdict, registry provenance, and contract drift monitoring.
<a href="https://mcpindex.ai/server/io-github-ni-c-wg-easy-mcp">Independent trust record for wg-easy</a> - screening verdict, registry provenance, and contract drift monitoring.
```

A live verdict badge for your README or listing. It reflects the current screen, links back here, and updates when the verdict does.

```
[![mcpindex](https://mcpindex.ai/api/v1/badge/io-github-ni-c-wg-easy-mcp)](https://mcpindex.ai/server/io-github-ni-c-wg-easy-mcp)
<a href="https://mcpindex.ai/server/io-github-ni-c-wg-easy-mcp"><img src="https://mcpindex.ai/api/v1/badge/io-github-ni-c-wg-easy-mcp" alt="mcpindex verdict" height="20" /></a>
```

`WG_EASY_URL`

Base URL of the wg-easy web UI, e.g. https://vpn.example.com:51821

`WG_EASY_USERNAME`

Username of a wg-easy admin account (2FA must be disabled)

`WG_EASY_PASSWORD`

Password of the wg-easy admin account

`WG_EASY_INSECURE_TLS`

Set to true to accept self-signed TLS certificates (scoped to the wg-easy connection)

`WG_EASY_READ_ONLY`

Set to true to register only the read tools (default: false)

`WG_EASY_ALLOW_TOOLS`

Comma-separated tool names or list_* prefixes to register; 'essential' selects a curated preset (default: all tools)

`WG_EASY_DENY_TOOLS`

Comma-separated tool names or list_* prefixes to remove from whatever WG_EASY_ALLOW_TOOLS left

`WG_EASY_URL`

Base URL of the wg-easy web UI, e.g. https://vpn.example.com:51821

`WG_EASY_USERNAME`

Username of a wg-easy admin account (2FA must be disabled)

`WG_EASY_PASSWORD`

Password of the wg-easy admin account

`WG_EASY_INSECURE_TLS`

Set to true to accept self-signed TLS certificates (scoped to the wg-easy connection)

`WG_EASY_READ_ONLY`

Set to true to register only the read tools (default: false)

`WG_EASY_ALLOW_TOOLS`

Comma-separated tool names or list_* prefixes to register; 'essential' selects a curated preset (default: all tools)

`WG_EASY_DENY_TOOLS`

Comma-separated tool names or list_* prefixes to remove from whatever WG_EASY_ALLOW_TOOLS left

[methodology](/methodology)

[AgentRoamai.agentroam/agentroam](/server/ai-agentroam-agentroam)

Buy travel eSIMs, gift cards and mobile top-ups with crypto — user confirms before any order.

[Authoryzeai.authoryze/authoryze](/server/ai-authoryze-authoryze)

Give your AI agent a spending limit: approval controls and single-use virtual cards.

[io.github.nice-one-code/NOC.McpServerio.github.nice-one-code/NOC.McpServer](/server/io-github-nice-one-code-noc-mcpserver)

MCP server exposing NiceOneCode's JSON-to-C# converter as an AI-callable tool.
