wireguard_add_peer
Add a WireGuard peer to a MikroTik interface by defining allowed addresses, remote public key, and optional endpoint or client config.
Instructions
Add a WireGuard peer. This server never generates keys; all values come from the user.
allowed_address (REQUIRED, ask the user): addresses this peer uses/routes, comma-separated, '/prefix' or dotted mask. E.g. '10.10.10.2/32' (phone/laptop) or '10.10.10.2/32, 192.168.50.0 255.255.255.0' (remote site + its LAN). Validated: format, overlap with other peers, inside the tunnel subnet, not the router's own IP. public_key: the REMOTE peer's public key (shown in its WireGuard app / remote router). Leave empty to have the user type it in a local popup on apply. Checked: format, not this router's own key, not already used on this interface. use_preshared_key: on apply the preshared key is entered in a local popup (or via preshared_key). Never ask the user to paste it in chat. endpoint: 'host:port' of the remote side for site-to-site. Omit for roaming clients. write_client_config: also save a .conf for the remote device. Requires (ask the user): client_allowed_ips: '0.0.0.0/0' for full tunnel, or specific subnets (split tunnel); server_endpoint: public IP/hostname (and :port) the client connects to. On apply the user may enter the client's private key in a popup to get a complete config + QR; it is checked against public_key. If left empty, a template is saved. client_dns: optional DNS server IP(s) for the client config.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | No | router | |
| site | No | ||
| comment | No | ||
| dry_run | No | ||
| endpoint | No | ||
| interface | Yes | ||
| client_dns | No | ||
| public_key | No | ||
| preshared_key | No | ||
| allowed_address | Yes | ||
| server_endpoint | No | ||
| rollback_minutes | No | ||
| use_preshared_key | No | ||
| client_allowed_ips | No | ||
| write_client_config | No | ||
| persistent_keepalive | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |