Your profiles 5 MIN READ

WireGuard & AmneziaWG

Find a WireGuard configuration from your VPN provider or home router, check AmneziaWG compatibility and import it onto Apple TV.

In the appProfiles → Add VPN profile → Review

Contents Browse all guides →

Match both ends of the connection

WireGuard creates an encrypted tunnel using peer keys. AmneziaWG adds options that change how tunnel packets appear on the network. Your VPN server must support the protocol and parameters in the client profile.

Changing a profile’s label does not convert a WireGuard server into an AmneziaWG server. Start with the client configuration exported by your provider or server administrator.

Find your configuration

WireFuse connects Apple TV using a WireGuard or compatible AmneziaWG client configuration. A provider login, an OpenVPN file or a router’s VPN client setting is not a substitute for that profile.

The examples below link to official configuration instructions. They confirm a documented WireGuard setup path, not a WireFuse test or partnership with every service. Plan, device and firmware requirements still apply.

VPN providers

Provider Where to start
Mullvad Use the WireGuard configuration download linked under “Unable to use the app?”.
IVPN Open the WireGuard configuration generator in your Client Area.
Proton VPN In your account, open Downloads → WireGuard configuration and download the generated .conf file.
Surfshark With an active subscription, use Manual setup → WireGuard, create a key pair and download a location’s configuration.

These links explain how to obtain the profile; use WireFuse’s import guide for the Apple TV steps. Provider-specific features in another app are not automatically included in an exported configuration.

Routers and home servers

Server What to prepare
Firewalla On a supported box, enable the WireGuard VPN server and export a client profile.
pfSense Follow the remote-access recipe to configure the server, peer and matching client settings.
OPNsense Follow the Road Warrior setup and use the peer generator for your client configuration.
UniFi On a supported gateway, create a WireGuard VPN server, add a client and download its configuration.

For access back home, the router must act as the VPN server. A router connecting outward to a commercial VPN is a different setup. Check the endpoint, firewall and return routes using the home-network guide.

Your provider isn’t listed? Check whether it exports a standard WireGuard or compatible AmneziaWG client configuration. You can try it with WireFuse’s free three-minute connections before choosing Lifetime access.

Official instructions checked on 27 September 2026.

Keep the supplied options

Import the complete configuration, including the AmneziaWG obfuscation settings when present. WireFuse validates supported fields before saving.

An unsupported option or invalid value is information about compatibility. Do not remove fields at random to make the file pass validation: the server may require them for a successful handshake.

AmneziaWG exports can vary with the server and tool version. If an export is rejected, ask the provider which version and configuration format it expects. There is no claim here that every future AmneziaWG field is supported.

Details worth checking

Detail Why it matters
Client private key Identifies this client; keep it private
Peer public key Must identify the intended server peer
Preshared key, if used Must match the server’s value for this client
Endpoint and UDP port Must reach the correct VPN service
AmneziaWG parameters Must be compatible with the server’s settings
Addresses and routes Must match the client and network configuration

After importing

Connect and check server verification and the latest handshake. A saved file proves that the configuration passed local validation; it does not prove the remote server is available.

If there is no recent handshake, check the endpoint, server availability and keys. See connection troubleshooting for the order of checks.

Network limits still apply

Neither protocol guarantees access on every network. Firewalls, provider restrictions and the remote server’s routing can affect the result. A VPN connection also does not automatically make local discovery or a streaming service available.

Still stuck? Contact support.