Remote device management without exposed ports

WireGuard central cloud management dashboard

Wantastic is a WireGuard central cloud management dashboard with secure remote Winbox access to MikroTik routers and OpenWrt devices behind firewalls and Starlink.

WireGuard meshMIT open sourceNo port forwarding

Features

WireGuard central cloud management dashboard

Wantastic is a WireGuard central cloud management dashboard with secure remote Winbox access to MikroTik routers and OpenWrt devices behind firewalls and Starlink.

Wantastic device fleet overview
Transmission protocol

Meet WUSP: USP semantics, WireGuard native.

Wantastic USP over WireGuard carries device-management operations inside the existing encrypted tunnel—without exposing another management socket or building a second trust layer.

WUSP protocol inspectorTunnel active

Control transmission path

Compact, typed and tunnel-only

USP operations

CRUD, operate, notify

WUSP envelope

Method + correlation ID

Control fragments

MTU-safe binary frames

WireGuard packet

Authenticated encrypted tunnel

GetSetAddDeleteOperateNotifyUploadDownload

Control transport

Noise fragmented datagram

Default payload

1200 bytes

Runtime model

TR-181 Device:2.20

WUSP is a purpose-built private transport for USP semantics in Wantastic. It is not a drop-in standard Broadband Forum USP Message Transfer Protocol.

Open-source edge client

One agent. Every edge. wantasticd.

A lightweight WireGuard mesh daemon for servers, desktops, OpenWrt routers and embedded IoT devices—with WUSP management and a factory-ready QR claim workflow.

Explore wantasticd

Cross-platform by design

One service model across modern operating systems, legacy init systems and embedded Linux.

Built for constrained devices

Headless claiming, BusyBox support and compact binaries make factory provisioning practical.

WUSP management included

Initialize USP-style device management over the same authenticated WireGuard tunnel.

root@factory-device — wantasticd genkey

/ # wantasticd genkey

Reused existing device claim key: /usrdata/wantastic/etc/device-claim-key.json

Public key: 0vNwglyJYpPOgsg9Q/AJgj7ke/48CUhWUXMQuRDG8yQ=

1

Stable device key

Generate once and preserve it in the manufacturer image.

2

Customer claim

Scan the printed QR to assign the device securely.

3

Mesh comes online

Create wantastic0 and establish the WireGuard peer.

4

Management starts

Load the runtime model and initialize WUSP.

Wantastic agent started successfully — System TUN + WUSP ready

Factory claim label

Print-ready manufacturer artwork

Example Wantastic device claim QR code
Wantastic ready

Scan to claim this device

Sign in to Wantastic, scan this code and the device configures its secure management tunnel automatically.

ID · 0vNwglyJYpPO…RDG8yQ

WireGuard securedWUSP enabled

The public claim key can be printed. Keep the private claim-key JSON on the device and never place it on the label.

Platforms and device classes

LinuxOpenWrtAlpinemacOSWindowsAndroidIoT / BusyBox

Published architecture targets

amd64arm64arm386mipsmipslemips64riscv64ppc64le
WireGuard central cloud management dashboard