Endpoints
endpoints hold protocol stacks that are inbound and outbound at once: a WireGuard or Tailscale instance, for example, both accepts connections arriving through the tunnel and originates connections into it. The entry shape is the same flat envelope as inbounds and outbounds — type / tag plus the selected type's own fields at the same level.
Envelope
| Field | Type | Default | Allowed values | Description |
|---|---|---|---|---|
type | string | — | wireguard | openconnect | openvpn-client | openvpn-server | tailscale | Endpoint type. Selects which option struct the rest of the object is decoded into. |
tag | string | — | — | Unique name for this endpoint. Usable wherever an outbound tag is expected, and matchable by route rules on the inbound side. |
Source: option/endpoint.go:18-22 · pinned at v1.14.2 (af6e64c)
Per-type fields are documented on WireGuard and Tailscale. OpenVPN and OpenConnect are documented on OpenVPN and OpenConnect.
Minimal example
json
{
"endpoints": [
{
"type": "wireguard",
"tag": "wg-ep",
"address": ["10.0.0.2/32"],
"private_key": "<base64-private-key>",
"peers": [
{
"address": "wg.example.com",
"port": 51820,
"public_key": "<base64-public-key>",
"allowed_ips": ["0.0.0.0/0"]
}
]
}
],
"route": { "final": "wg-ep" }
}Notes
- WireGuard is an endpoint; there is no
wireguardoutbound. The same struct covers both directions of the tunnel. wireguardrequires a build with thewith_wireguardtag,tailscaleone withwith_tailscale,openvpn-client/openvpn-serverone withwith_openvpn, andopenconnectone withwith_openconnect(official release binaries include all four).openvpn-client/openvpn-serverinteroperate with standard OpenVPN servers and clients, including static-key mode and legacy ciphers and digests. The companionopenvpnDNS server type uses the DNS options the OpenVPN server pushes.openconnectis client-only and talks to Cisco AnyConnect, GlobalProtect, Fortinet, F5, Pulse Connect Secure and Juniper Network Connect servers; theopenconnectDNS server type uses its pushed split-DNS resolvers. Interactive logins (e.g. SSO) go through the graphical clients or the sing-box Dashboard.- TCP, UDP and ICMP connections from L3 inbounds (TUN, WireGuard, Tailscale) can be forwarded to WireGuard and Tailscale endpoints directly at L3 during pre-match, without L3-to-L4 translation.
- Route rules can match traffic coming out of an endpoint the same way they match an inbound tag.
Cross-core notes
- Xray-core keeps WireGuard as a normal inbound or outbound protocol (
protocol: "wireguard"withIsClientdecided by position). See Xray WireGuard. - mihomo models WireGuard as a proxy (outbound) only. See mihomo WireGuard.
Source: option/endpoint.go:18-22 · v1.14.2 (af6e64c)
