How to Get a WireGuard Configuration for Octo Browser in Mullvad and Proton VPN

A WireGuard configuration is a .conf file with keys, DNS and server settings for creating a VPN tunnel for a separate profile.
It is used to connect a VPN not to the whole computer, but to a specific Octo Browser profile. During setup, pay attention to the private key in the file, DNS, WebRTC, UDP traffic and the difference between VPN and proxy usage. If you are choosing a route specifically for an antidetect profile, it helps to first understand VPN alternatives for profile work, because a VPN does not replace browser fingerprint and cookie isolation.
In Mullvad, the file is usually created through Downloads, WireGuard configuration. In Proton VPN, the current path is Downloads, WireGuard configuration inside the Proton VPN account. After generation, you receive a .conf file that can be uploaded to Octo Browser or pasted as text in the VPN tab. After import, do not skip the IP, DNS and WebRTC leak checks through UDP and QUIC, because this is where it most often becomes clear whether the profile really goes through the expected tunnel.
The main mistake here is simple: users treat VPN as a universal proxy replacement. A VPN changes the network route and encrypts traffic to the VPN server, while proxy servers for different tasks are more often used to bind separate accounts to a stable IP, geo or rotation setup. For one profile, a VPN can be convenient. For dozens of profiles, a more controlled setup is usually needed.
What a WireGuard configuration file contains
A WireGuard configuration file contains client and server parameters required to create a VPN tunnel. A standard .conf file has two blocks: [Interface] for your side of the connection and [Peer] for the VPN server.
In antidetect browser work, it is not enough to simply get the file. you need to understand what exactly you are passing into the profile. PrivateKey works as an access secret. Address sets the internal VPN address. DNS defines which DNS servers the profile should use to resolve domains. Endpoint shows the VPN server IP or domain and port, while AllowedIPs describes which traffic will go through the tunnel.
A typical structure looks like this:
| parameter | what it means | what to check |
|---|---|---|
PrivateKey | client private key | do not publish the file or send it in chats |
Address | internal address in the VPN network | do not reuse one file on different devices without a reason |
DNS | tunnel DNS servers | check DNS leaks after import |
PublicKey | VPN server public key | do not change it manually without understanding the configuration |
Endpoint | connection server and port | choose the geolocation for the profile task |
AllowedIPs | routes through the VPN | 0.0.0.0/0, ::/0 means a full tunnel |
If the file contains AllowedIPs = 0.0.0.0/0, ::/0, this configuration routes all IPv4 and IPv6 traffic through the tunnel. If only specific ranges are listed, part of the traffic may go directly. That is not always an error, but for a browser profile with an account it can create a mismatch between network routes.
Do not edit keys manually if the provider generated the file. One extra character in PrivateKey or PublicKey, and the tunnel will not come up. If you accidentally change DNS, an IP check may show the correct country, while DNS requests go through another route. As a result, the connection may look correct from the outside, even though the profile's network parameters are not consistent.
How to get a WireGuard configuration in Mullvad
In Mullvad, the configuration is created through the WireGuard generator in the account area. The service uses an account number instead of the classic email and password pair, so before you start, prepare the 16-digit account number and check that it has active access.
The current flow is this: you log in to the account, open Downloads, go to WireGuard configuration, create or import a key, choose a platform, country, city or specific server, and then download the file or ZIP archive. Mullvad also lets you choose DNS content blockers if they are needed for your scenario.
- open the Mullvad website and log in with the account number
- go to Downloads and choose WireGuard configuration
- click Generate key or import an existing private key
- choose the platform, for example Windows, if you need a standard file for import
- choose a country, city or specific server
- enable DNS content blockers only when you understand their effect on the site or account
- click Download file or Download zip archive
- unpack the archive if Mullvad generated several
.conffiles
Mullvad has a limit on the number of WireGuard keys for one account.

If the generation button is inactive, check the key list and delete only the key that is no longer used. Do not delete a key at random: all configurations created from it will stop working.
For Octo Browser, it is more convenient to use a separate VPN file for each stable working profile, or at least a separate key inside a clear naming scheme. If one file is used on several devices at the same time, the provider may see the same peer in multiple locations. Simultaneous use of one peer on different devices can make the connection unstable, including because of traffic routing issues.
How to get a WireGuard configuration in Proton VPN
In Proton VPN, the WireGuard file is created in the account through Downloads, WireGuard configuration. Proton asks you to name the configuration, choose a platform, VPN options and a server. After you click Create, the service generates a .conf file that can be downloaded.
There is an important difference from Mullvad here. In Proton VPN, the configuration is usually created for one selected server or a recommended server. If you need different geolocations for different profiles, create separate files with human-readable names, for example proton-us-profile-01.conf or proton-de-profile-02.conf. Later, you will not have to guess which file belongs to which profile.
- log in to the Proton VPN account
- open Downloads and choose WireGuard configuration
- enter the configuration name
- choose Platform
- set VPN options if they are available in your plan
- choose Server or leave the recommended server
- click Create
- wait for generation and click Download
On the free Proton VPN plan, some options may be unavailable. That is normal. Do not try to compensate for plan limits by manually editing the file if the issue is on the provider's plan or server policy side. A configuration file cannot create capabilities that do not exist in the account.

Before import, open the file in a text editor only to check its structure. Do not paste it into online formatters or third-party validators. The file contains a private key, so treat it like a password. If the file has already appeared in an open chat, task tracker or someone else's email, it is better to reissue the configuration.
How to add VPN to an Octo Browser profile
In Octo Browser, VPN is added in the profile connection settings almost the same way as a proxy. The difference is that for VPN you need to switch to the VPN tab and add the .conf file or paste its contents as text.
Before importing, decide whether this is a temporary connection for one profile or a configuration that should be saved in the Proxies and VPNs list. A temporary option is convenient for a one-time test. A saved VPN is useful when you plan to bind it to several profiles or templates. Still, do not confuse reuse on one device with simultaneous launches on different devices.
- open Octo Browser
- create a new profile or open an existing profile for editing
- find the Proxy / VPN block in the profile settings
- click to add a new connection
- switch to the VPN tab
- upload the
.conffile or paste its text into the configuration field - set a clear name, for example
Mullvad NL profile 07 - save the connection or leave it temporary for the current profile
- wait for the automatic outbound IP check
- launch the profile and check IP, DNS, WebRTC and timezone
If you use VPN and proxy at the same time, speed may drop. This is expected because traffic passes through an additional network route and needs extra processing. For a normal account login, this can be acceptable. For resource-heavy tasks, such as working with marketplaces, large ad accounts or pages with many scripts, latency quickly becomes noticeable.
This is also where the browser fingerprint matters. A VPN changes the IP and DNS route, but it does not make the browser fingerprint natural by itself. Canvas, WebGL, Client Hints, language, timezone and cookies remain separate layers. After connecting VPN to a profile, check not only the IP but also fingerprint checker bypass through WebRTC and proxies, especially if the profile has already been used before.
How VPN differs from proxy in an antidetect profile
VPN creates an encrypted tunnel from the profile to the VPN server, while a proxy acts as an intermediary for a specific traffic type or browser route. To the user, these can look similar because the site sees a different IP address. At the network level, however, these connection methods behave differently.

Proxies are more often chosen for multi-accounting, where each profile must be tied to a separate IP, geo, provider or network type. VPN is convenient when you need a full tunnel and encryption between the client and the VPN server, or when the service accepts a WireGuard .conf file without additional logins and passwords. At the same time, public VPN service IP addresses may be used by many users, so their reputation and history can differ from dedicated or residential proxies.
| criterion | WireGuard VPN | proxy |
|---|---|---|
| operating level | tunnel for the profile's network traffic | intermediary for HTTP, HTTPS, SOCKS5 or another protocol |
| access format | .conf file with keys and DNS | host, port, login, password or IP whitelist |
| typical use | full route through a VPN server | separate IP for an account or task group |
| error risk | DNS leak, duplicated keys, incorrect AllowedIPs | poor IP reputation, unstable rotation, geo mismatch |
| scaling | convenient for a small number of profiles | easier to control for many accounts |
There is no universally better option. If you run one profile with a clear geolocation and want a full tunnel, WireGuard can be convenient. If you have dozens of profiles, different platforms, teams, account warm-up and separate roles, proxies are usually easier to control.
How to check IP, DNS and leaks after connection
Post-import checks are always necessary. Successfully adding a .conf file does not yet mean the profile is not showing an old DNS server, local WebRTC candidate or mismatched timezone.
Start with a simple IP check. Open the Octo Browser profile, use an IP checking service and compare the country, city, ASN and provider with the server you selected in Mullvad or Proton VPN. Then check for a DNS leak. If the DNS server belongs to your local internet provider while the IP shows VPN, the configuration needs correction or regeneration.
- launch the profile with connected VPN
- check the IPv4 and IPv6 address
- open a DNS leak test and see whether your local provider's DNS is visible
- check WebRTC candidates in a browser fingerprint checking service
- compare timezone, browser language and IP geo
- open 2 or 3 heavy pages and assess loading stability
- restart the profile and repeat a short check
If the IP is correct but DNS does not match expectations, regenerate the configuration with the provider's DNS or check whether Octo Browser is applying its own DNS in the profile. If WebRTC shows a local address or another route, check the WebRTC settings in the profile. If pages load very slowly, try another server in the same region.

For working accounts, it is useful to keep a short change log: date, profile, provider, geolocation, .conf file name, IP/DNS/WebRTC check result. This log helps quickly identify what changed if an account requests additional verification: server, DNS, timezone, proxy, cookies or behavior.
How Afina helps manage profiles, proxies and checks
When the number of profiles, geolocations and accounts grows, network settings become harder to manage. A team needs to separate work environments, record profile purposes and control connection changes.
In Afina, browser profiles, cookies, browser fingerprint, proxies, tags, groups, team spaces and automation are combined in one workflow. For tasks where VPN is unnecessary or hard to scale, a profile can be built around proxies, isolated sessions and controlled fingerprint settings. For new users, there is also a separate explanation of profiles, fingerprints and proxies in an antidetect browser, so the network route is not confused with the fingerprint.
If a team tests different access routes, each profile in Afina has its own context, tags show its purpose, and automation plus API help reduce repeated manual actions. This material is provided for informational and educational purposes only.
Afina does not override platform rules and does not make VPN or proxy setups error-free. It provides a technical base for separating environments, avoiding account mix-ups and finding the cause faster when an IP, DNS or WebRTC check suddenly shows something unexpected.
DownloadFAQ — Frequently Asked Questions
What is a WireGuard configuration?
A WireGuard configuration is a .conf file with VPN tunnel parameters. It usually contains a private key, client address, DNS, server public key and Endpoint connection address.
Where can I find WireGuard configuration in Mullvad?
In Mullvad, it is located in the account area under Downloads, WireGuard configuration. There you can create a key, choose a server and download a .conf file or archive.
Where can I download a WireGuard configuration in Proton VPN?
In Proton VPN, log in to the account and open Downloads, WireGuard configuration. After choosing the platform, VPN options and server, click Create and then Download.
Can one WireGuard file be used for several profiles?
One WireGuard file can be assigned to several profiles on one device if it fits your workflow. Still, one peer with the same key should not be used on different devices at the same time, because it can make the connection unstable.
How does VPN differ from proxy for Octo Browser?
VPN creates a tunnel for the profile's network traffic, while a proxy sets an intermediary for a specific route. For large-scale multi-accounting, proxies are usually easier to control.
Why does the IP not change after importing WireGuard?
Most often, the profile did not apply VPN, the file has an error or the tunnel did not start. Check the connection status, endpoint, keys and restart the profile.
How can I check a DNS leak after connecting VPN?
Launch the profile and open a DNS leak test. If it shows the local provider's DNS, regenerate the configuration or check DNS in the profile settings.
Does WireGuard replace an antidetect browser?
No, WireGuard changes the network route, but it does not isolate fingerprint, cookies and behavioral signals. Accounts still need separate work with the browser profile.
