@jonah Wireguard is absolutely excellent, you should look into it.
They can see your traffic with just the public key, but they would have no way to imitate you (or allow others to imitate you) without the private key. It is not a deal breaker as long as it is fixed in the long run, I assume they built the keygen tool this way to make it easy to use, but it is not ideal and is a security vulnerability.