Netbird implemented something like this in their client. If native wireguard-connection fails they access a relay to tunnel wireguard-traffic through. That works automatically (fallback). Maybe a "standard" for such a relay-service could be used - for example check their implementation (which I expect should be rather slim; mainly tunneling wireguard-udp back and forth).
https://docs.netbird.io/about-netbird/ports-and-firewalls
https://github.com/netbirdio/netbird
https://docs.netbird.io/about-netbird/ports-and-firewalls
https://github.com/netbirdio/netbird
"