OpenZiti
An open-source zero trust networking platform that connects services by identity instead of IP address.
These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.
About OpenZiti
OpenZiti builds an overlay network where clients reach named services using enrolled identities rather than IP addresses or public hostnames, so services need no open inbound ports. You run the controller and routers yourself and manage them through the Ziti console.
Connectivity can be added to existing apps through tunnellers or embedded directly with SDKs for Python, Go, Java, JavaScript, C#, C and Swift. It is developed by NetFoundry and suits teams replacing traditional VPN access with identity-based access.
Strengths
- Services stay hidden with no open inbound ports
- Identity-based access instead of network-level access
- SDKs to embed connectivity directly in applications
- Self-hostable controller and routers
Limitations
- More complex to deploy than a simple mesh VPN
- Aimed at developers and administrators rather than home users
Details
- Pricing
- FreeFree and open source to self-host; NetFoundry sells a hosted version.
- License
- Open source, license not stated
- Developer
- NetFoundry
- Platforms
- Linux, Self-hosted, Command line
- How it runs
- Downloadable app, Self-hosted
- Account
- Not required
- Best suited for
- Teams replacing VPN access with self-hosted zero trust networking
- Categories
- VPN, Network tools, IT administration
- Last verified
- Added
- Provenance
- Facts checked against the developer's own pages and store listings, 1 sources on file.
Alternatives to OpenZiti
Compare allSoftware that can replace OpenZiti for an important use case, and what changes if you switch.
Twingate
An identity-based network access service meant to replace a traditional VPN for teams.
Twingate is a hosted identity-based access service with a free tier for small teams, removing self-hosting but making you depend on a closed commercial service.
Firezone
WireGuard-based zero trust access with self-hosted gateways.
Firezone uses WireGuard for zero trust access with identity provider policies and self-hosted gateways under Apache-2.0, but its control plane cannot be fully self-hosted.
Octelium
A self-hosted zero trust access platform that can act as a remote access VPN or ZTNA gateway.
Octelium is a self-hosted AGPL and Apache licensed platform combining VPN, ZTNA and gateway roles, and can replace ngrok-style tunnels, though it requires operating a cluster.
NetBird
A WireGuard-based mesh network with single sign-on, multi-factor authentication and access policies, self-hostable or managed.
NetBird provides a WireGuard mesh with SSO, MFA and group-based access rules, self-hostable under the AGPL, and is simpler to deploy than application-embedded connectivity.
Tailscale
Builds a private network between your own devices using WireGuard, without opening ports or running a server.
Tailscale offers WireGuard networking with central access rules and clients for all major platforms, but relies on a hosted coordination server and network-level access.
defguard
A self-hosted WireGuard VPN platform with built-in identity management and multi-factor authentication per connection.
defguard is a self-hosted WireGuard VPN with per-connection MFA and LDAP, Active Directory and OIDC integration, keeping a VPN model rather than hiding services by identity.
OpenZiti as an alternative
Listings that name OpenZiti as an alternative.
Pomerium
An identity-aware reverse proxy that gives secure access to internal applications without a VPN.
OpenZiti is an open source zero trust networking platform that hides services with no inbound ports and offers SDKs, but it is more complex to deploy.
Teleport
An identity-based access platform for infrastructure such as servers, Kubernetes, databases and desktops.
OpenZiti is an open-source zero trust networking platform with a self-hostable controller and SDKs to embed connectivity in applications, and it is more complex to deploy.
Similar software
Related functionality, not necessarily a direct replacement.
nebula
Connect devices through an encrypted overlay network.
ZeroTier One
Puts machines anywhere in the world on the same virtual Ethernet network, as if they were plugged into one switch.
OpenVPN Access Server
A self-hosted business VPN server with a web admin interface, free for two simultaneous connections.
Pritunl
A self-hosted VPN server for OpenVPN, WireGuard and IPsec, managed through a web interface.
Netmaker
Self-hosted platform for building and managing WireGuard mesh networks.
headscale
A self-hosted, open-source implementation of the Tailscale control server, so your mesh VPN does not depend on a company.