NetBird
NetBird builds a secure WireGuard-based overlay network for devices and users, with SSO, MFA and granular access controls.
- GitHub stars
- 30k
- Last commit
- today
- Latest release
- v0.80.0
- Self-hosted
- Yes
- Hosted version
- Available

NetBird joins a configuration-free peer-to-peer private network with a central access control system on one platform. It creates a WireGuard-based overlay that connects machines over encrypted tunnels automatically, which avoids opening ports, writing complex firewall rules or running VPN gateways. It is written in Go and can be used for an organization or a home network. The repository metadata lists the license as Other.
Connectivity features include kernel WireGuard, peer-to-peer connections with relay fallback, routes to external networks, exit nodes, and private DNS with custom zones. For management and security there is an admin web UI, automatic peer discovery, SSO and MFA, identity provider integrations, groups and rules for access control, activity logging, traffic events and device posture checks. A public API, setup keys, a Terraform provider and a self-hosting quickstart script support automation. Clients cover Linux, macOS, Windows, Android and Android TV, and an agent network beta targets AI agents.
Key features
- WireGuard-based peer-to-peer overlay network
- Relay fallback when direct connections fail
- SSO, MFA and identity provider integrations
- Access control through groups and rules
- Private DNS, exit nodes and network routes
- Public API and Terraform provider
Pricing: The cloud Free plan covers up to 5 users. Team costs €6 and Business €12 per user per month, with a free trial; Enterprise is custom, and NetBird can also be self-hosted.


