7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

5 alternatives ranked by real activity

Open-source Cloudflare Zero Trust alternatives

A curated, ranked list of the 5 best open-source alternatives to Cloudflare Zero Trust.

The best open-source alternative to Cloudflare Zero Trust is NetBird. If that doesn't suit you, other good options are OAuth2 Proxy, Pomerium, OpenZiti and Octelium.

Cloudflare Zero Trust alternatives are mainly networking & VPN tools, but some are also auth & identity tools and security tools. 5 of them shipped code in the last 30 days, 5 can be self-hosted, and 3 use a permissive licence.

Last updated October 2, 2026 · ranked by GitHub stars, growth and recent commits

NetBird

NetBird builds a secure WireGuard-based overlay network for devices and users, with SSO, MFA and granular access controls.

GitHub stars
30k
Last commit
today
Latest release
v0.80.0
Self-hosted
Yes
Hosted version
Available
netbird.ioNetBird homepage screenshot

NetBird joins a configuration-free peer-to-peer private network with a central access control system on one platform. It creates a WireGuard-based overlay that connects machines over encrypted tunnels automatically, which avoids opening ports, writing complex firewall rules or running VPN gateways. It is written in Go and can be used for an organization or a home network. The repository metadata lists the license as Other.

Connectivity features include kernel WireGuard, peer-to-peer connections with relay fallback, routes to external networks, exit nodes, and private DNS with custom zones. For management and security there is an admin web UI, automatic peer discovery, SSO and MFA, identity provider integrations, groups and rules for access control, activity logging, traffic events and device posture checks. A public API, setup keys, a Terraform provider and a self-hosting quickstart script support automation. Clients cover Linux, macOS, Windows, Android and Android TV, and an agent network beta targets AI agents.

Key features

  • WireGuard-based peer-to-peer overlay network
  • Relay fallback when direct connections fail
  • SSO, MFA and identity provider integrations
  • Access control through groups and rules
  • Private DNS, exit nodes and network routes
  • Public API and Terraform provider

Pricing: The cloud Free plan covers up to 5 users. Team costs €6 and Business €12 per user per month, with a free trial; Enterprise is custom, and NetBird can also be self-hosted.

Read more about NetBirdWebsite GitHub

OAuth2 Proxy

OAuth2 Proxy is a reverse proxy and middleware that protects web apps with OAuth2 and OpenID Connect sign-in from many identity providers.

GitHub stars
15k
Last commit
yesterday
Latest release
v7.15.5
Licence
MIT
Self-hosted
Yes
oauth2-proxy.github.ioOAuth2 Proxy homepage screenshot

OAuth2 Proxy is an open-source tool that adds OAuth2 and OIDC authentication to web applications. It can run as a standalone reverse proxy that intercepts requests and redirects users to an identity provider, or as middleware plugged into an existing reverse proxy or load balancer so it handles authentication for several applications.

It works with a generic OIDC client and also has specific implementations for providers such as Google, Microsoft Entra ID, GitHub and login.gov. Provider-specific code lets it extract details such as preferred usernames and groups, which can then be passed to upstream applications as HTTP headers. This avoids building login logic into each internal app.

OAuth2 Proxy is written in Go and released under the MIT license. Compiled binaries are published on GitHub for all major architectures and some less common ones, and container images are based on distroless since version 7.6.0, with Alpine-based images still available. Nightly images are built from the main branch.

Key features

  • Standalone reverse proxy or middleware mode
  • OAuth2 and OIDC authentication
  • Provider support for Google, Entra ID and GitHub
  • User details forwarded as HTTP headers
  • Binaries for many architectures
  • Distroless container images

Pricing: Free and open source under the MIT license.

Read more about OAuth2 ProxyWebsite GitHub

Pomerium

An identity and context-aware access proxy written in Go that secures internal apps and services without a corporate VPN.

GitHub stars
5k
Last commit
today
Latest release
v0.33.3
Licence
Apache-2.0
Self-hosted
Yes
Hosted version
Available
pomerium.comPomerium homepage screenshot

Pomerium is an identity and context-aware reverse proxy that makes secure, clientless connections to internal web apps and other services. The goal is to protect internal resources without asking users to connect through a corporate VPN.

According to the project, clientless access makes it easier to adopt, running tunnel-free and close to your apps and services makes it faster, and verifying each action before it executes makes it safer. Context-aware policies can draw on data from several sources, so access decisions can reflect your organization's own needs. Repository topics point to zero-trust, BeyondCorp-style, identity-aware proxy and IAM use cases.

Pomerium is written in Go and licensed under Apache-2.0. Teams that want a hosted control plane and a management GUI can look at Pomerium Zero, while the open-source proxy can be run on your own infrastructure. Documentation and tutorials are available on pomerium.com.

Key features

  • Identity-aware reverse proxy
  • Clientless access to internal apps
  • Per-request verification of every action
  • Context-aware access policies
  • Tunnel-free deployment near your services
  • Hosted control plane via Pomerium Zero

Pricing: Free Personal plan. Business costs $7 per user per month billed annually, with a free trial; Enterprise for fully self-hosted deployments is quoted.

Read more about PomeriumWebsite GitHub

OpenZiti

OpenZiti's core project, an open-source zero-trust networking platform that authenticates every connection with cryptographic identity and keeps services hidden.

GitHub stars
4.4k
Last commit
today
Latest release
v2.0.6
Licence
Apache-2.0
Self-hosted
Yes
Hosted version
Available

Ziti is the parent project of OpenZiti, an open-source zero-trust networking platform that makes network services invisible to unauthorized users. Every connection, whether from a person, service, device or workload, is authenticated with a cryptographic identity, authorized by policy and encrypted end to end.

It works with existing applications through lightweight tunnelers that need no code changes, and with new applications through embedded SDKs for the strongest zero-trust model. The README lists use cases such as replacing VPNs with per-service authorization, hiding APIs and services so they have no listening ports, and giving IoT devices and other non-human workloads their own identities.

OpenZiti was created and sponsored by NetFoundry and is licensed under Apache-2.0. The code is written in Go, the README describes three deployment models, and a managed solution is available for teams that prefer not to operate it themselves.

Key features

  • Zero-trust overlay networking
  • Cryptographic identity for every connection
  • End-to-end encryption
  • Tunnelers for apps without code changes
  • Embedded SDKs for new applications
  • Policy-based authorization per service
  • Dark services with no listening ports
Read more about OpenZitiWebsite GitHub

Octelium

Octelium is a self-hosted zero trust access platform that can act as a VPN, ZTNA system, API and AI gateway, tunnel service or PaaS on Kubernetes.

GitHub stars
4.1k
Last commit
today
Latest release
v0.43.0
Licence
AGPL-3.0
Self-hosted
Yes
octelium.comOctelium homepage screenshot

Octelium is a self-hosted, open-source platform that unifies zero trust secure access under one system. It is flexible enough to act as a zero-config remote access VPN, a Zero Trust Network Access and BeyondCorp-style platform, an alternative to ngrok and Cloudflare Tunnel, an API gateway, an AI and LLM gateway, and an infrastructure for building MCP gateways and AI agent access.

Repository topics list attribute-based access control, policy as code, WireGuard, QUIC, SSO, multi-factor authentication, OpenTelemetry and SSH access. The README includes use cases, a feature overview, a guide to try it in a Codespace, CLI installation and instructions to install your first cluster. It is written in Go and runs on Kubernetes. It is compared to ngrok, Cloudflare Tunnel and Apigee for different roles.

Octelium is licensed under AGPL-3.0 and you operate the cluster yourself. It suits platform and security teams, homelab users and developers who want to replace several access, tunnel and gateway tools with one self-hosted system.

Key features

  • Zero-config remote access VPN
  • ZTNA and BeyondCorp-style access
  • API, AI and MCP gateway capabilities
  • Tunnel service as ngrok alternative
  • Attribute-based policy as code
  • Runs on Kubernetes clusters

Pricing: Free and open source under AGPL-3.0.

Read more about OcteliumWebsite GitHub

Cloudflare Zero Trust alternatives: questions

What is the best open-source alternative to Cloudflare Zero Trust?
NetBird is the top-ranked open-source alternative to Cloudflare Zero Trust on Enlisted: NetBird builds a secure WireGuard-based overlay network for devices and users, with SSO, MFA and granular access controls. Other strong options are OAuth2 Proxy, Pomerium, OpenZiti and Octelium.
Are these Cloudflare Zero Trust alternatives free?
All 5 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer. 3 also offer a paid or managed cloud version if you'd rather not host it yourself.
How is this list of Cloudflare Zero Trust alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 5 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all