7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

6 alternatives ranked by real activity

Open-source ngrok alternatives

A curated, ranked list of the 6 best open-source alternatives to ngrok.

The best open-source alternative to ngrok is frp. If that doesn't suit you, other good options are Pangolin, Rathole, Zrok and OpenZiti.

ngrok alternatives are mainly networking & VPN tools. 5 of them shipped code in the last 30 days, 6 can be self-hosted, and 4 use a permissive licence.

Last updated October 2, 2026 · ranked by GitHub stars, growth and recent commits

frp

A fast reverse proxy that makes services on a machine behind a NAT or firewall reachable from the internet over TCP, UDP, HTTP and HTTPS.

GitHub stars
110k
Last commit
18 days ago
Latest release
v0.71.0
Licence
Apache-2.0
Self-hosted
Yes

frp is an open-source reverse proxy that makes a server sitting behind a NAT or firewall reachable from the internet. It supports TCP and UDP traffic as well as HTTP and HTTPS, so requests can be forwarded to internal services using a domain name. It also offers a peer-to-peer connect mode. The project is written in Go and licensed under Apache-2.0.

Typical setups include reaching a computer on a home or office LAN over SSH, sharing one port between several SSH services, serving internal web apps on custom domains, forwarding DNS queries and Unix domain sockets, exposing a simple HTTP file server, enabling HTTPS for a local service, and exposing a service privately. Configuration is handled through files, with support for environment variables and splitting settings across several files.

Operations features include a server dashboard, a client admin UI, dynamic proxy management, Prometheus monitoring and client authentication. A server component runs on a machine with a public address, and a client runs beside your internal service. It suits developers, homelab users and small teams who want to host their own tunnel instead of using a commercial tunneling service.

Key features

  • Reverse proxy for TCP, UDP, HTTP and HTTPS
  • Peer-to-peer connect mode
  • Custom domain routing for internal web services
  • Server dashboard and client admin UI
  • Prometheus monitoring support
  • Authentication for connecting clients

Pricing: Free and open source under the Apache-2.0 license.

Read more about frpGitHub

Pangolin

An open-source SASE platform on WireGuard combining zero-trust VPN and proxy access, privileged access control and an AI gateway that understands identity.

GitHub stars
23k
Last commit
yesterday
Latest release
1.24.0
Self-hosted
Yes
Hosted version
Available
pangolin.netPangolin homepage screenshot

Pangolin is an open-source secure access service edge platform built on WireGuard. It aims to connect and protect users wherever they are by combining networking and security in one system: a zero-trust VPN, a zero-trust reverse proxy, privileged access control and a gateway for AI workloads that is aware of user identity, with one identity and policy model underneath.

The project compares its idea to commercial platforms such as Cloudflare One, Zscaler and Prisma, but argues that it is open, self-hostable and light enough to be easy to deploy. Legacy SASE products, it says, are heavy, closed and cloud-locked. Topics include reverse proxy, single sign-on, OIDC, SSH, tunneling, NAT traversal and remote access. Because the source is open to inspection, you can verify how traffic and access decisions are handled.

You can use Pangolin Cloud at app.pangolin.net or run it yourself. The repository's license is listed as 'Other' on GitHub, because it mixes open-source and enterprise components, so check the terms. It suits homelab users, small companies and IT teams that want zero-trust remote access without a large vendor contract.

Key features

  • Zero-trust VPN built on WireGuard
  • Zero-trust reverse proxy
  • Privileged access management
  • Identity-aware AI gateway
  • Single identity and policy model
  • Cloud or self-hosted deployment

Pricing: Basic is free for up to 5 users. Team costs $4 and Business $9 per user per month with a 10-day free trial; Enterprise is custom. Pangolin can run in the cloud or self-hosted.

Rathole

Rathole is a reverse proxy for NAT traversal written in Rust that exposes services behind a firewall through a public server, as an alternative to frp and ngrok.

GitHub stars
14k
Last commit
1 mo ago
Latest release
v0.5.0
Licence
Apache-2.0
Self-hosted
Yes

Rathole is a reverse proxy for NAT traversal, written in Rust. Like frp and ngrok, it exposes a service on a device behind a NAT to the internet through a server that has a public IP, for example to reach a home NAS over SSH from outside the network.

The README highlights several design points. It claims higher throughput than frp and more stability under many connections, with benchmarks provided, and low memory use that allows a small binary suitable for embedded devices such as routers. Each service requires a token, and server and client each hold their own configuration. Encryption can be set up with the optional Noise Protocol without self-signed certificates, and TLS is also supported. Services can be added or removed by hot-reloading the configuration file.

Rathole is licensed under Apache-2.0. Usage is similar to frp, with the difference that a service is configured separately on the client and server sides. Binaries are published on the release page, you can build from source, and a Docker image is available.

Key features

  • Reverse proxy for NAT traversal
  • Mandatory per-service tokens
  • Optional Noise Protocol encryption
  • TLS support
  • Hot reload of configuration
  • Small binary for embedded devices

Pricing: Free and open source under the Apache-2.0 licence.

Read more about RatholeGitHub

Zrok

zrok is an open-source tool for sharing web services, files and network resources securely over the internet without firewall or port-forwarding changes.

GitHub stars
4.7k
Last commit
3 days ago
Latest release
v2.0.6
Licence
Apache-2.0
Self-hosted
Yes
Hosted version
Available
zrok.ioZrok homepage screenshot

zrok lets you share web services, files and network resources with other people, whether they are across the internet or on a private network. It is built on zero-trust networking, so it works through firewalls and NAT without port forwarding or other network changes, and it behaves like a secure reverse proxy and peer-to-peer sharing tool.

Getting started takes a few steps: install zrok, create an account with the invite command, using the free zrok.io service, and enable sharing on your machine. After that you can publish a local web app, share a folder or expose a private resource to selected users. The project is part of the OpenZiti ecosystem and written in Go.

zrok is licensed under Apache-2.0. You can use the hosted zrok.io service or run your own zrok instance, which suits developers who need to expose a local service temporarily, teams sharing files securely and homelab owners who want remote access without opening ports.

Key features

  • Share web services without port forwarding
  • File sharing over zero-trust networking
  • Works through firewalls and NAT
  • Public and private share modes
  • Free hosted zrok.io service
  • Self-hostable zrok server

Pricing: The hosted service is free with a 5 GB daily allowance and no card required, and Zrok can be self-hosted at no cost. Commercial options with SLAs are quoted by NetFoundry.

OpenZiti

OpenZiti's core project, an open-source zero-trust networking platform that authenticates every connection with cryptographic identity and keeps services hidden.

GitHub stars
4.4k
Last commit
today
Latest release
v2.0.6
Licence
Apache-2.0
Self-hosted
Yes
Hosted version
Available

Ziti is the parent project of OpenZiti, an open-source zero-trust networking platform that makes network services invisible to unauthorized users. Every connection, whether from a person, service, device or workload, is authenticated with a cryptographic identity, authorized by policy and encrypted end to end.

It works with existing applications through lightweight tunnelers that need no code changes, and with new applications through embedded SDKs for the strongest zero-trust model. The README lists use cases such as replacing VPNs with per-service authorization, hiding APIs and services so they have no listening ports, and giving IoT devices and other non-human workloads their own identities.

OpenZiti was created and sponsored by NetFoundry and is licensed under Apache-2.0. The code is written in Go, the README describes three deployment models, and a managed solution is available for teams that prefer not to operate it themselves.

Key features

  • Zero-trust overlay networking
  • Cryptographic identity for every connection
  • End-to-end encryption
  • Tunnelers for apps without code changes
  • Embedded SDKs for new applications
  • Policy-based authorization per service
  • Dark services with no listening ports

Octelium

Octelium is a self-hosted zero trust access platform that can act as a VPN, ZTNA system, API and AI gateway, tunnel service or PaaS on Kubernetes.

GitHub stars
4.1k
Last commit
today
Latest release
v0.43.0
Licence
AGPL-3.0
Self-hosted
Yes
octelium.comOctelium homepage screenshot

Octelium is a self-hosted, open-source platform that unifies zero trust secure access under one system. It is flexible enough to act as a zero-config remote access VPN, a Zero Trust Network Access and BeyondCorp-style platform, an alternative to ngrok and Cloudflare Tunnel, an API gateway, an AI and LLM gateway, and an infrastructure for building MCP gateways and AI agent access.

Repository topics list attribute-based access control, policy as code, WireGuard, QUIC, SSO, multi-factor authentication, OpenTelemetry and SSH access. The README includes use cases, a feature overview, a guide to try it in a Codespace, CLI installation and instructions to install your first cluster. It is written in Go and runs on Kubernetes. It is compared to ngrok, Cloudflare Tunnel and Apigee for different roles.

Octelium is licensed under AGPL-3.0 and you operate the cluster yourself. It suits platform and security teams, homelab users and developers who want to replace several access, tunnel and gateway tools with one self-hosted system.

Key features

  • Zero-config remote access VPN
  • ZTNA and BeyondCorp-style access
  • API, AI and MCP gateway capabilities
  • Tunnel service as ngrok alternative
  • Attribute-based policy as code
  • Runs on Kubernetes clusters

Pricing: Free and open source under AGPL-3.0.

ngrok alternatives: questions

What is the best open-source alternative to ngrok?
frp is the top-ranked open-source alternative to ngrok on Enlisted: A fast reverse proxy that makes services on a machine behind a NAT or firewall reachable from the internet over TCP, UDP, HTTP and HTTPS. Other strong options are Pangolin, Rathole, Zrok and OpenZiti.
Are these ngrok alternatives free?
All 6 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer. 3 also offer a paid or managed cloud version if you'd rather not host it yourself.
How is this list of ngrok alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 5 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all