6,598 open-source and SaaS tools, with GitHub stats refreshed every day.

12 alternatives ranked by real activity

Open-source Twingate alternatives

A curated, ranked list of the 12 best open-source alternatives to Twingate.

The best open-source alternative to Twingate is Tailscale. If that doesn't suit you, other good options are NetBird, Pangolin, Nebula and ZeroTier.

Twingate alternatives are mainly Networking & VPN tools, but some are also Security. 12 of them shipped code in the last 30 days, 12 can be self-hosted, and 5 use a permissive licence.

Last updated October 2, 2026 · ranked by GitHub stars, growth and recent commits

Tailscale

Tailscale builds private WireGuard-based networks between your devices; this repository holds the open-source client daemon and CLI.

GitHub stars
37k
Last commit
today
Latest release
v1.102.5
Licence
BSD-3-Clause
Hosted version
Available
tailscale.comTailscale homepage screenshot

Tailscale makes private networks between devices using the WireGuard protocol, with sign-in handled by existing identity providers and two-factor authentication. The GitHub repository contains most of the company's open-source code, notably the tailscaled daemon and the tailscale command-line tool. It is published under the BSD-3-Clause license and written in Go.

The daemon runs on Linux, Windows and macOS, with partial support on FreeBSD and OpenBSD. The iOS and Android apps reuse this code, while the graphical wrappers for some non-open platforms are not open source, so the full product is a mix of open and proprietary parts. Packages for many distributions are served from the project's package site, and the code can be built from source with the latest Go release. The service itself is hosted by Tailscale.

Key features

  • WireGuard-based private device networking
  • tailscaled daemon and tailscale CLI
  • Sign-in through SSO and two-factor authentication
  • Clients for Linux, Windows, macOS, iOS and Android
  • Packages for Synology, QNAP and Debian-style distros
  • Client source code under BSD-3-Clause

Pricing: Personal is free forever for up to 6 users. Standard costs $8 and Premium $18 per user per month; Enterprise is custom and quoted through sales.

NetBird

NetBird builds a secure WireGuard-based overlay network for devices and users, with SSO, MFA and granular access controls.

GitHub stars
30k
Last commit
today
Latest release
v0.80.0
Self-hosted
Yes
Hosted version
Available
netbird.ioNetBird homepage screenshot

NetBird joins a configuration-free peer-to-peer private network with a central access control system on one platform. It creates a WireGuard-based overlay that connects machines over encrypted tunnels automatically, which avoids opening ports, writing complex firewall rules or running VPN gateways. It is written in Go and can be used for an organization or a home network. The repository metadata lists the license as Other.

Connectivity features include kernel WireGuard, peer-to-peer connections with relay fallback, routes to external networks, exit nodes, and private DNS with custom zones. For management and security there is an admin web UI, automatic peer discovery, SSO and MFA, identity provider integrations, groups and rules for access control, activity logging, traffic events and device posture checks. A public API, setup keys, a Terraform provider and a self-hosting quickstart script support automation. Clients cover Linux, macOS, Windows, Android and Android TV, and an agent network beta targets AI agents.

Key features

  • WireGuard-based peer-to-peer overlay network
  • Relay fallback when direct connections fail
  • SSO, MFA and identity provider integrations
  • Access control through groups and rules
  • Private DNS, exit nodes and network routes
  • Public API and Terraform provider

Pricing: The cloud Free plan covers up to 5 users. Team costs €6 and Business €12 per user per month, with a free trial; Enterprise is custom, and NetBird can also be self-hosted.

Pangolin

An open-source SASE platform on WireGuard combining zero-trust VPN and proxy access, privileged access control and an AI gateway that understands identity.

GitHub stars
23k
Last commit
yesterday
Latest release
1.24.0
Self-hosted
Yes
Hosted version
Available
pangolin.netPangolin homepage screenshot

Pangolin is an open-source secure access service edge platform built on WireGuard. It aims to connect and protect users wherever they are by combining networking and security in one system: a zero-trust VPN, a zero-trust reverse proxy, privileged access control and a gateway for AI workloads that is aware of user identity, with one identity and policy model underneath.

The project compares its idea to commercial platforms such as Cloudflare One, Zscaler and Prisma, but argues that it is open, self-hostable and light enough to be easy to deploy. Legacy SASE products, it says, are heavy, closed and cloud-locked. Topics include reverse proxy, single sign-on, OIDC, SSH, tunneling, NAT traversal and remote access. Because the source is open to inspection, you can verify how traffic and access decisions are handled.

You can use Pangolin Cloud at app.pangolin.net or run it yourself. The repository's license is listed as 'Other' on GitHub, because it mixes open-source and enterprise components, so check the terms. It suits homelab users, small companies and IT teams that want zero-trust remote access without a large vendor contract.

Key features

  • Zero-trust VPN built on WireGuard
  • Zero-trust reverse proxy
  • Privileged access management
  • Identity-aware AI gateway
  • Single identity and policy model
  • Cloud or self-hosted deployment

Pricing: Basic is free for up to 5 users. Team costs $4 and Business $9 per user per month with a 10-day free trial; Enterprise is custom. Pangolin can run in the cloud or self-hosted.

Nebula

Nebula is an open-source overlay networking tool that connects computers anywhere using peer-to-peer, certificate-based encrypted tunnels.

GitHub stars
18k
Last commit
today
Latest release
v1.11.2
Licence
MIT
Self-hosted
Yes

Nebula is an overlay networking tool, created at Slack, that connects computers anywhere in the world into one private network. It is designed around performance, simplicity and security, and it can link a handful of machines or scale up to tens of thousands. It runs on Linux, macOS, Windows and FreeBSD, with iOS and Android versions available as source code.

Technically, Nebula is a mutually authenticated peer-to-peer software-defined network based on the Noise Protocol Framework. Certificates assert each node's IP address, name and membership in user-defined groups, and those groups allow traffic filtering between nodes regardless of cloud provider. Discovery nodes called lighthouses help peers find each other, with optional UDP hole punching to connect through most firewalls and NATs.

Because addressing does not depend on where machines run, data can move between nodes across different cloud providers, data centers and endpoints without a fixed addressing scheme. Nebula fills a role similar to a mesh VPN. It is written in Go, released under the MIT license and can be self-hosted, with packages available for several Linux distributions, Homebrew and Docker.

Key features

  • Mutually authenticated peer-to-peer tunnels
  • Certificate-based identity and group membership
  • Group-based firewall rules between nodes
  • Lighthouse discovery with UDP hole punching
  • Runs on Linux, macOS, Windows and FreeBSD
  • Scales from a few hosts to thousands

Pricing: Free and open source under the MIT license.

Read more about NebulaGitHub

ZeroTier

ZeroTier is a peer-to-peer virtual network that lets devices, VMs and containers communicate as if they were on the same local network.

GitHub stars
17k
Last commit
29 days ago
Latest release
1.16.2
Self-hosted
Yes
Hosted version
Available
zerotier.comZeroTier homepage screenshot

ZeroTier describes itself as a programmable Ethernet switch for the planet. It lets networked devices, virtual machines, containers and applications communicate as if they were located in the same data center or cloud region, no matter where they actually are. The client is written in C++.

It combines an encrypted peer-to-peer network layer, called VL1, with an Ethernet emulation layer, called VL2, that works somewhat like VXLAN. The virtualization layer includes enterprise SDN features such as fine-grained access control rules for micro-segmentation and security monitoring. Traffic is encrypted end to end with keys the user controls, and most of it flows directly between peers, with free but slow relaying for cases where a direct connection cannot be made.

Android and iOS apps are available free of charge from the app stores. Most of the code sits under a Mozilla Public License file, while parts of the repository are marked as non-free, source-available code, which is why the repository lists the license as 'Other'. The vendor also offers a network controller, a service API and commercial support.

Key features

  • Peer-to-peer virtual Ethernet networking
  • End-to-end encrypted traffic
  • Access control rules for micro-segmentation
  • Relay fallback when direct links fail
  • Apps for Android and iOS
  • Network controller and service API

Pricing: Free Personal plan for 10 devices. Essential is $18 a month and Scale $179 a month, each with extra devices billed per device; Enterprise is custom.

OpenVPN

OpenVPN is an open-source VPN daemon, developed in C, for creating secure virtual private network connections.

GitHub stars
15k
Last commit
today
Latest release
v2.7.7
Self-hosted
Yes

This entry is the OpenVPN source repository. OpenVPN is an open-source VPN daemon, a program that creates secure virtual private network connections between machines. The code is written in C, and the repository is tagged for security and VPN.

No readme or homepage details were available for this entry, so specifics about features, deployment and licensing are not listed here. The repository lists its license as 'Other', and the project community site is community.openvpn.net, which is the place to look for downloads, documentation and support.

Key features

  • Open-source VPN daemon
  • Secure virtual private network connections
  • Written in C
  • Community-supported project

Pricing: Self-hosted Access Server is free for up to 2 connections. Growth is $7 per connection per month on yearly billing with a 14-day trial; Enterprise is custom.

Netmaker

A platform that automates WireGuard networks for mesh VPNs, remote access and site-to-site links, available as open-source self-hosted software or a managed SaaS.

GitHub stars
12k
Last commit
today
Latest release
v1.7.0
Self-hosted
Yes
Hosted version
Available
netmaker.ioNetmaker homepage screenshot

Netmaker builds on WireGuard to create and manage virtual networks automatically, from a home lab to an enterprise. It markets itself as a zero trust networking platform for connecting devices, clouds and sites, with an admin UI so that networks do not have to be configured by hand with wg-quick files.

Its capabilities include WireGuard networks, mesh VPNs, remote access gateways, site-to-site connectivity, private DNS, access control lists and OAuth sign-in. Clients are available for Linux, Mac and Windows, and the server can be deployed with Docker or on Kubernetes. The topics also mention IPv6 support and overlay networking.

You can deploy the open-source server yourself, for example on an Ubuntu 24.04 cloud VM with a static public IP, using a quick-start script and opening the documented ports, or install the self-hosted Pro version. A managed Netmaker SaaS is also offered for those who want to skip operations. The repository lists the license as Other.

Key features

  • Automated WireGuard network management
  • Mesh VPNs and site-to-site links
  • Remote access gateways
  • Admin UI for network administration
  • Access control lists and private DNS
  • OAuth login support
  • Clients for Linux, Mac and Windows

Pricing: The open-source edition is free to self-host. Team starts at $2 and Business at $4 per active connection per month, with a 7-day trial; a self-hosted Professional tier is $99 per month and Enterprise is custom.

Firezone

Firezone is a zero trust access platform based on WireGuard, released as open source, that replaces traditional VPNs with policy-based access to apps and networks.

GitHub stars
9.1k
Last commit
today
Latest release
android-client-1.5.15
Licence
Apache-2.0
Hosted version
Available
firezone.devFirezone homepage screenshot

Firezone is a zero trust access platform that uses WireGuard and is published as open source. It is positioned as a replacement for a traditional VPN, connecting users to internal apps, services and networks through access policies rather than broad network-level rules.

Administrators define policies for resources and can restrict access by conditions such as device location and time of day, with every authorized connection visible by user, resource or policy. Users and groups sync from an identity provider, which simplifies onboarding and offboarding. Lightweight Gateways run as Linux binaries wherever access is needed, and using two or more Gateways gives automatic load balancing and failover. Hole-punching keeps protected resources hidden from the public internet.

Client apps are available for macOS, Windows, Linux, Android, ChromeOS and iOS. The codebase is licensed under Apache-2.0 and written largely in Elixir, with Rust used for networking components. The vendor offers a hosted admin portal, a free way to get started and a separate pricing page.

Key features

  • WireGuard-based VPN replacement
  • Access policies per resource and group
  • Identity provider directory sync
  • Conditional access by location and time
  • Gateways with load balancing and failover
  • Clients for desktop and mobile platforms

Pricing: Free Starter plan for up to 6 users. Team costs $5 per user per month, or $4.16 billed annually; Enterprise is quoted via sales. Source code can be self-hosted without vendor support.

Pomerium

An identity and context-aware access proxy written in Go that secures internal apps and services without a corporate VPN.

GitHub stars
5k
Last commit
today
Latest release
v0.33.3
Licence
Apache-2.0
Self-hosted
Yes
Hosted version
Available
pomerium.comPomerium homepage screenshot

Pomerium is an identity and context-aware reverse proxy that makes secure, clientless connections to internal web apps and other services. The goal is to protect internal resources without asking users to connect through a corporate VPN.

According to the project, clientless access makes it easier to adopt, running tunnel-free and close to your apps and services makes it faster, and verifying each action before it executes makes it safer. Context-aware policies can draw on data from several sources, so access decisions can reflect your organization's own needs. Repository topics point to zero-trust, BeyondCorp-style, identity-aware proxy and IAM use cases.

Pomerium is written in Go and licensed under Apache-2.0. Teams that want a hosted control plane and a management GUI can look at Pomerium Zero, while the open-source proxy can be run on your own infrastructure. Documentation and tutorials are available on pomerium.com.

Key features

  • Identity-aware reverse proxy
  • Clientless access to internal apps
  • Per-request verification of every action
  • Context-aware access policies
  • Tunnel-free deployment near your services
  • Hosted control plane via Pomerium Zero

Pricing: Free Personal plan. Business costs $7 per user per month billed annually, with a free trial; Enterprise for fully self-hosted deployments is quoted.

OpenZiti

OpenZiti's core project, an open-source zero-trust networking platform that authenticates every connection with cryptographic identity and keeps services hidden.

GitHub stars
4.4k
Last commit
today
Latest release
v2.0.6
Licence
Apache-2.0
Self-hosted
Yes
Hosted version
Available

Ziti is the parent project of OpenZiti, an open-source zero-trust networking platform that makes network services invisible to unauthorized users. Every connection, whether from a person, service, device or workload, is authenticated with a cryptographic identity, authorized by policy and encrypted end to end.

It works with existing applications through lightweight tunnelers that need no code changes, and with new applications through embedded SDKs for the strongest zero-trust model. The README lists use cases such as replacing VPNs with per-service authorization, hiding APIs and services so they have no listening ports, and giving IoT devices and other non-human workloads their own identities.

OpenZiti was created and sponsored by NetFoundry and is licensed under Apache-2.0. The code is written in Go, the README describes three deployment models, and a managed solution is available for teams that prefer not to operate it themselves.

Key features

  • Zero-trust overlay networking
  • Cryptographic identity for every connection
  • End-to-end encryption
  • Tunnelers for apps without code changes
  • Embedded SDKs for new applications
  • Policy-based authorization per service
  • Dark services with no listening ports

2 more Twingate alternatives

Twingate alternatives: questions

What is the best open-source alternative to Twingate?
Tailscale is the top-ranked open-source alternative to Twingate on Enlisted: Tailscale builds private WireGuard-based networks between your devices; this repository holds the open-source client daemon and CLI. Other strong options are NetBird, Pangolin, Nebula and ZeroTier.
Are these Twingate alternatives free?
All 12 are open source, so the code is free to use under its licence, and 12 of them can be self-hosted on your own server. 8 also offer a paid or managed cloud version if you'd rather not host it yourself.
How is this list of Twingate alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 12 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all