Firezone
Firezone is a zero trust access platform based on WireGuard, released as open source, that replaces traditional VPNs with policy-based access to apps and networks.
- GitHub stars
- 9.1k
- Last commit
- yesterday
- Latest release
- android-client-1.5.15
- Licence
- Apache-2.0
- Hosted version
- Available

Firezone is a zero trust access platform that uses WireGuard and is published as open source. It is positioned as a replacement for a traditional VPN, connecting users to internal apps, services and networks through access policies rather than broad network-level rules.
Administrators define policies for resources and can restrict access by conditions such as device location and time of day, with every authorized connection visible by user, resource or policy. Users and groups sync from an identity provider, which simplifies onboarding and offboarding. Lightweight Gateways run as Linux binaries wherever access is needed, and using two or more Gateways gives automatic load balancing and failover. Hole-punching keeps protected resources hidden from the public internet.
Client apps are available for macOS, Windows, Linux, Android, ChromeOS and iOS. The codebase is licensed under Apache-2.0 and written largely in Elixir, with Rust used for networking components. The vendor offers a hosted admin portal, a free way to get started and a separate pricing page.
Key features
- WireGuard-based VPN replacement
- Access policies per resource and group
- Identity provider directory sync
- Conditional access by location and time
- Gateways with load balancing and failover
- Clients for desktop and mobile platforms
Pricing: Free Starter plan for up to 6 users. Team costs $5 per user per month, or $4.16 billed annually; Enterprise is quoted via sales. Source code can be self-hosted without vendor support.

