7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

4 alternatives ranked by real activity

Open-source Zscaler alternatives

A curated, ranked list of the 4 best open-source alternatives to Zscaler.

The best open-source alternative to Zscaler is Firezone. If that doesn't suit you, other good options are Pomerium, OpenZiti and Octelium.

Zscaler alternatives are mainly networking & VPN tools, but some are also security tools. 4 of them shipped code in the last 30 days, 4 can be self-hosted, and 3 use a permissive licence.

Last updated October 2, 2026 · ranked by GitHub stars, growth and recent commits

Firezone

Firezone is a zero trust access platform based on WireGuard, released as open source, that replaces traditional VPNs with policy-based access to apps and networks.

GitHub stars
9.1k
Last commit
yesterday
Latest release
android-client-1.5.15
Licence
Apache-2.0
Hosted version
Available
firezone.devFirezone homepage screenshot

Firezone is a zero trust access platform that uses WireGuard and is published as open source. It is positioned as a replacement for a traditional VPN, connecting users to internal apps, services and networks through access policies rather than broad network-level rules.

Administrators define policies for resources and can restrict access by conditions such as device location and time of day, with every authorized connection visible by user, resource or policy. Users and groups sync from an identity provider, which simplifies onboarding and offboarding. Lightweight Gateways run as Linux binaries wherever access is needed, and using two or more Gateways gives automatic load balancing and failover. Hole-punching keeps protected resources hidden from the public internet.

Client apps are available for macOS, Windows, Linux, Android, ChromeOS and iOS. The codebase is licensed under Apache-2.0 and written largely in Elixir, with Rust used for networking components. The vendor offers a hosted admin portal, a free way to get started and a separate pricing page.

Key features

  • WireGuard-based VPN replacement
  • Access policies per resource and group
  • Identity provider directory sync
  • Conditional access by location and time
  • Gateways with load balancing and failover
  • Clients for desktop and mobile platforms

Pricing: Free Starter plan for up to 6 users. Team costs $5 per user per month, or $4.16 billed annually; Enterprise is quoted via sales. Source code can be self-hosted without vendor support.

Pomerium

An identity and context-aware access proxy written in Go that secures internal apps and services without a corporate VPN.

GitHub stars
5k
Last commit
today
Latest release
v0.33.3
Licence
Apache-2.0
Self-hosted
Yes
Hosted version
Available
pomerium.comPomerium homepage screenshot

Pomerium is an identity and context-aware reverse proxy that makes secure, clientless connections to internal web apps and other services. The goal is to protect internal resources without asking users to connect through a corporate VPN.

According to the project, clientless access makes it easier to adopt, running tunnel-free and close to your apps and services makes it faster, and verifying each action before it executes makes it safer. Context-aware policies can draw on data from several sources, so access decisions can reflect your organization's own needs. Repository topics point to zero-trust, BeyondCorp-style, identity-aware proxy and IAM use cases.

Pomerium is written in Go and licensed under Apache-2.0. Teams that want a hosted control plane and a management GUI can look at Pomerium Zero, while the open-source proxy can be run on your own infrastructure. Documentation and tutorials are available on pomerium.com.

Key features

  • Identity-aware reverse proxy
  • Clientless access to internal apps
  • Per-request verification of every action
  • Context-aware access policies
  • Tunnel-free deployment near your services
  • Hosted control plane via Pomerium Zero

Pricing: Free Personal plan. Business costs $7 per user per month billed annually, with a free trial; Enterprise for fully self-hosted deployments is quoted.

OpenZiti

OpenZiti's core project, an open-source zero-trust networking platform that authenticates every connection with cryptographic identity and keeps services hidden.

GitHub stars
4.4k
Last commit
today
Latest release
v2.0.6
Licence
Apache-2.0
Self-hosted
Yes
Hosted version
Available

Ziti is the parent project of OpenZiti, an open-source zero-trust networking platform that makes network services invisible to unauthorized users. Every connection, whether from a person, service, device or workload, is authenticated with a cryptographic identity, authorized by policy and encrypted end to end.

It works with existing applications through lightweight tunnelers that need no code changes, and with new applications through embedded SDKs for the strongest zero-trust model. The README lists use cases such as replacing VPNs with per-service authorization, hiding APIs and services so they have no listening ports, and giving IoT devices and other non-human workloads their own identities.

OpenZiti was created and sponsored by NetFoundry and is licensed under Apache-2.0. The code is written in Go, the README describes three deployment models, and a managed solution is available for teams that prefer not to operate it themselves.

Key features

  • Zero-trust overlay networking
  • Cryptographic identity for every connection
  • End-to-end encryption
  • Tunnelers for apps without code changes
  • Embedded SDKs for new applications
  • Policy-based authorization per service
  • Dark services with no listening ports

Octelium

Octelium is a self-hosted zero trust access platform that can act as a VPN, ZTNA system, API and AI gateway, tunnel service or PaaS on Kubernetes.

GitHub stars
4.1k
Last commit
today
Latest release
v0.43.0
Licence
AGPL-3.0
Self-hosted
Yes
octelium.comOctelium homepage screenshot

Octelium is a self-hosted, open-source platform that unifies zero trust secure access under one system. It is flexible enough to act as a zero-config remote access VPN, a Zero Trust Network Access and BeyondCorp-style platform, an alternative to ngrok and Cloudflare Tunnel, an API gateway, an AI and LLM gateway, and an infrastructure for building MCP gateways and AI agent access.

Repository topics list attribute-based access control, policy as code, WireGuard, QUIC, SSO, multi-factor authentication, OpenTelemetry and SSH access. The README includes use cases, a feature overview, a guide to try it in a Codespace, CLI installation and instructions to install your first cluster. It is written in Go and runs on Kubernetes. It is compared to ngrok, Cloudflare Tunnel and Apigee for different roles.

Octelium is licensed under AGPL-3.0 and you operate the cluster yourself. It suits platform and security teams, homelab users and developers who want to replace several access, tunnel and gateway tools with one self-hosted system.

Key features

  • Zero-config remote access VPN
  • ZTNA and BeyondCorp-style access
  • API, AI and MCP gateway capabilities
  • Tunnel service as ngrok alternative
  • Attribute-based policy as code
  • Runs on Kubernetes clusters

Pricing: Free and open source under AGPL-3.0.

Zscaler alternatives: questions

What is the best open-source alternative to Zscaler?
Firezone is the top-ranked open-source alternative to Zscaler on Enlisted: Firezone is a zero trust access platform based on WireGuard, released as open source, that replaces traditional VPNs with policy-based access to apps and networks. Other strong options are Pomerium, OpenZiti and Octelium.
Are these Zscaler alternatives free?
All 4 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer. 3 also offer a paid or managed cloud version if you'd rather not host it yourself.
How is this list of Zscaler alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 4 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all