7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

Pangolin

Open source

An open-source SASE platform on WireGuard combining zero-trust VPN and proxy access, privileged access control and an AI gateway that understands identity.

pangolin.net
Pangolin homepage screenshot
GitHub stars
23k
Last commit
yesterday
Repository age
2 years
Version
1.24.0
Licence
Custom
Self-hosted
Yes

About Pangolin

Pangolin is an open-source secure access service edge platform built on WireGuard. It aims to connect and protect users wherever they are by combining networking and security in one system: a zero-trust VPN, a zero-trust reverse proxy, privileged access control and a gateway for AI workloads that is aware of user identity, with one identity and policy model underneath.

The project compares its idea to commercial platforms such as Cloudflare One, Zscaler and Prisma, but argues that it is open, self-hostable and light enough to be easy to deploy. Legacy SASE products, it says, are heavy, closed and cloud-locked. Topics include reverse proxy, single sign-on, OIDC, SSH, tunneling, NAT traversal and remote access. Because the source is open to inspection, you can verify how traffic and access decisions are handled.

You can use Pangolin Cloud at app.pangolin.net or run it yourself. The repository's license is listed as 'Other' on GitHub, because it mixes open-source and enterprise components, so check the terms. It suits homelab users, small companies and IT teams that want zero-trust remote access without a large vendor contract.

Key features

  • Zero-trust VPN built on WireGuard
  • Zero-trust reverse proxy
  • Privileged access management
  • Identity-aware AI gateway
  • Single identity and policy model
  • Cloud or self-hosted deployment

Good fit for

  • →Secure remote access to internal apps
  • →Replacing a commercial ZTNA product
  • →Exposing homelab services safely
Built with
TypeScript
Tags
sase
zero-trust
wireguard
vpn
reverse-proxy
sso
remote-access
self-hosted
ztna

Pangolin: questions and answers

What is Pangolin used for?
Pangolin is an open-source SASE platform on WireGuard combining zero-trust VPN and proxy access, privileged access control and an AI gateway that understands identity. It is a good fit for secure remote access to internal apps, replacing a commercial ZTNA product and exposing homelab services safely.
Is Pangolin open source?
Yes. Pangolin is open source under a custom licence. Its source code is on GitHub at fosrl/pangolin and is written mainly in TypeScript.
Is Pangolin free?
Yes. Pangolin is open source, so the software itself is free to use under the terms of its own licence. A managed cloud version is also available, with paid plans from $4 per seat per month.
Can I self-host Pangolin?
Yes. Pangolin can be self-hosted on your own server or infrastructure.
What is Pangolin an alternative to?
Pangolin is an open-source alternative to Cloudflare Tunnel, Tailscale, Twingate and ngrok. Other open-source alternatives to Cloudflare Tunnel include Octelium and Zrok.
Is Pangolin actively maintained?
Yes. The most recent commit to Pangolin was on 2 October 2026, and the latest release is 1.24.0, published on 30 September 2026. The project has 23k stars on GitHub.

Open-source alternatives to Pangolin

See all

SaaS alternatives to Pangolin

See all