Open-source zero-trust networking platform delivering a WireGuard-based private network with centralized access control, SSO/MFA, and cross-platform clients.

27.8k stars1.5k forkslast commit Actively maintained
Zero Trust access service that secures internal applications, SSH, and RDP by enforcing identity-based policies. Integrates with SSO/IdPs, performs device posture checks, issues short‑lived credentials, and replaces traditional VPN access.
Open-source zero-trust networking platform delivering a WireGuard-based private network with centralized access control, SSO/MFA, and cross-platform clients.

27.8k stars1.5k forkslast commit Actively maintained
Open-source IdP delivering SSO, OAuth2/OIDC, SAML2, LDAP, RADIUS, MFA, WebAuthn, conditional access and application-proxy capabilities for self-hosted deployments.

22.5k stars1.7k forkslast commit Actively maintained
Open-source identity-based remote access platform combining WireGuard VPN and tunneled reverse proxy access with granular zero-trust controls.

21.9k stars745 forkslast commit Actively maintained
Secure access platform for servers, Kubernetes, databases, desktops, and web apps with SSO/MFA, short-lived certificates, and full session auditing.

20.7k stars2.1k forksAGPL-3.0last commit Actively maintained
CLI tool to create Cloudflare Tunnels and route traffic through Cloudflare’s edge.

15k stars1.4k forksApache-2.0last commit Actively maintained
OAuth2 Proxy is a reverse proxy and middleware that protects web apps with OAuth2/OIDC login and forwards authenticated user identity to upstream services.

14.8k stars2.2k forksMITlast commit Actively maintained
Casdoor is an open-source, UI-first IAM/SSO platform supporting OAuth 2.0, OIDC, SAML, LDAP, SCIM, WebAuthn and MFA, with an admin web UI and SDKs.
14.1k stars1.8k forksApache-2.0last commit Actively maintained
Firezone is a zero-trust VPN replacement built on WireGuard, providing identity-aware access policies, peer-to-peer encrypted tunnels, and lightweight gateways.

8.9k stars436 forksApache-2.0last commit Actively maintained
Tinyauth is a lightweight auth middleware that adds a login screen, OAuth, or LDAP authentication in front of your apps via common reverse proxies.

8k stars258 forksAGPL-3.0last commit Actively maintained
iodine is a DNS tunneling tool that forwards IPv4 traffic through DNS queries and replies, providing a TUN interface to route IP traffic when only DNS is allowed.

7.9k stars596 forksISClast commit Slowing down
Cosmos Cloud is a security-focused self-hosting platform that provides an app store, reverse proxy with automatic HTTPS, SSO/MFA, container management, backups, and monitoring.

6.1k stars237 forkslast commit Actively maintained
Pomerium is an identity-aware access proxy that provides zero trust, per-request authorization to internal web apps and services without a traditional VPN.

4.9k stars343 forksApache-2.0last commit Actively maintained
OpenZiti is an open-source zero trust networking platform that builds an identity-based overlay mesh with SDKs, tunnelers, and policy-based access controls.

4.3k stars262 forksApache-2.0last commit Actively maintained
Enterprise-grade zero-trust access management platform providing WireGuard VPN with true protocol-level 2FA/MFA, plus integrated OpenID Connect SSO and user/device controls.

2.8k stars107 forkslast commit Actively maintained
Centralized SSH gateway to remotely manage Linux servers, containers and IoT devices via web or native SSH; offers key auth, firewall rules, audit logging and session recording.

2k stars186 forksApache-2.0last commit Actively maintained
Self-hosted ingress platform that exposes internal HTTP/TCP services to the internet through reverse WireGuard tunnels, with NGINX routing and automatic TLS certificates.

1.6k stars76 forksApache-2.0last commit Actively maintained
NetGoat is a self-hostable reverse proxy and traffic management platform offering Cloudflare-like features such as TLS termination, rate limiting, WAF-style filtering, and dashboards.

888 stars47 forksAGPL-3.0last commit Actively maintained
Single-binary TLS reverse proxy for self-hosted apps that provides SSH- and Telegram-based authorization, simple SSO, Let's Encrypt support and whitelist access control.
189 stars9 forksGPL-3.0last commit Likely dormant
A minimal, Rust-based forward authentication middleware for reverse proxies (Traefik, Caddy, nginx) using a passwd file and signed auth tokens.
157 stars8 forksMITlast commit Actively maintained
Advanced SSH server and bastion that authenticates via OpenID Connect or keys, runs sessions inside Docker containers or Kubernetes pods, and supports automatic user provisioning.

83 stars2 forksApache-2.0last commit Actively maintained
Every option on this page is open source and free to run on your own hardware, so you own the data and there is no subscription to cancel. 18 of 20 shipped a commit in the last six months. Licences in this list: AGPL-3.0, Apache-2.0, MIT, ISC, GPL-3.0. In exchange you take on hosting, backups and updates yourself.
Browse everything in Identity & Access Management (IAM).