Best Self-hosted Security & Privacy tools in 2026

117 self-hosted open source alternatives in this category

117 services found

MyIP (IPCheck.ing)

MyIP (IPCheck.ing)

Open-source IP toolbox for IP, DNS, WebRTC and network diagnostics

9.6k
1.1k
Last commit: 13d ago

MyIP (IPCheck.ing) is an open-source web IP toolbox that detects local/public IPs, runs DNS leak and WebRTC checks, speed/latency/MTR tests, availability and whois lookup...

Alternative to:
WhatIsMyIPAddress.com
WhatIsMyIPAddress.com
+10
Amnezia

Amnezia

Cross-platform client to deploy and use your own VPN server

9.6k
673
Last commit: 3d ago

Open-source VPN client for desktop and mobile that can automatically set up a private VPN server and connect using WireGuard, OpenVPN, IKEv2, and obfuscated modes.

Alternative to:
NordVPN
NordVPN
+15
Firezone

Firezone

Zero-trust remote access platform built on WireGuard

8.4k
399
Last commit: 2d ago

Firezone is a zero-trust VPN replacement built on WireGuard, providing identity-aware access policies, peer-to-peer encrypted tunnels, and lightweight gateways.

Alternative to:
Tailscale
Tailscale
+11
step-ca

step-ca

Private certificate authority and ACME server for X.509 and SSH

8k
520
Last commit: 4d ago

step-ca is a private CA and ACME server for issuing and automating X.509 TLS and SSH certificates, enabling short-lived credentials and secure enrollment for teams.

Alternative to:
HashiCorp Vault
HashiCorp Vault
+7
Graylog

Graylog

Centralized log management and analysis platform

7.9k
1.1k
Last commit: 2d ago

Graylog is an open source platform for collecting, indexing, searching, and alerting on logs and machine data from many sources in one place.

Alternative to:
Graylog Cloud
Graylog Cloud
+11
iodine

iodine

IPv4-over-DNS tunneling server and client

7.6k
574
Last commit: 4mo ago

iodine is a DNS tunneling tool that forwards IPv4 traffic through DNS queries and replies, providing a TUN interface to route IP traffic when only DNS is allowed.

Alternative to:
Cloudflare Tunnel
Cloudflare Tunnel
+15
Tinyauth

Tinyauth

Lightweight authentication middleware for protecting web apps

6.8k
213
Last commit: 3d ago

Tinyauth is a lightweight auth middleware that adds a login screen, OAuth, or LDAP authentication in front of your apps via common reverse proxies.

Alternative to:
Cloudflare Access
Cloudflare Access
+17
WatchYourLAN

WatchYourLAN

Lightweight LAN IP scanner with web UI, alerts, and metrics export

6.7k
228
Last commit: 4mo ago

Self-hosted lightweight LAN IP/ARP scanner with web dashboard, new-host notifications, online/offline history, and metrics export to Prometheus or InfluxDB for Grafana.

Alternative to:
Fing
Fing
+9
Warpgate

Warpgate

Transparent bastion and PAM for SSH, HTTPS, MySQL and PostgreSQL

6.4k
224
Last commit: 3d ago

Self-hosted transparent bastion host and PAM for SSH, HTTPS, MySQL and Postgres with RBAC, session recording, and SSO/2FA—no client-side software required.

Alternative to:
Teleport
Teleport
+7
OneUptime

OneUptime

Open-source monitoring, incident management, and observability platform

6.4k
307
Last commit: 2d ago

Self-hostable observability platform for uptime monitoring, alerting, incident management, on-call, status pages, logs, and APM in one integrated suite.

Alternative to:
OneUptime
OneUptime
+19
Pocket ID

Pocket ID

A passkey-only OpenID Connect identity provider

6.2k
186
Last commit: 3d ago

Pocket ID is a simple self-hosted OpenID Connect (OIDC) provider that lets users sign in to apps using passkeys instead of passwords.

Alternative to:
Auth0
Auth0
+19
ClamAV

ClamAV

Open-source antivirus engine for gateway and file scanning

6.1k
826
Last commit: 4d ago

ClamAV is an open-source antivirus toolkit providing a multi-threaded daemon, command-line scanners, and automatic signature updates for mail gateways and file scanning.

Alternative to:
McAfee
McAfee
+8
MeshCentral

MeshCentral

Open-source web-based remote device management and remote desktop server

5.9k
783
Last commit: 2d ago

Self-hosted Node.js server for remote monitoring, web-based remote desktop, terminal, file access and multi-DB device management.

Alternative to:
TeamViewer
TeamViewer
+14
LLDAP

LLDAP

Lightweight LDAP authentication server with a web UI

5.9k
310
Last commit: 5d ago

LLDAP is a lightweight LDAP server for authentication and user management, providing a simplified LDAP interface, a web admin UI, and SQLite/MySQL/PostgreSQL backends.

Alternative to:
Microsoft Active Directory
Microsoft Active Directory
+2
Passbolt

Passbolt

Open-source password and secret manager for teams

5.6k
362
Last commit: 27d ago

Passbolt is an open-source, security-first password and secret manager for teams, with end-to-end encryption, granular sharing permissions, and auditing.

Alternative to:
Passbolt Cloud
Passbolt Cloud
+11
Cosmos Cloud

Cosmos Cloud

Security-first self-hosting platform with reverse proxy, SSO, and apps

5.5k
198
Last commit: 3d ago

Cosmos Cloud is a security-focused self-hosting platform that provides an app store, reverse proxy with automatic HTTPS, SSO/MFA, container management, backups, and monit...

Alternative to:
Cloudron
Cloudron
+18
NetAlertX

NetAlertX

Network device scanner and presence detection with alerts

5.4k
308
Last commit: 6h ago

Self-hosted network visibility and presence scanner that discovers connected devices and alerts on new, unknown, or changed hosts across your LAN/Wi‑Fi.

Alternative to:
Fing
Fing
+8
OpenBao

OpenBao

Open source secrets management for keys, certificates, and tokens

5.2k
309
Last commit: 2d ago

OpenBao is an open source secrets management platform to securely store, generate, lease, and revoke secrets, certificates, and encryption keys with auditing and access c...

Alternative to:
HashiCorp Vault
HashiCorp Vault
+3
Cap

Cap

Privacy-first proof-of-work CAPTCHA alternative for web and APIs

4.8k
254
Last commit: 7d ago

Lightweight, self-hostable CAPTCHA alternative using SHA-256 proof-of-work challenges to protect forms and APIs from bots without tracking or visual puzzles.

Alternative to:
Google reCAPTCHA
Google reCAPTCHA
+8
Pomerium

Pomerium

Identity- and context-aware access proxy for zero trust access

4.6k
321
Last commit: 2d ago

Pomerium is an identity-aware access proxy that provides zero trust, per-request authorization to internal web apps and services without a traditional VPN.

Alternative to:
Cloudflare Access
Cloudflare Access
+12
Kanidm

Kanidm

Simple, secure identity management and SSO provider

4.5k
284
Last commit: 2d ago

Kanidm is a secure identity management platform providing SSO, passkeys (WebAuthn), and integrations like OAuth2/OIDC, RADIUS, and LDAP gateway for legacy apps.

Alternative to:
Okta
Okta
+19
Cerbos

Cerbos

Context-aware authorization and access control policy engine

4.2k
171
Last commit: 2d ago

Cerbos is a scalable, language-agnostic authorization layer for defining and evaluating context-aware access control policies via a dedicated Policy Decision Point (PDP)...

Alternative to:
OSO Cloud
OSO Cloud
+17
OPNsense

OPNsense

Open source firewall and routing platform for network security

4.2k
895
Last commit: 19h ago

OPNsense is an open source FreeBSD-based firewall and routing platform with a web GUI, API, VPN, traffic shaping, and security features for networks and homelabs.

Alternative to:
Fortinet FortiGate
Fortinet FortiGate
+12
OpenZiti

OpenZiti

Open-source zero trust networking overlay for applications

3.8k
233
Last commit: 3d ago

OpenZiti is an open-source zero trust networking platform that builds an identity-based overlay mesh with SDKs, tunnelers, and policy-based access controls.

Alternative to:
Zscaler Private Access
Zscaler Private Access
+14
2FAuth

2FAuth

Web-based TOTP/HOTP authenticator and 2FA account manager

3.7k
261
Last commit: 4d ago

Open-source web app to manage TOTP/HOTP 2FA accounts: scan QR codes, generate one-time codes, import/export tokens, and protect access with WebAuthn and optional encrypti...

Alternative to:
Google Authenticator
Google Authenticator
+3
WGDashboard

WGDashboard

Web dashboard to manage and monitor WireGuard VPN

3.3k
396
Last commit: 9d ago

Self-hosted web dashboard for WireGuard and AmneziaWG to manage configs, peers, and access with a simple UI and optional 2FA.

Alternative to:
Tailscale
Tailscale
+15
Password Pusher

Password Pusher

Securely share passwords and sensitive data with auto-expiring links.

2.8k
425
Last commit: 3d ago

Open-source app that creates self-deleting secret links with audit logs.

Alternative to:
Onetime Secret
Onetime Secret
+1
GLAuth

GLAuth

Lightweight LDAP authentication server with pluggable backends

2.8k
238
Last commit: 5mo ago

GLAuth is a lightweight LDAP/LDAPS authentication server for development, CI, and homelabs, supporting file, S3, SQL, or LDAP proxy backends and optional 2FA.

Alternative to:
Microsoft Active Directory
Microsoft Active Directory
+5
Canarytokens

Canarytokens

Honeytokens that alert when accessed or executed

2.7k
393
Last commit: 6d ago

Canarytokens generates honeytokens (URLs, files, credentials, docs) that alert you when an attacker touches them, helping detect breaches early.

Alternative to:
Thinkst Canary
Thinkst Canary
+2
Onetime Secret

Onetime Secret

Self-destructing service for sharing single-use encrypted secrets

2.7k
422
Last commit: 1d ago

Open-source web and API service to create encrypted, single-view links for sharing secrets with configurable expiry and optional passphrase protection.

Alternative to:
Onetime Secret
Onetime Secret
+6