
OpenZiti
Open-source zero trust networking overlay for applications
4.4k stars 266 forks last commit first released Apache-2.0
Actively maintained
Last commit 26 Aug 2026.

OpenZiti is an open-source, programmable zero trust networking platform for connecting applications using an identity-based overlay network instead of IP-based trust. It provides a fabric (mesh), edge components, and SDKs/tunnelers to securely connect users, devices, and services with policy-driven access.
Key Features
- Identity-based connectivity with certificate-backed identities and policy-based authorization
- Application segmentation and “deny by default” access controls for services
- Overlay mesh fabric with smart routing and pluggable capabilities
- “Dark” services and routers that can operate without inbound listening ports by using outbound connections into the fabric
- End-to-end encryption options, including application-embedded connectivity via SDKs
- REST management APIs and a web-based admin console for managing the network
- Support for integrating existing apps through tunnelers and proxies when embedding SDKs is not feasible
Use Cases
- Zero trust access to internal applications across hybrid and multi-cloud environments
- Secure machine-to-machine or service-to-service communications without exposing ports
- Replacing or reducing traditional VPN access with per-application access policies
Limitations and Considerations
- Some advanced capabilities (for example, true process-to-process protection) are best achieved when applications embed the OpenZiti SDKs rather than relying only on tunnelers
- Designing policies, identity lifecycle, and PKI can add operational complexity compared to simple IP allowlists
OpenZiti is well-suited for teams that want a flexible, open-source foundation for zero trust application access. It combines a scalable overlay fabric with strong identity controls and multiple integration options, ranging from SDK embedding to tunneling and proxying.
Categories:
Tags:
Tech Stack:
Similar to OpenZiti

NetBird
WireGuard-based overlay network with SSO/MFA and granular access controls.
Open-source zero-trust networking platform delivering a WireGuard-based private network with centralized access control, SSO/MFA, and cross-platform clients.
Pomerium
Identity- and context-aware access proxy for zero trust access
Pomerium is an identity-aware access proxy that provides zero trust, per-request authorization to internal web apps and services without a traditional VPN.
Cerbos
Context-aware authorization and access control policy engine
Cerbos is a scalable, language-agnostic authorization layer for defining and evaluating context-aware access control policies via a dedicated Policy Decision Point (PDP) API.
ZITADEL
API-first identity and access management platform for applications
ZITADEL is an open source IAM/CIAM platform providing SSO, MFA, OIDC/OAuth2, SAML, user management, and multi-tenant organizations with audit logging.
Pocket ID
A passkey-only OpenID Connect identity provider
Pocket ID is a simple self-hosted OpenID Connect (OIDC) provider that lets users sign in to apps using passkeys instead of passwords.

Hasura GraphQL Engine
Open-source GraphQL engine providing instant, realtime APIs on your data
Hasura is an open-source GraphQL engine that instantly exposes realtime, secure GraphQL APIs over databases and other data sources with fine-grained access control.



