OpenZiti logo

OpenZiti

Website

Open-source zero trust networking overlay for applications

4.4k stars 266 forks last commit first released Apache-2.0

Actively maintained

Last commit 26 Aug 2026.

OpenZiti screenshot

OpenZiti is an open-source, programmable zero trust networking platform for connecting applications using an identity-based overlay network instead of IP-based trust. It provides a fabric (mesh), edge components, and SDKs/tunnelers to securely connect users, devices, and services with policy-driven access.

Key Features

  • Identity-based connectivity with certificate-backed identities and policy-based authorization
  • Application segmentation and “deny by default” access controls for services
  • Overlay mesh fabric with smart routing and pluggable capabilities
  • “Dark” services and routers that can operate without inbound listening ports by using outbound connections into the fabric
  • End-to-end encryption options, including application-embedded connectivity via SDKs
  • REST management APIs and a web-based admin console for managing the network
  • Support for integrating existing apps through tunnelers and proxies when embedding SDKs is not feasible

Use Cases

  • Zero trust access to internal applications across hybrid and multi-cloud environments
  • Secure machine-to-machine or service-to-service communications without exposing ports
  • Replacing or reducing traditional VPN access with per-application access policies

Limitations and Considerations

  • Some advanced capabilities (for example, true process-to-process protection) are best achieved when applications embed the OpenZiti SDKs rather than relying only on tunnelers
  • Designing policies, identity lifecycle, and PKI can add operational complexity compared to simple IP allowlists

OpenZiti is well-suited for teams that want a flexible, open-source foundation for zero trust application access. It combines a scalable overlay fabric with strong identity controls and multiple integration options, ranging from SDK embedding to tunneling and proxying.

Categories:

Tags:

Tech Stack:

Share:

Similar to OpenZiti

NetBird logo

NetBird

WireGuard-based overlay network with SSO/MFA and granular access controls.

28.7k
1.6k
Last commit

Open-source zero-trust networking platform delivering a WireGuard-based private network with centralized access control, SSO/MFA, and cross-platform clients.

Actively maintained
Alternative to:
Tailscale logo
Tailscale
+17

Pomerium

Identity- and context-aware access proxy for zero trust access

5k
350
Last commit

Pomerium is an identity-aware access proxy that provides zero trust, per-request authorization to internal web apps and services without a traditional VPN.

Apache-2.0Actively maintained
Alternative to:
Cloudflare Access logo
Cloudflare Access
+12
Cerbos logo

Cerbos

Context-aware authorization and access control policy engine

4.6k
208
Last commit

Cerbos is a scalable, language-agnostic authorization layer for defining and evaluating context-aware access control policies via a dedicated Policy Decision Point (PDP) API.

Apache-2.0Actively maintained
Alternative to:
OSO Cloud logo
OSO Cloud
+17
ZITADEL logo

ZITADEL

API-first identity and access management platform for applications

14.9k
1.3k
Last commit

ZITADEL is an open source IAM/CIAM platform providing SSO, MFA, OIDC/OAuth2, SAML, user management, and multi-tenant organizations with audit logging.

AGPL-3.0Actively maintained
Alternative to:
Auth0 logo
Auth0
+19
Pocket ID logo

Pocket ID

A passkey-only OpenID Connect identity provider

9k
304
Last commit

Pocket ID is a simple self-hosted OpenID Connect (OIDC) provider that lets users sign in to apps using passkeys instead of passwords.

BSD-2-ClauseActively maintained
Alternative to:
Auth0 logo
Auth0
+19
Hasura GraphQL Engine logo

Hasura GraphQL Engine

Open-source GraphQL engine providing instant, realtime APIs on your data

32.1k
3k
Last commit

Hasura is an open-source GraphQL engine that instantly exposes realtime, secure GraphQL APIs over databases and other data sources with fine-grained access control.

Apache-2.0Actively maintained
Alternative to:
Hasura logo
Hasura
+16