
OpenZiti
Open-source zero trust networking overlay for applications

OpenZiti is an open-source, programmable zero trust networking platform for connecting applications using an identity-based overlay network instead of IP-based trust. It provides a fabric (mesh), edge components, and SDKs/tunnelers to securely connect users, devices, and services with policy-driven access.
Key Features
- Identity-based connectivity with certificate-backed identities and policy-based authorization
- Application segmentation and “deny by default” access controls for services
- Overlay mesh fabric with smart routing and pluggable capabilities
- “Dark” services and routers that can operate without inbound listening ports by using outbound connections into the fabric
- End-to-end encryption options, including application-embedded connectivity via SDKs
- REST management APIs and a web-based admin console for managing the network
- Support for integrating existing apps through tunnelers and proxies when embedding SDKs is not feasible
Use Cases
- Zero trust access to internal applications across hybrid and multi-cloud environments
- Secure machine-to-machine or service-to-service communications without exposing ports
- Replacing or reducing traditional VPN access with per-application access policies
Limitations and Considerations
- Some advanced capabilities (for example, true process-to-process protection) are best achieved when applications embed the OpenZiti SDKs rather than relying only on tunnelers
- Designing policies, identity lifecycle, and PKI can add operational complexity compared to simple IP allowlists
OpenZiti is well-suited for teams that want a flexible, open-source foundation for zero trust application access. It combines a scalable overlay fabric with strong identity controls and multiple integration options, ranging from SDK embedding to tunneling and proxying.
Categories:
Tags:
Tech Stack:
Similar Services

Pi-hole
Network-wide DNS sinkhole for ad and tracker blocking
Pi-hole is a network-wide DNS sinkhole that blocks ads and trackers for all devices on your network, with a web dashboard, query logs, and optional DHCP server.

Headscale
Self-hosted control server for Tailscale-based WireGuard networks
Headscale is an open source, self-hosted implementation of the Tailscale control server for managing a private tailnet, nodes, keys, IPs, and routes.

AdGuard Home
Network-wide DNS server that blocks ads, trackers, phishing and malware
Open-source DNS-based ad & tracker blocking server for networks. Offers per-device rules, parental controls, encrypted upstream DNS (DoH/DoT/DNSCrypt), web UI and API.

Web-Check
All-in-one OSINT tool for analyzing any website.
Comprehensive on-demand OSINT to analyze a website's security, architecture, and tech stack.

wg-easy
WireGuard VPN server with a web-based admin interface
Run a WireGuard VPN server with an easy web admin UI to manage clients, generate configs and QR codes, and monitor connections and traffic.

NetBird
WireGuard-based overlay network with SSO/MFA and granular access controls.
Open-source zero-trust networking platform delivering a WireGuard-based private network with centralized access control, SSO/MFA, and cross-platform clients.
Go
Docker
Bash