
Pangolin
Identity-aware VPN and reverse proxy for secure remote access
22.5k stars 765 forks last commit first released
Actively maintained
Last commit 26 Aug 2026.

Pangolin is an identity-based remote access platform built on WireGuard that securely routes traffic to private and public resources across multiple networks. It combines VPN-style connectivity with browser-based reverse proxy access to applications, using zero-trust access controls.
Key Features
- WireGuard-based tunnels to connect remote networks (“sites”) without exposing ports or requiring public IPs
- Browser-based access to web applications via identity- and context-aware tunneled reverse proxy
- Client-based access to private resources (for example SSH, databases, RDP, and network ranges)
- Granular zero-trust access controls so users only reach explicitly allowed resources
- SSO and OIDC support, plus additional authentication options such as PIN and passwords
- Centralized dashboard to manage applications across networks, with access logging and policy enforcement
- Automatic TLS/SSL certificate handling for proxied apps
Use Cases
- Provide secure access to internal tools (Grafana, Bitwarden, admin panels) across offices, cloud VPCs, and edge locations
- Replace or complement traditional VPNs with per-application access and stronger identity enforcement
- Publish self-hosted web apps safely without directly exposing the underlying network
Limitations and Considerations
- Dual-licensed: Community Edition under AGPL-3, with separate enterprise/commercial licensing terms
Pangolin is well-suited for teams and homelabs that need identity-aware access to distributed networks and apps. It emphasizes minimizing network exposure while still enabling convenient browser and client access to protected resources.
Categories:
Tags:
Tech Stack:
Similar to Pangolin
GoDoxy
Reverse proxy and container-aware traffic manager with Web UI
High-performance reverse proxy for self-hosted apps with Web UI, Docker/Podman auto-routing, HTTPS via Let's Encrypt, access control, and OIDC/ForwardAuth support.

NetBird
WireGuard-based overlay network with SSO/MFA and granular access controls.
Open-source zero-trust networking platform delivering a WireGuard-based private network with centralized access control, SSO/MFA, and cross-platform clients.

Firezone
Zero-trust remote access platform built on WireGuard
Firezone is a zero-trust VPN replacement built on WireGuard, providing identity-aware access policies, peer-to-peer encrypted tunnels, and lightweight gateways.
Pomerium
Identity- and context-aware access proxy for zero trust access
Pomerium is an identity-aware access proxy that provides zero trust, per-request authorization to internal web apps and services without a traditional VPN.
OAuth2 Proxy
Reverse proxy and middleware for OAuth2/OIDC authentication
OAuth2 Proxy is a reverse proxy and middleware that protects web apps with OAuth2/OIDC login and forwards authenticated user identity to upstream services.

DockFlare
Cloudflare Tunnel ingress controller automated with Docker labels
Self-hosted controller that automates Cloudflare Tunnels, DNS records, and Access policies using Docker labels, with a web UI and optional multi-server agents.




