Open-source mesh VPNs and private networks
7 mesh VPNs and private networks whose code is public under an OSI-approved license, rated for privacy with evidence. Picks first, then by score.
Headscale Grade B Our pick
Self-hosted, open-source implementation of the Tailscale coordination server, letting official Tailscale clients join a private network without using Tailscale's hosted service.
BSD-3-Clause. Source code
innernet Grade B
Open-source private network system built on WireGuard, with a self-hosted server that manages peers, CIDR-based groups and access rules.
MIT. Source code
tinc Grade B
Long-running open-source VPN daemon that builds an encrypted mesh between nodes, sending traffic directly to its destination where possible, with no central server.
GPL-2.0 or later. Source code
ionscale Grade B
Open-source, self-hosted Tailscale control server with support for multiple tailnets, OIDC login, ACLs and DNS, used with the official Tailscale clients.
BSD-3-Clause. Source code
Nebula Grade C
Overlay networking tool originally built at Slack that connects hosts over mutually authenticated, encrypted tunnels using its own certificate authority and firewall rules, with self-hosted lighthouse nodes for discovery.
MIT. Source code
NetBird Grade C
WireGuard-based mesh VPN and zero-trust access platform with open-source clients and a management server that can be self-hosted or used as NetBird's hosted service.
BSD-3-Clause for the clients and AGPL-3.0 for the management, signal and relay servers. Source code
OpenZiti Grade D
Open-source zero-trust networking platform from NetFoundry that connects apps and devices through an overlay of self-hosted routers and a controller, with tunneler apps and SDKs.
Apache-2.0. Source code
Compare all 17 mesh VPNs and private networks, open source or not.