# Pangolin

Published January 1, 2026 · Updated August 10, 2026

Identity-aware VPN and proxy for remote access

Category: Developer Tools · Free · Replaces Tailscale ($18/month) · [Official website](https://pangolin.net/)

## Install with Homebrew

`brew install --cask pangolin`

## Quick take

Pangolin (fosrl/pangolin) is a strong identity-aware WireGuard proxy for people who outgrew disposable ngrok URLs but do not want to surrender every origin to Cloudflare. Cloud Basic makes experimentation cheap; AGPL CE and generously licensed EE make serious self-hosting viable for hobbyists and smaller businesses. Browser remoting and SSO put it closer to zero-trust access gateways than dumb tunnels. Ops complexity remains real for self-hosters, and large enterprises may still prefer Twingate or Cloudflare Zero Trust—but for homelabs and indie teams, Pangolin is one of the best open options in 2026.

Best for: Homelab operators exposing apps without port forwarding, Developers who want self-hosted or Fossorial-cloud alternatives to ngrok, Small teams needing SSO-protected internal tools and browser remoting

## What is Pangolin?

Pangolin is an identity-aware VPN and tunneled reverse proxy built on WireGuard by Fossorial Inc. The open-source project lives at github.com/fosrl/pangolin (roughly 22,000 GitHub stars) with current software around version 1.21.1 on pangolin.net. It lets you publish internal apps—homelab dashboards, staging APIs, admin UIs—through encrypted tunnels with HTTPS, SSO, and fine-grained access control instead of opening router ports or handing everyone a full VPN profile.

In practice you run Pangolin either as managed cloud at app.pangolin.net or as self-hosted infrastructure. Clients such as Newt connect private sites; Gerbil handles tunneling; Traefik terminates HTTP with Let's Encrypt certificates. Users reach apps through a browser-based HTTPS proxy and can also open VNC, RDP, or SSH sessions inside the browser when remote desktop or shell access is required. Peer-to-peer paths and paid device posture checks extend the zero-trust story beyond simple password gates.

Compared with ngrok, Cloudflare Tunnel, Tailscale Funnel/Zero Trust, or Twingate, Pangolin emphasizes an identity-aware proxy plus WireGuard transport you can fully self-host under AGPL-3 Community Edition, or run on Fossorial's cloud with freemium seats. Self-hosted Enterprise Edition uses the Fossorial Commercial License and stays free for personal/hobby use and for businesses under $100K revenue. Cloud Basic is free for 5 users, 5 sites, and 5 domains; Team is $4 per user per month; Business is $9 per user per month; Enterprise is custom.

Pangolin targets developers, homelab operators, and small teams who want Cloudflare-Zero-Trust-like access without surrendering all traffic to a third-party edge—or who want a managed option without building Traefik and WireGuard plumbing from scratch. Documentation at docs.pangolin.net covers Docker Compose installs, cloud onboarding, and Enterprise Edition licensing so you can pick the deployment model that matches compliance and ops capacity.

## Features

- **WireGuard Identity-Aware Tunneling.** Pangolin uses WireGuard as the encrypted transport between private sites and the Pangolin control/data plane. Sites connect outbound through Newt and related tunnel components, so home NATs and CGNAT links work without inbound port forwards. The identity-aware proxy then decides who may reach each resource after authentication rather than exposing raw services to the open internet.
- **Browser-Based HTTPS Proxy.** Publish web apps with automatic HTTPS via Traefik and Let's Encrypt. Custom domains map to internal services; Pangolin proxies authenticated browser traffic to the correct backend through the tunnel. This is the primary path for dashboards, admin panels, and internal SaaS replacements that already speak HTTP.
- **VNC, RDP, and SSH in the Browser.** Beyond HTTP apps, Pangolin can present VNC, RDP, and SSH sessions inside the browser so support staff or admins reach desktops and shells without installing a separate VPN client on every device. Access still flows through the same identity policies as web resources, which keeps remote administration inside the zero-trust boundary.
- **Newt Client and Gerbil Tunnel.** Newt is the site/client agent that attaches private networks to Pangolin. Gerbil provides tunnel plumbing so traffic rides WireGuard efficiently between edges. Together they replace ad-hoc SSH reverse tunnels with a managed control plane for multiple sites, domains, and services.
- **SSO, OIDC, and Access Policies.** Integrate OIDC/SSO providers so teammates sign in with existing IdPs instead of sharing long-lived passwords per app. Define per-resource policies for public links, authenticated users, or narrower groups. Paid tiers add device posture checks so access can require healthy, managed endpoints—not only a valid login.
- **Peer-to-Peer Connectivity.** Pangolin supports peer-to-peer paths that keep traffic between participants more direct when network conditions allow, reducing unnecessary hairpinning through a central relay. For latency-sensitive internal tools, P2P complements the reverse-proxy model without abandoning identity controls.
- **Cloud and Self-Hosted Deployment Choices.** Use Fossorial cloud at app.pangolin.net for managed control, or self-host Community Edition (AGPL-3) with Docker Compose from the official docs. Enterprise Edition under the Fossorial Commercial License unlocks commercial terms while remaining free for personal/hobby use and organizations under $100K revenue. Choose cloud for speed, self-host for data-plane sovereignty.

## How to Install Pangolin (Cloud or Self-Hosted)

Pick managed cloud for the fastest path, or self-host Community Edition with Docker Compose when you want the data plane on your VPS.

1. **Choose Cloud or Self-Host.** For cloud, create an account at app.pangolin.net and start on Basic (5 users / 5 sites / 5 domains). For self-host, provision a Linux VPS with a public IP and follow docs.pangolin.net Docker Compose guidance to bring up the stack.
2. **Deploy or Configure the Control Plane.** Self-hosters run the official compose stack so Traefik, Pangolin services, and tunnel components start together. Point DNS for your domains at the VPS or follow cloud DNS instructions. Confirm Let's Encrypt issuance for HTTPS.
3. **Connect Sites with Newt.** Install and authenticate the Newt client on each private site (home server, laptop, office network). Newt establishes the WireGuard-backed tunnel so Pangolin can reach internal listeners without inbound NAT holes.
4. **Publish Resources and Policies.** In the dashboard, add HTTPS resources, optional VNC/RDP/SSH targets, domains, and SSO/OIDC providers. Attach access policies per resource. Upgrade to Team, Business, or Enterprise if you need more seats, posture, or commercial terms.

## Pros

- Identity-aware WireGuard reverse proxy with real SSO/OIDC controls
- Browser HTTPS proxy plus in-browser VNC/RDP/SSH for admin workflows
- Choice of Fossorial cloud or AGPL-3 self-hosted Community Edition
- Enterprise Edition free for hobbyists and sub-$100K-revenue businesses under commercial license terms
- Newt/Gerbil/Traefik/Let's Encrypt stack documented for Docker Compose
- Peer-to-peer options and paid device posture for stronger zero trust
- Transparent cloud tiers starting with a usable free Basic plan

## Cons

- Self-hosting still requires a public VPS, DNS, and ongoing updates
- More moving parts than one-command ngrok tunnels
- AGPL-3 CE licensing may not fit every company's distribution model without EE
- Device posture and higher seat counts require paid cloud or commercial EE paths
- Smaller ecosystem mindshare than Cloudflare Tunnel or Tailscale

## Deep Dive: Identity-Aware Tunnels Without Surrendering the Edge

Pangolin sits at the intersection of reverse proxies, WireGuard VPNs, and zero-trust access gateways.

## FAQ

### Is Pangolin the same as nicklama/pangolin?

No. The Fossorial product documented here is github.com/fosrl/pangolin. Older materials that cited nicklama/pangolin were wrong and should be ignored. Use fosrl/pangolin, pangolin.net, and docs.pangolin.net as canonical sources.

### How is Pangolin different from ngrok?

ngrok optimizes one-command ephemeral tunnels and request inspection through ngrok's cloud. Pangolin focuses on identity-aware, longer-lived publishing with WireGuard, SSO, browser remoting, and optional full self-hosting. Use ngrok for quick webhook demos; use Pangolin for authenticated ongoing access.

### Do I need a VPS?

Not if you use Fossorial cloud at app.pangolin.net. Self-hosted Community or Enterprise Edition needs a publicly reachable host (typically a small VPS) plus DNS. Cloud Basic can cover small homelab setups within the 5/5/5 free limits.

### What does Pangolin cost?

Cloud: Basic free (5 users, 5 sites, 5 domains), Team $4/user/month, Business $9/user/month, Enterprise custom. Self-host CE is free under AGPL-3. EE uses Fossorial's commercial license and is free for personal/hobby and businesses under $100K revenue. Always confirm on pangolin.net/pricing and EE docs.

### Can Pangolin replace a traditional VPN?

For browser-reachable web apps and in-browser VNC/RDP/SSH, often yes. For arbitrary non-HTTP protocols or full network routes, you may still want Tailscale, a classic VPN, or Pangolin features beyond simple HTTP proxying. Many teams mix: Pangolin for apps, mesh VPN for raw network access.

### What are Newt and Gerbil?

Newt is the client/site agent that connects private networks to Pangolin. Gerbil participates in the tunnel path that carries traffic over WireGuard-oriented plumbing. Together with Traefik and Let's Encrypt they form the usual self-host data path described in Fossorial docs.

### Does Pangolin support SSO?

Yes. OIDC/SSO integrations let you require organizational logins before resources load. Pair SSO with per-resource policies and, on paid offerings, device posture for stronger zero-trust guarantees.

### Is the project actively maintained?

Yes. fosrl/pangolin is actively developed with recent 1.21.x releases advertised on pangolin.net and documentation continuously updated at docs.pangolin.net. Check GitHub releases for exact patch versions.

## Sources

- [Pangolin Official Website](https://pangolin.net/)
- [Pangolin Pricing](https://pangolin.net/pricing)
- [fosrl/pangolin on GitHub](https://github.com/fosrl/pangolin)
- [Pangolin Documentation](https://docs.pangolin.net/)
- [Pangolin Docker Compose Self-Host Manual](https://docs.pangolin.net/self-host/manual/docker-compose)
- [Pangolin Enterprise Edition](https://docs.pangolin.net/self-host/enterprise-edition)
- [Pangolin Cloud Signup](https://app.pangolin.net)

## Related

- [Cursor](https://bundl.run/apps/cursor)
- [Claude Code](https://bundl.run/apps/claude-code)
- [ChatGPT](https://bundl.run/apps/chatgpt)
- [Claude](https://bundl.run/apps/claude)
- [Codex](https://bundl.run/apps/codex)
- [Windsurf](https://bundl.run/apps/windsurf)
- [Pangolin vs Tailscale](https://bundl.run/compare/pangolin-vs-tailscale)
- [Pangolin vs ZeroTier](https://bundl.run/compare/pangolin-vs-zerotier)
- [Free alternative to Tailscale](https://bundl.run/https:/)

```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "Organization",
      "@id": "https://bundl.run/#organization",
      "name": "Bundl.run",
      "url": "https://bundl.run",
      "logo": {
        "@type": "ImageObject",
        "url": "https://bundl.run/og-image.png",
        "width": 1200,
        "height": 630
      },
      "description": "The Ninite for Mac. Install all your essential Mac apps with one terminal command.",
      "sameAs": [
        "https://github.com/abhiofficial/bundl-mac-setup",
        "https://x.com/bundlrun",
        "https://www.producthunt.com/products/bundl-run"
      ],
      "foundingDate": "2024",
      "contactPoint": {
        "@type": "ContactPoint",
        "contactType": "customer support",
        "url": "https://bundl.run/faq"
      }
    },
    {
      "@type": "WebSite",
      "@id": "https://bundl.run/#website",
      "name": "Bundl.run",
      "url": "https://bundl.run",
      "description": "The Ninite for Mac. Install all your essential Mac apps with one terminal command.",
      "publisher": {
        "@id": "https://bundl.run/#organization"
      },
      "inLanguage": "en-US"
    },
    {
      "@type": "Person",
      "@id": "https://bundl.run/authors/alex-chen#person",
      "name": "Alex Chen",
      "jobTitle": "Senior Developer Tools Specialist",
      "url": "https://bundl.run/authors/alex-chen",
      "worksFor": {
        "@id": "https://bundl.run/#organization"
      },
      "description": "Alex Chen has been evaluating developer tools and productivity software for over 12 years, with deep expertise in code editors, terminal emulators, and development environments. As a former software engineer at several Bay Area startups, Alex brings hands-on experience with the real-world workflows these tools are meant to enhance. Alex tests each application extensively on both Intel and Apple Silicon Macs, documenting performance metrics, integration capabilities, and workflow efficiency. When not reviewing software, Alex contributes to open-source projects and writes technical tutorials for the developer community.",
      "knowsAbout": [
        "Code Editors & IDEs",
        "Terminal Emulators",
        "Version Control Tools",
        "DevOps & CI/CD",
        "API Development",
        "Performance Benchmarking"
      ],
      "image": "https://bundl.run/authors/alex-chen.svg"
    },
    {
      "@type": "BreadcrumbList",
      "@id": "https://bundl.run/apps/pangolin#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://bundl.run"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Apps",
          "item": "https://bundl.run/apps"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Pangolin",
          "item": "https://bundl.run/apps/pangolin"
        }
      ]
    },
    {
      "@type": "WebPage",
      "@id": "https://bundl.run/apps/pangolin",
      "url": "https://bundl.run/apps/pangolin",
      "name": "Pangolin for Mac",
      "description": "Identity-aware VPN and proxy for remote access",
      "isPartOf": {
        "@id": "https://bundl.run/#website"
      },
      "publisher": {
        "@id": "https://bundl.run/#organization"
      },
      "inLanguage": "en-US",
      "datePublished": "2026-01-01T00:00:00Z",
      "dateModified": "2026-08-10T13:34:04.000Z",
      "author": {
        "@id": "https://bundl.run/authors/alex-chen#person"
      },
      "mainEntity": {
        "@id": "https://bundl.run/apps/pangolin#software"
      },
      "breadcrumb": {
        "@id": "https://bundl.run/apps/pangolin#breadcrumb"
      }
    },
    {
      "@type": "SoftwareApplication",
      "@id": "https://bundl.run/apps/pangolin#software",
      "name": "Pangolin",
      "description": "Identity-aware VPN and proxy for remote access",
      "applicationCategory": "DeveloperApplication",
      "operatingSystem": "macOS",
      "url": "https://bundl.run/apps/pangolin",
      "image": {
        "@type": "ImageObject",
        "url": "https://img.logo.dev/pangolin.dev",
        "caption": "Pangolin app icon for Mac"
      },
      "sameAs": [
        "https://pangolin.net/",
        "https://formulae.brew.sh/cask/pangolin"
      ],
      "review": {
        "@type": "Review",
        "author": {
          "@id": "https://bundl.run/authors/alex-chen#person"
        },
        "reviewBody": "Pangolin (fosrl/pangolin) is a strong identity-aware WireGuard proxy for people who outgrew disposable ngrok URLs but do not want to surrender every origin to Cloudflare. Cloud Basic makes experimentation cheap; AGPL CE and generously licensed EE make serious self-hosting viable for hobbyists and smaller businesses. Browser remoting and SSO put it closer to zero-trust access gateways than dumb tunnels. Ops complexity remains real for self-hosters, and large enterprises may still prefer Twingate or Cloudflare Zero Trust—but for homelabs and indie teams, Pangolin is one of the best open options in 2026."
      },
      "about": {
        "@type": "Thing",
        "name": "Pangolin",
        "description": "Identity-aware VPN and proxy for remote access"
      },
      "isPartOf": {
        "@id": "https://bundl.run/#website"
      }
    },
    {
      "@type": "Article",
      "@id": "https://bundl.run/apps/pangolin#article",
      "headline": "Pangolin for Mac — Full Review & Installation Guide 2026",
      "description": "Pangolin (fosrl/pangolin) is a strong identity-aware WireGuard proxy for people who outgrew disposable ngrok URLs but do not want to surrender every origin to Cloudflare. Cloud Basic makes experimentation cheap; AGPL CE and generously licensed EE make serious self-hosting viable for hobbyists and smaller businesses. Browser remoting and SSO put it closer to zero-trust access gateways than dumb tunnels. Ops complexity remains real for self-hosters, and large enterprises may still prefer Twingate or Cloudflare Zero Trust—but for homelabs and indie teams, Pangolin is one of the best open options in 2026.",
      "image": "https://img.logo.dev/pangolin.dev",
      "author": {
        "@id": "https://bundl.run/authors/alex-chen#person"
      },
      "publisher": {
        "@id": "https://bundl.run/#organization"
      },
      "datePublished": "2026-01-01T00:00:00Z",
      "dateModified": "2026-08-10T13:34:04.000Z",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://bundl.run/apps/pangolin"
      },
      "articleSection": "DeveloperApplication",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".key-facts"
        ]
      },
      "about": {
        "@type": "SoftwareApplication",
        "name": "Pangolin",
        "url": "https://bundl.run/apps/pangolin"
      },
      "mentions": [
        {
          "@type": "SoftwareApplication",
          "name": "Tailscale"
        }
      ]
    },
    {
      "@type": "FAQPage",
      "@id": "https://bundl.run/apps/pangolin#faq",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is Pangolin the same as nicklama/pangolin?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. The Fossorial product documented here is github.com/fosrl/pangolin. Older materials that cited nicklama/pangolin were wrong and should be ignored. Use fosrl/pangolin, pangolin.net, and docs.pangolin.net as canonical sources."
          }
        },
        {
          "@type": "Question",
          "name": "How is Pangolin different from ngrok?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "ngrok optimizes one-command ephemeral tunnels and request inspection through ngrok's cloud. Pangolin focuses on identity-aware, longer-lived publishing with WireGuard, SSO, browser remoting, and optional full self-hosting. Use ngrok for quick webhook demos; use Pangolin for authenticated ongoing access."
          }
        },
        {
          "@type": "Question",
          "name": "Do I need a VPS?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Not if you use Fossorial cloud at app.pangolin.net. Self-hosted Community or Enterprise Edition needs a publicly reachable host (typically a small VPS) plus DNS. Cloud Basic can cover small homelab setups within the 5/5/5 free limits."
          }
        },
        {
          "@type": "Question",
          "name": "What does Pangolin cost?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Cloud: Basic free (5 users, 5 sites, 5 domains), Team $4/user/month, Business $9/user/month, Enterprise custom. Self-host CE is free under AGPL-3. EE uses Fossorial's commercial license and is free for personal/hobby and businesses under $100K revenue. Always confirm on pangolin.net/pricing and EE docs."
          }
        },
        {
          "@type": "Question",
          "name": "Can Pangolin replace a traditional VPN?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "For browser-reachable web apps and in-browser VNC/RDP/SSH, often yes. For arbitrary non-HTTP protocols or full network routes, you may still want Tailscale, a classic VPN, or Pangolin features beyond simple HTTP proxying. Many teams mix: Pangolin for apps, mesh VPN for raw network access."
          }
        },
        {
          "@type": "Question",
          "name": "What are Newt and Gerbil?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Newt is the client/site agent that connects private networks to Pangolin. Gerbil participates in the tunnel path that carries traffic over WireGuard-oriented plumbing. Together with Traefik and Let's Encrypt they form the usual self-host data path described in Fossorial docs."
          }
        },
        {
          "@type": "Question",
          "name": "Does Pangolin support SSO?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. OIDC/SSO integrations let you require organizational logins before resources load. Pair SSO with per-resource policies and, on paid offerings, device posture for stronger zero-trust guarantees."
          }
        },
        {
          "@type": "Question",
          "name": "Is the project actively maintained?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. fosrl/pangolin is actively developed with recent 1.21.x releases advertised on pangolin.net and documentation continuously updated at docs.pangolin.net. Check GitHub releases for exact patch versions."
          }
        }
      ],
      "isPartOf": {
        "@id": "https://bundl.run/apps/pangolin"
      }
    }
  ]
}
```