ZeroTier
Global software-defined networking
Install with Homebrew
brew install --cask zerotier-one
ZeroTier — Official Website
Quick Take: ZeroTier
ZeroTier One remains a reliable Mac client for virtual Ethernet overlays in August 2026, with a maintained 1.16.x line and clear device-based cloud pricing. It is excellent for labs, mixed OS fleets, and LAN-shaped apps over the internet. Revisit Tailscale/NetBird if identity-first WireGuard UX or seat economics fit better.
Best For
- •Homelabs needing simple cross-NAT Ethernet-style access
- •Mixed IoT + laptop fleets
- •Teams that prefer device-priced overlays
What is ZeroTier One?
ZeroTier One is the cross-platform client that joins your Mac (and nearly every other OS) to ZeroTier virtual networks. Where classic VPNs hairpin all traffic through a central concentrator, ZeroTier builds encrypted peer-to-peer paths that behave like a global virtual Ethernet switch, Layer 2 semantics, stable virtual MACs/IPs, and controllable bridging for labs and edge devices. As of August 2026 the supported desktop/mobile client line is ZeroTier One 1.16.x (1.16.2 released 20 May 2026), with macOS 10.13+ packages still published on the official download page. The control plane story evolved too: ZeroTier Central has a New Central experience for organizations created after 5 November 2025 alongside Legacy Central for older accounts. Pricing on the platform side is device-based: Personal free (10 devices, 1 network, 1 admin), Essential at $18/month for 10 devices ($2 per extra device), Scale at $179/month for 100 devices ($1.80 per extra device), plus Enterprise and Quantum custom tiers that include post-quantum-oriented options. On a Mac, ZeroTier One appears as a menu-bar app plus a background service. You paste a 16-digit Network ID, authorize the node in Central (or via API/automation), and traffic flows. Advanced users push managed routes, flow rules, and SSO-connected admin workflows on paid tiers. Competitors such as Tailscale, NetBird, and self-hosted Headscale remain the usual comparison set, especially after Tailscale's 2026 seat-pricing changes pushed some homelabs to re-evaluate device-priced meshes. ZeroTier One is actively developed, not discontinued. Choose it when you want Ethernet-like multiprotocol flexibility (including non-IP oddities in some setups), broad IoT/embedded reach, and a client that is thin enough to script. Choose something else when identity-first WireGuard meshes with MagicDNS ergonomics matter more than virtual L2. If you manage Macs, verify the app's Gatekeeper signature and grant Full Disk Access only when a workflow truly needs it. After major macOS upgrades, recheck Login Items and network extension approvals, and keep a known-good installer handy. Judge any networking or productivity tool on your own numbers: cold start, RAM use after an hour, extension or driver stability, and what the price looks like after a year of adding devices. Rely on the vendor docs and GitHub release notes first, pricing pages and download pages are the authority, not roundup posts. Treat chatter on X as a slow signal, pay attention when many people report breakage after an update, ignore single angry threads. For open source dependencies, confirm the project still tags releases, answers issues and ships security fixes, stars are not proof of maintenance. Apple Silicon runs native builds well, but Rosetta-only helpers can still hurt battery during long sessions. Keep your config in dotfiles or MDM, leave auto-updates on, use least privilege and phishing resistant auth where you can, and do not trust random mirrors. For CI, use short-lived joins so headless runners do not quietly inflate your device count toward Essential overage. If you advertise a LAN route from a Mac, mark which machine is the router, two routers fighting creates asymmetric routing. Export your Central network config when your plan allows, rebuilding flow rules from memory is painful. Remember iOS uses VPN profiles while macOS uses system extensions, so train users on both. Finally, price out 25, 50 and 100 devices against Tailscale seats before you standardize.
Deep Dive: Client versus control plane
Why ZeroTier One feels like a VPN app but is really a network hypervisor endpoint.
History & Background
ZeroTier spent years as a developer-favorite overlay before formalizing device-based commercial tiers. The 1.16 era continues that commercialization while keeping a free Personal on-ramp.
How It Works
Each One client is a peer. Controllers distribute configuration. Data tries to go P2P; relays save connectivity. Flow rules evaluate paths similarly to distributed ACLs.
Ecosystem & Integrations
Routers, NAS packages, Docker sidecars, and mobile clients extend the same Network ID concept. Mac users usually only see the menu bar tip of that iceberg.
Future Development
Watch Quantum cryptography options, Central UX unification, and how Essential 'coming soon' feature flags land for smaller businesses.
Key Features
Virtual Ethernet Overlay
Creates global L2-ish networks so devices look local even across NATs and mobile networks. Useful for games, labs, and appliances that assume LAN semantics.
Peer-to-Peer with Relays
Nodes attempt direct paths and fall back to ZeroTier infrastructure when hole punching fails. Paid tiers expand relay and admin capabilities.
Menu Bar Client + CLI
On macOS, join/leave networks from the menu bar or automate with the zerotier-cli. Status, networks, and peers are inspectable without a heavy GUI suite.
Central Authorization & Flow Rules
Nodes must be authorized. Flow rules and managed routes let admins shape which peers talk, similar in spirit to a distributed firewall.
Cross-Platform Reach
Clients exist for macOS, Windows, Linux, iOS, Android, NAS appliances, and more, handy when your 'network' includes a Pi, a cloud VM, and a MacBook.
1.16 Platform & Licensing Updates
The 1.16 line brought licensing/model updates for bundling, mobile custom root sets, and continued macOS tun/tap polish through 1.16.2 fixes in May 2026.
SSO & Admin Controls on Paid Plans
Essential and above add business licensing features such as more networks/admins and OIDC-oriented admin patterns; Enterprise/Quantum expand compliance and sovereignty options.
Who Should Use ZeroTier?
1Homelab Operator
A Mac mini at home, a VPS, and a travel MacBook join one free Personal network so SSH and HTTPS to internal services work without opening router ports.
2Small MSP
A consultant places customer edge devices on Essential, automates authorization via API, and keeps admin seats limited while device count scales at $2 each.
3Game Server Host
Friends join a ZeroTier network to play LAN-only games over the internet with fewer CGNAT tears than DIY WireGuard for non-technical players.
4IoT Prototyper
Embedded boards and laptops share a network for MQTT and firmware work where virtual Ethernet behavior is more convenient than pure L3 tunnels.
How to Install ZeroTier One on Mac
Install the official PKG from zerotier.com/download or use package managers that track upstream. Current advertised macOS support starts at 10.13+.
Download ZeroTier One
Get the macOS PKG for version 1.16.x from https://www.zerotier.com/download/ and install it.
Allow system extension / network permissions
Approve prompts in System Settings so the virtual interface can run. On newer macOS releases, check Login Items and Network Extensions if join fails.
Create or copy a Network ID
In ZeroTier Central (New or Legacy, depending on account age), create a network and copy the 16-digit ID.
Join and authorize
From the menu bar choose Join Network, paste the ID, then authorize the device in Central before expecting traffic.
Optional CLI checks
Use zerotier-cli status and zerotier-cli listnetworks to verify online state and assigned addresses.
Pro Tips
- • Stay on supported 1.16.x (or vendor-supported prior majors) for security fixes.
- • Do not publish Network IDs publicly if your network auto-authorizes, prefer manual auth.
- • For travel networks, test both Wi-Fi and LTE paths; some captive portals block UDP hole punching until you authenticate.
Configuration Tips
Name devices in Central immediately
Default node names are opaque. Rename MacBooks and servers so flow-rule mistakes are obvious.
Prefer managed routes over ad-hoc IP memory
Publish LAN routes intentionally from a single exit/subnet router node instead of teaching humans raw addresses.
Separate lab and production networks
Personal free allows one network, when you outgrow it, split environments rather than flat-connecting everything.
Alternatives to ZeroTier
Mesh VPN and overlay alternatives on Mac in 2026.
Tailscale
WireGuard mesh with identity-provider login and MagicDNS. Often easier for humans-as-seats; pricing is seat-oriented after 2026 v4 changes.
NetBird
Open-source WireGuard mesh with self-host options; frequently evaluated when ZeroTier device math or SSO packaging does not fit.
Headscale
Self-hosted Tailscale-compatible control plane for teams that want Tailscale clients without SaaS control.
WireGuard (stock)
Minimal, fast, DIY. Choose stock WireGuard when you will manage keys and endpoints yourself.
Pricing
ZeroTier One the client is free to download. Platform plans (August 2026): Personal free forever with 10 devices, 1 network, and 1 admin; Essential $18/month includes 10 devices then $2.00 per additional device/month, 10 networks, 5 admins; Scale $179/month includes 100 devices then $1.80 per additional device/month, unlimited networks, 10 admins; Enterprise and Quantum are custom (compliance, self-host, PQ-oriented features). Charities/education can request discounts. Client version 1.16.2 is current in the 1.16 line.
Pros
- ✓Simple join UX for non-experts via Network ID
- ✓True multi-platform client including Mac menu bar
- ✓Virtual Ethernet flexibility beyond pure WireGuard L3
- ✓Generous free 10-device Personal tier for labs
- ✓Active 1.16.x maintenance into 2026
Cons
- ✗Device pricing can exceed seat-priced meshes at scale
- ✗Free tier limited to one network and one admin
- ✗Central split (New vs Legacy) can confuse long-time users
- ✗Some enterprises prefer identity-first WireGuard ecosystems
- ✗Relay dependency when P2P fails can add latency
Community & Support
Support spans docs.zerotier.com, community forums, and ticketed support on paid plans. On X, operators still share homelab and tactical networking setups, while ZeroTier markets Quantum/post-quantum networking for public sector via partners. Homelab users celebrate free Personal until the 10-device cap forces Essential.
Video Tutorials
Getting Started with ZeroTier
More Tutorials
How to Setup and Use ZeroTier - What is it and how does it work?
Learn How-To • 42.2K views
Work Remotely Using ZEROTIER & Remote Desktop / Securely connect with zero config !
IT Networks & Security • 5.5K views
"ZeroTier Remote Desktop Setup – Easy & Secure!"
Wire Network • 8.7K views
Frequently Asked Questions about ZeroTier
About the Author
Expert Tips for ZeroTier
Homelab chatter still treats ZeroTier as the 'paste a network ID and go' path for friends and appliances, with pricing pain appearing only after device sprawl beyond ten nodes.
Official materials increasingly emphasize New Central and higher-tier Quantum/compliance stories, so free users should not expect enterprise SSO packaging on Personal.
Related Technologies & Concepts
Related Topics
Sources & References
Fact-CheckedLast verified: Aug 9, 2026
Key Verified Facts
- Personal plan includes 10 devices, 1 network, and 1 admin at $0.[cite-1]
- Essential is $18/month for 10 devices with $2 per additional device per month.[cite-1]
- ZeroTier One 1.16.2 was released on 20 May 2026 and is advertised on the download page.[cite-2, cite-3]
- 1ZeroTier Pricing
Accessed Aug 9, 2026
"Personal free 10 devices; Essential $18; Scale $179; Enterprise/Quantum custom."
- 2
- 3
- 4
- 5
- 6NetBird ZeroTier alternatives context
Accessed Aug 9, 2026
"Competitive framing versus WireGuard meshes."
Research queries: ZeroTier One 1.16.2; ZeroTier pricing Essential Scale; ZeroTier Mac download