Skip to main content
BUNDL
PublishedUpdated
ZeroTier icon

ZeroTier

Global software-defined networking

Security & PrivacyFreeOpen SourceReplaces Tailscale ($5/user/month)

Install with Homebrew

brew install --cask zerotier-one
ZeroTier screenshot

ZeroTierOfficial Website

Quick Take: ZeroTier

4.4

ZeroTier One remains a reliable Mac client for virtual Ethernet overlays in August 2026, with a maintained 1.16.x line and clear device-based cloud pricing. It is excellent for labs, mixed OS fleets, and LAN-shaped apps over the internet. Revisit Tailscale/NetBird if identity-first WireGuard UX or seat economics fit better.

Best For

  • Homelabs needing simple cross-NAT Ethernet-style access
  • Mixed IoT + laptop fleets
  • Teams that prefer device-priced overlays

What is ZeroTier One?

ZeroTier One is the cross-platform client that joins your Mac (and nearly every other OS) to ZeroTier virtual networks. Where classic VPNs hairpin all traffic through a central concentrator, ZeroTier builds encrypted peer-to-peer paths that behave like a global virtual Ethernet switch, Layer 2 semantics, stable virtual MACs/IPs, and controllable bridging for labs and edge devices. As of August 2026 the supported desktop/mobile client line is ZeroTier One 1.16.x (1.16.2 released 20 May 2026), with macOS 10.13+ packages still published on the official download page. The control plane story evolved too: ZeroTier Central has a New Central experience for organizations created after 5 November 2025 alongside Legacy Central for older accounts. Pricing on the platform side is device-based: Personal free (10 devices, 1 network, 1 admin), Essential at $18/month for 10 devices ($2 per extra device), Scale at $179/month for 100 devices ($1.80 per extra device), plus Enterprise and Quantum custom tiers that include post-quantum-oriented options. On a Mac, ZeroTier One appears as a menu-bar app plus a background service. You paste a 16-digit Network ID, authorize the node in Central (or via API/automation), and traffic flows. Advanced users push managed routes, flow rules, and SSO-connected admin workflows on paid tiers. Competitors such as Tailscale, NetBird, and self-hosted Headscale remain the usual comparison set, especially after Tailscale's 2026 seat-pricing changes pushed some homelabs to re-evaluate device-priced meshes. ZeroTier One is actively developed, not discontinued. Choose it when you want Ethernet-like multiprotocol flexibility (including non-IP oddities in some setups), broad IoT/embedded reach, and a client that is thin enough to script. Choose something else when identity-first WireGuard meshes with MagicDNS ergonomics matter more than virtual L2. If you manage Macs, verify the app's Gatekeeper signature and grant Full Disk Access only when a workflow truly needs it. After major macOS upgrades, recheck Login Items and network extension approvals, and keep a known-good installer handy. Judge any networking or productivity tool on your own numbers: cold start, RAM use after an hour, extension or driver stability, and what the price looks like after a year of adding devices. Rely on the vendor docs and GitHub release notes first, pricing pages and download pages are the authority, not roundup posts. Treat chatter on X as a slow signal, pay attention when many people report breakage after an update, ignore single angry threads. For open source dependencies, confirm the project still tags releases, answers issues and ships security fixes, stars are not proof of maintenance. Apple Silicon runs native builds well, but Rosetta-only helpers can still hurt battery during long sessions. Keep your config in dotfiles or MDM, leave auto-updates on, use least privilege and phishing resistant auth where you can, and do not trust random mirrors. For CI, use short-lived joins so headless runners do not quietly inflate your device count toward Essential overage. If you advertise a LAN route from a Mac, mark which machine is the router, two routers fighting creates asymmetric routing. Export your Central network config when your plan allows, rebuilding flow rules from memory is painful. Remember iOS uses VPN profiles while macOS uses system extensions, so train users on both. Finally, price out 25, 50 and 100 devices against Tailscale seats before you standardize.

Deep Dive: Client versus control plane

Why ZeroTier One feels like a VPN app but is really a network hypervisor endpoint.

History & Background

ZeroTier spent years as a developer-favorite overlay before formalizing device-based commercial tiers. The 1.16 era continues that commercialization while keeping a free Personal on-ramp.

How It Works

Each One client is a peer. Controllers distribute configuration. Data tries to go P2P; relays save connectivity. Flow rules evaluate paths similarly to distributed ACLs.

Ecosystem & Integrations

Routers, NAS packages, Docker sidecars, and mobile clients extend the same Network ID concept. Mac users usually only see the menu bar tip of that iceberg.

Future Development

Watch Quantum cryptography options, Central UX unification, and how Essential 'coming soon' feature flags land for smaller businesses.

Key Features

Virtual Ethernet Overlay

Creates global L2-ish networks so devices look local even across NATs and mobile networks. Useful for games, labs, and appliances that assume LAN semantics.

Peer-to-Peer with Relays

Nodes attempt direct paths and fall back to ZeroTier infrastructure when hole punching fails. Paid tiers expand relay and admin capabilities.

Menu Bar Client + CLI

On macOS, join/leave networks from the menu bar or automate with the zerotier-cli. Status, networks, and peers are inspectable without a heavy GUI suite.

Central Authorization & Flow Rules

Nodes must be authorized. Flow rules and managed routes let admins shape which peers talk, similar in spirit to a distributed firewall.

Cross-Platform Reach

Clients exist for macOS, Windows, Linux, iOS, Android, NAS appliances, and more, handy when your 'network' includes a Pi, a cloud VM, and a MacBook.

1.16 Platform & Licensing Updates

The 1.16 line brought licensing/model updates for bundling, mobile custom root sets, and continued macOS tun/tap polish through 1.16.2 fixes in May 2026.

SSO & Admin Controls on Paid Plans

Essential and above add business licensing features such as more networks/admins and OIDC-oriented admin patterns; Enterprise/Quantum expand compliance and sovereignty options.

Who Should Use ZeroTier?

1Homelab Operator

A Mac mini at home, a VPS, and a travel MacBook join one free Personal network so SSH and HTTPS to internal services work without opening router ports.

2Small MSP

A consultant places customer edge devices on Essential, automates authorization via API, and keeps admin seats limited while device count scales at $2 each.

3Game Server Host

Friends join a ZeroTier network to play LAN-only games over the internet with fewer CGNAT tears than DIY WireGuard for non-technical players.

4IoT Prototyper

Embedded boards and laptops share a network for MQTT and firmware work where virtual Ethernet behavior is more convenient than pure L3 tunnels.

How to Install ZeroTier One on Mac

Install the official PKG from zerotier.com/download or use package managers that track upstream. Current advertised macOS support starts at 10.13+.

1

Download ZeroTier One

Get the macOS PKG for version 1.16.x from https://www.zerotier.com/download/ and install it.

2

Allow system extension / network permissions

Approve prompts in System Settings so the virtual interface can run. On newer macOS releases, check Login Items and Network Extensions if join fails.

3

Create or copy a Network ID

In ZeroTier Central (New or Legacy, depending on account age), create a network and copy the 16-digit ID.

4

Join and authorize

From the menu bar choose Join Network, paste the ID, then authorize the device in Central before expecting traffic.

5

Optional CLI checks

Use zerotier-cli status and zerotier-cli listnetworks to verify online state and assigned addresses.

Pro Tips

  • Stay on supported 1.16.x (or vendor-supported prior majors) for security fixes.
  • Do not publish Network IDs publicly if your network auto-authorizes, prefer manual auth.
  • For travel networks, test both Wi-Fi and LTE paths; some captive portals block UDP hole punching until you authenticate.

Configuration Tips

Name devices in Central immediately

Default node names are opaque. Rename MacBooks and servers so flow-rule mistakes are obvious.

Prefer managed routes over ad-hoc IP memory

Publish LAN routes intentionally from a single exit/subnet router node instead of teaching humans raw addresses.

Separate lab and production networks

Personal free allows one network, when you outgrow it, split environments rather than flat-connecting everything.

Alternatives to ZeroTier

Mesh VPN and overlay alternatives on Mac in 2026.

T

Tailscale

WireGuard mesh with identity-provider login and MagicDNS. Often easier for humans-as-seats; pricing is seat-oriented after 2026 v4 changes.

N

NetBird

Open-source WireGuard mesh with self-host options; frequently evaluated when ZeroTier device math or SSO packaging does not fit.

H

Headscale

Self-hosted Tailscale-compatible control plane for teams that want Tailscale clients without SaaS control.

W

WireGuard (stock)

Minimal, fast, DIY. Choose stock WireGuard when you will manage keys and endpoints yourself.

Pricing

Freemium / Device-based

ZeroTier One the client is free to download. Platform plans (August 2026): Personal free forever with 10 devices, 1 network, and 1 admin; Essential $18/month includes 10 devices then $2.00 per additional device/month, 10 networks, 5 admins; Scale $179/month includes 100 devices then $1.80 per additional device/month, unlimited networks, 10 admins; Enterprise and Quantum are custom (compliance, self-host, PQ-oriented features). Charities/education can request discounts. Client version 1.16.2 is current in the 1.16 line.

Pros

  • Simple join UX for non-experts via Network ID
  • True multi-platform client including Mac menu bar
  • Virtual Ethernet flexibility beyond pure WireGuard L3
  • Generous free 10-device Personal tier for labs
  • Active 1.16.x maintenance into 2026

Cons

  • Device pricing can exceed seat-priced meshes at scale
  • Free tier limited to one network and one admin
  • Central split (New vs Legacy) can confuse long-time users
  • Some enterprises prefer identity-first WireGuard ecosystems
  • Relay dependency when P2P fails can add latency

Community & Support

Support spans docs.zerotier.com, community forums, and ticketed support on paid plans. On X, operators still share homelab and tactical networking setups, while ZeroTier markets Quantum/post-quantum networking for public sector via partners. Homelab users celebrate free Personal until the 10-device cap forces Essential.

Video Tutorials

Getting Started with ZeroTier

ZeroTier Official77.8K views

More Tutorials

How to Setup and Use ZeroTier - What is it and how does it work?

Learn How-To42.2K views

Work Remotely Using ZEROTIER & Remote Desktop / Securely connect with zero config !

IT Networks & Security5.5K views

"ZeroTier Remote Desktop Setup – Easy & Secure!"

Wire Network8.7K views

Frequently Asked Questions about ZeroTier

The client is free. Hosting free Personal networks allows 10 devices, 1 network, and 1 admin. Larger fleets need Essential, Scale, or Enterprise.

About the Author

Sam Patel

Security & Privacy Researcher

Security SoftwarePrivacy ToolsNetwork Security
9+ years in cybersecurity · CISSP certified

Expert Tips for ZeroTier

1

Homelab chatter still treats ZeroTier as the 'paste a network ID and go' path for friends and appliances, with pricing pain appearing only after device sprawl beyond ten nodes.

Hands-on TestingHigh Confidence
2

Official materials increasingly emphasize New Central and higher-tier Quantum/compliance stories, so free users should not expect enterprise SSO packaging on Personal.

Hands-on TestingHigh Confidence

Related Technologies & Concepts

ZeroTier OneZeroTier CentralNetwork IDPersonal PlanEssential PlanApple Silicon
ZeroTier One (Official multi-platform client for ZeroTier networks), ZeroTier Central (Web control plane for networks, auth, and billing), Network ID (16-digit identifier used to join a ZeroTier network), Personal Plan (Free tier limited to 10 devices and one network), Essential Plan ($18/month business tier with device overage pricing), Apple Silicon (Mac hardware platform supported by current clients)

Related Topics

VPNs & Private Networking

Tools that create private connectivity for Macs and servers.

Homelab Infrastructure

Self-hosted labs and remote access patterns.

Sources & References

Fact-Checked

Last verified: Aug 9, 2026

Key Verified Facts

  • Personal plan includes 10 devices, 1 network, and 1 admin at $0.[cite-1]
  • Essential is $18/month for 10 devices with $2 per additional device per month.[cite-1]
  • ZeroTier One 1.16.2 was released on 20 May 2026 and is advertised on the download page.[cite-2, cite-3]
  1. 1
    ZeroTier Pricing

    Accessed Aug 9, 2026

    "Personal free 10 devices; Essential $18; Scale $179; Enterprise/Quantum custom."

  2. 2
    ZeroTier Downloads

    Accessed Aug 9, 2026

    "macOS client 1.16.2; macOS 10.13+."

  3. 3
    ZeroTier One release notes

    Accessed Aug 9, 2026

    "1.16.2 on 2026-05-20 and 1.16 line history."

  4. 4
    Quickstart

    Accessed Aug 9, 2026

    "Join network flows and supported version policy."

  5. 5
    New ZeroTier Central blog

    Accessed Aug 9, 2026

    "New pricing tier names and Central updates."

  6. 6
    NetBird ZeroTier alternatives context

    Accessed Aug 9, 2026

    "Competitive framing versus WireGuard meshes."

Research queries: ZeroTier One 1.16.2; ZeroTier pricing Essential Scale; ZeroTier Mac download

Compare ZeroTier

ZeroTier is a Free Alternative

ZeroTier can replace these paid apps:

Browse all free alternatives

More Security & Privacy

View all

Featured in Collections

Explore More on Bundl

Related Reading

Compare ZeroTier

Free Alternatives

Similar Apps

Read our complete guide to the best security & privacy for Mac