

Octelium
A next-gen FOSS self-hosted unified zero trust secure access platform that can operate as a remote access VPN, a ZTNA/BeyondCorp platform, API/AI gateway, a PaaS, and more.
Features
Properties
- Lightweight
- Privacy focused
Features
- Built-in VPN
- WireGuard
- No registration required
- AES-256 Encryption
- End-to-End Encryption
- Block Trackers
- No Logs
- Multi-Factor Authentication (MFA)
- Model Context Protocol (MCP) Support
Tags
- Tunnel
- VPN Tunnel
- Security Utilities
- Security & Privacy
- zero-trust-network
- ngrok
Octelium News & Activities
Recent activities
acromc added Octelium as alternative to Gravitational Teleport- niksavc liked Octelium
- acromc added Octelium
- POX updated Octelium
Octelium information
What is Octelium?
Octelium is a free and open source, self-hosted, unified platform for zero trust resource access that is primarily meant to be a modern alternative to remote access VPNs and similar tools. It is built to be generic enough to not only operate as a zero-config remote access VPN (i.e. alternative to OpenVPN Access Server, Twingate, Tailscale, etc...), a ZTNA platform (i.e. alternative to Cloudflare Access, Teleport, Google BeyondCorp, etc...), a scalable infrastructure for secure tunnels (i.e. alternative to ngrok), but can also operate as an API gateway, an AI gateway, an infrastructure for MCP gateways and A2A architectures, a PaaS-like platform for secure as well as anonymous hosting and deployment for containerized applications, a Kubernetes gateway/ingress/load balancer and even as an infrastructure for your own homelab. Octelium provides a scalable zero trust architecture (ZTA) for identity-based, application-layer (L7) aware secret-less secure access, via both private client-based access over WireGuard/QUIC tunnels as well as public clientless access (i.e. BeyondCorp), for users, both humans and workloads, to any private/internal resource behind NAT in any environment as well as to publicly protected resources such as SaaS APIs and databases via context-aware access control on a per-request basis through policy-as-code.



