FAQ

Answers to common questions about Pangolin.

What is Pangolin?

Pangolin is an open-source security and networking platform. It unifies a WireGuard-based VPN, reverse proxy, privileged access, and an identity-aware AI Gateway under one identity and policy model.

Use it to connect to private apps, infrastructure, and AI workloads. Read more on How Pangolin Works.

Is Pangolin open source?

Yes. The core platform is open source under a dual license and self-hostable. Community Edition is licensed under AGPLv3. The Enterprise Edition uses the Fossorial Commercial License. All code including Enterprise Edition code is available on GitHub.

What license does Pangolin use?

Community Edition uses AGPLv3. Enterprise Edition uses the Fossorial Commercial License. Pangolin Cloud is governed by the Terms of Service and Privacy Policy.

Should I use Pangolin Cloud or self-host?

Choose Pangolin Cloud if you want the fastest, most scalable option where Pangolin operates and manages the control plane. You still run the lightweight connectors at your sites.

Self-host everything if you want the full stack on your own infrastructure for cost control or compliance. Community Edition is free. Paid self-hosted plans add enterprise features, commercial licensing, and higher limits. Compare options on the pricing page.

Does Pangolin replace a VPN?

Pangolin replaces a traditional remote-access VPN. Users install a Pangolin Client, sign in with identity, then reach only the apps, hosts, and infrastructure that admins allow them to see, all over peer-to-peer WireGuard-based tunnels.

It also covers clientless web access through an identity-aware reverse proxy, so end-users don't always have to download and connect with a client. See Zero Trust Access for the product overview.

How does Pangolin differ from a VPN?

A traditional VPN puts users on the private network. Once connected, they can often reach anything that network allows. Pangolin is resource-centric: users reach only the apps, hosts, and ranges you grant, under one identity and policy model.

It also includes reverse proxy capabilities that a VPN does not. Public resources serve HTTP, APIs, SSH, RDP, VNC, and AI Gateway in the browser. Private resources work like a zero-trust VPN through the Pangolin client. Read Pangolin vs. Proxy vs. VPN.

Is Pangolin a mesh VPN?

Pangolin is not a mesh VPN but is similar. It uses a hub-and-spoke model: you deploy site connectors on your networks, and clients connect to those sites to reach only the resources you grant. Clients do not form a mesh with each other, and sites do not connect to other sites.

That client-to-resource model keeps access control easy. You choose which users can reach which resources, instead of isolating which nodes on an overlay can connect to each other and what traffic they can send, often with complicated ACLs. The control plane coordinates identity, discovery, and NAT traversal. See Pangolin vs. Proxy vs. VPN.

Can Pangolin replace Tailscale?

Yes, for teams that want identity-based access to apps, hosts, and infrastructure rather than building an overlay network or device mesh. Tailscale creates an overlay where devices peer with each other, and you typically control that with ACLs that decide which nodes can connect and what traffic they can send. Pangolin grants users access to specific resources behind site connectors, so you say which users can access which resources. It also covers clientless web access through an identity-aware reverse proxy.

If every laptop and server needs to talk to every other node, a mesh VPN is a closer fit. If you want to publish resources and enforce identity and policy, Pangolin is built for that. Compare in Pangolin vs. Tailscale and Pangolin vs. Proxy vs. VPN.

Does Pangolin use WireGuard?

Yes. Pangolin uses WireGuard for encrypted tunnels between clients, site connectors, and the Pangolin server. Site backhaul, peer-to-peer client connections, and relayed traffic all ride on WireGuard.

WireGuard is the underlying transport layer. Pangolin adds identity, resource-level policy, NAT traversal, and an identity-aware reverse proxy on top. See Pangolin vs. WireGuard for how the platform differs from running WireGuard on its own.

Do I need to open inbound firewall ports?

Pangolin uses NAT traversal and intelligent routing, so inbound ports on your sites can remain closed.

For the reverse proxy, this means outbound tunnels from site connectors to Pangolin. For clients connecting to Pangolin sites, connections go peer-to-peer through firewall hole punching, or relay through the Pangolin server. Read more in How Pangolin Punches Through NATs and Firewalls.

How does identity and SSO work?

Users authenticate through your identity provider with SSO and MFA. Pangolin then enforces roles and resource policies on every connection.

Cloud Team and above, and paid self-hosted plans, add external identity providers, RBAC, and related controls. See pricing for what each plan includes.

What resources can I protect with Pangolin?

HTTP apps, TCP services, SSH, RDP, VNC, databases, internal APIs, and AI gateways. Access can be client-based over the Pangolin client or browser-based for web and remote desktop workflows.

Read about all resource types in Understanding Resources.

What is the Pangolin AI Gateway?

AI Gateway is an identity-aware resource on the same platform as your apps and infrastructure. It tunnels coding agents and other AI workloads to major cloud providers and self-hosted models, with budgets, session logs, and the identities you already use. It leverages Pangolin tunneling to authenticate users to AI providers and to serve self-hosted models.

Learn more on the AI Gateway page.

How much does Pangolin cost?

Cloud Basic and self-hosted Community Edition are free. Cloud Team starts at $4/user/mo. Self-hosted Starter and Scale are annual licenses with options for custom limits and SLAs.

The self-hosted Enterprise Edition is entirely free for personal use.

See the full comparison on pricing.

What is included in Community Edition?

Community Edition is the free self-hosted core: sites, resources, users, and community support, licensed under AGPLv3.

SSO, RBAC, audit logging, high availability, and more related enterprise controls are on paid self-hosted plans.

Is the Enterprise Edition free for personal use?

Yes. Self-hosted Enterprise Edition is free for personal, non-commercial use, such as personal learning and hobby projects. It is also free for small-scale commercial use when your organization's gross annual revenue is under $100,000 USD.

Organizations above that threshold need a paid commercial license. Eligibility is defined in the Fossorial Commercial License.

Do government, education, or other public-sector organizations qualify for a free license?

The free personal license is for individuals and for qualifying small-scale commercial use under the revenue threshold. Government agencies, municipalities, cities, counties, public universities, colleges, school districts, K-12 schools, research institutions, and other public-sector or educational organizations are not treated as personal use.

Those deployments need a paid Enterprise license. We sometimes offer discounts for public-sector and education. Contact us with details about your institution.

How do I generate a free personal Enterprise Edition license key?

Create a free Pangolin Cloud account, then create an organization. Open Billing & Licenses in the dashboard, complete the license application, and your key is issued as soon as it is approved.

The full walkthrough is in the Enterprise Edition licensing docs. You can also start from the self-hosted pricing page.

How can I request a trial license key for my business?

Request a free limited trial of Enterprise Edition from the self-hosted pricing page. Submit the trial form with your organization details and use case, and we will reach out with a trial key.

If you already know you need a commercial license, purchase Starter or Scale or contact us for a custom Enterprise agreement.

Is Pangolin SOC 2 and ISO 27001 certified?

Fossorial maintains SOC 2 Type 2 and ISO 27001 certifications. Controls, subprocessors, and reports are in the Trust Center.

How do I get support?

Community users can ask in Slack or Discord. Paid Cloud and Enterprise plans include vendor support, with priority support and an SLA on Enterprise.

For sales or a named contact, use the contact form or book a meeting.

Is there a Pangolin client for desktop and mobile?

Yes. Install the Pangolin client for macOS, Windows, Linux, iOS, and Android from Downloads. The client is used for private resources, peer-to-peer tunnels, and keyless AI Gateway access.

Can MSPs and resellers use Pangolin?

Yes. The partner program covers resale, referrals, and implementation, with deal registration and a partner portal. Start at Partners.

How do I get started?

Create a Cloud account, or follow the quick install to self-host. Download a client when you need private resource access.

If you want a walkthrough, book a demo.