# Pangolin > Open-source SASE platform providing secure access and connectivity to apps, infrastructure, and AI workloads. Connect and protect your users. ## Marketing - [Home](https://pangolin.net/): Open-source SASE platform providing secure access and connectivity to apps, infrastructure, and AI workloads. Connect and protect your users. - [Product](https://pangolin.net/ztna): Open-source SASE unifying a zero-trust VPN, reverse proxy, privileged access, and an identity-aware AI gateway. Open, self-hostable, and simple to deploy. - [AI Gateway](https://pangolin.net/ai-gateway): Tunnel AI workloads to cloud and self-hosted models with Pangolin client tunnels, site connectors, identity-aware access, budgets, and session logs. - [Pricing](https://pangolin.net/pricing): Self-host Community Edition for free, upgrade to Enterprise, or use Pangolin Cloud. Starts at $4/user/mo. Contact us for Enterprise pricing. - [Solutions - Zero Trust Access by Industry](https://pangolin.net/solutions): Explore how Pangolin secures access for different industries and teams with an open, identity-based zero trust platform. - [MSP - Secure Zero Trust Access](https://pangolin.net/solutions/msp): Zero trust remote access for managed service providers. Unify identity-based access across hybrid cloud and on-prem workloads. - [Contact](https://pangolin.net/contact): Contact Pangolin for sales, support, or enterprise inquiries. - [FAQ](https://pangolin.net/faq): Answers to common questions about Pangolin, self-hosting, Cloud, identity, pricing, and support. - [Partner With Us - MSP and Reseller Program](https://pangolin.net/partners): Unlock new opportunities with Pangolin partnerships. Resell, refer, and implement identity-based zero trust access with co-marketing, deal protection, and partner portal support. - [Register a Deal - Partner Program](https://pangolin.net/partners/register-deal): Register your Pangolin sales opportunity to protect your deal and receive partner guidance. ## News & Articles - [News & Articles](https://pangolin.net/news): Stay up to date with the latest product updates, guides, and insights in the zero trust remote access space by reading Pangolin's articles. - [Pangolin 1.24: Exit Nodes and Improved Clients](https://pangolin.net/news/1-24-release): Pangolin 1.24 adds exit nodes, on-demand connections on Mac and iOS, an overhaul of the client UI on Mac and Windows, and a subnet router for Linux machine clients. - [Branch Office Networking with Pangolin](https://pangolin.net/news/branch-office-networking): How to connect branch offices, stores, and factories to a cloud network or to each other with Pangolin subnet routers, using a hub and spoke model with no inbound firewall rules. - [How to Build Your Own Self-Hosted VPN](https://pangolin.net/news/build-your-own-self-hosted-vpn): Build your own self-hosted VPN with Pangolin - [Best Open Source AI Gateways in 2026](https://pangolin.net/news/best-open-source-ai-gateways): Compare the best open source and self-hosted AI gateways in 2026, including LiteLLM, Bifrost, Pangolin, Portkey Gateway, and Kong AI Gateway. - [What Is an AI Gateway?](https://pangolin.net/news/what-is-an-ai-gateway): Learn what an AI gateway is, how it sits between applications, agents, and models, and how it differs from API, LLM, and MCP gateways. - [How We Built A Highly Available Reverse Proxy](https://pangolin.net/news/building-pangolin-high-availability): How we turned Pangolin from a single-box reverse proxy into a stateless, horizontally-scalable cluster. - [Highly Available Identity-Aware Proxy: Self-Hosting Zero Trust Without a Single Point of Failure](https://pangolin.net/news/highly-available-identity-aware-proxy): Why an identity-aware proxy is harder to make highly available than a normal load balancer, and how to self-host one that stays up without sending traffic through someone else's cloud. - [Highly Available VPN: How to Remove the Single Point of Failure](https://pangolin.net/news/highly-available-vpn): What makes a VPN highly available, why most self-hosted VPNs are a single point of failure, and three ways to get real HA remote access with Pangolin. - [Pangolin 1.23: High Availability and Clustering](https://pangolin.net/news/1-23-release): Pangolin 1.23 makes high availability and clustering self-service on Scale and Enterprise, adds sites to the Pangolin CLI, and improves the server admin panel and Resource Launcher. - [How to Scrape Prometheus Metrics Behind a Firewall With No Open Ports](https://pangolin.net/news/prometheus-metrics-header-auth): Publish a private /metrics endpoint as an authenticated Pangolin resource and scrape it with Prometheus using HTTP Basic credentials, without opening inbound ports or standing up a VPN. - [How to Stop Using Virtual API Keys for Your AI Gateway](https://pangolin.net/news/how-to-stop-using-virtual-api-keys): Move your team off shared and per-user virtual API keys and onto identity-based access for your AI gateway - no keys to generate, distribute, or rotate for human users. - [Why Virtual API Keys Are a Bad Fit for LiteLLM and Bifrost Deployments](https://pangolin.net/news/why-virtual-api-keys-are-bad-with-litellm-bifrost): Virtual API keys solve model routing and budgeting well, but they were never built to be an identity system. Here's where that gap shows up in self-hosted LiteLLM and Bifrost deployments, and what to do instead. - [How to Connect Any Self-Hosted AI Model to Pangolin](https://pangolin.net/news/self-hosted-ai-gateway-remote-access): A general-purpose guide to putting any self-hosted model server - vLLM, Ollama, llama.cpp, LM Studio, LocalAI, or a private downstream gateway - behind Pangolin's identity-aware AI gateway. - [Self-Host DeepSeek, Qwen, and Kimi K2: Private Access From Anywhere](https://pangolin.net/news/self-hosting-deepseek-qwen-kimi-k2): Run open-weight models like DeepSeek, Qwen, and Kimi K2 on your own hardware, then reach them securely from anywhere through Pangolin's AI gateway - no API keys, no data leaving your infrastructure. - [vLLM and Ollama Clusters: Secure Remote Access Without a VPN](https://pangolin.net/news/vllm-ollama-cluster-remote-access): Give engineers and coding agents access to a self-hosted vLLM or Ollama cluster from one endpoint, authenticated by identity instead of API keys passed around a team. - [Pangolin 1.22: AI Gateway for Cloud and Self-Hosted Models](https://pangolin.net/news/1-22-release): Pangolin 1.22 introduces an AI Gateway for cloud and self-hosted models with identity-aware access. SSH, RDP, and VNC public resources, plus SSH and HTTPS private resources, are now available in Community Edition. - [NVIDIA DGX Spark Remote Access: Run Inference From Anywhere](https://pangolin.net/news/dgx-spark-remote-access): Access your NVIDIA DGX Spark from any laptop without SSH, a VPN, or an open port. Run Ollama on the Spark and reach it through Pangolin's identity-aware AI gateway, from the same endpoint you use for cloud models. - [Pangolin 1.21: Same Network Detection](https://pangolin.net/news/1-21-release): Pangolin 1.21 adds same-network detection for clients and sites, improves share links and access tokens, and tightens the pending sites provisioning workflow. - [Pangolin 1.20: Resource Launcher & Global Command Palette](https://pangolin.net/news/1-20-release): Pangolin 1.20 rebuilds the Resource Launcher with saved views, grouping, and filtering, and adds a global command palette for administrators. - [RDP in the Browser: Remote Desktop Without Installing a Client](https://pangolin.net/news/browser-based-rdp-remote-access): Access Windows desktops through a full RDP session rendered in the browser, with clipboard, file transfer, and standard RDP features. Users need only a web browser on their side. - [SSH in the Browser: Web-Based Terminal Access Without a Client](https://pangolin.net/news/browser-based-ssh-remote-access): Run a full SSH session in any modern browser. Users connect with a URL and authentication, without installing an SSH client, VPN, or desktop app. - [VNC in the Browser: Remote Display Access Without a Viewer](https://pangolin.net/news/browser-based-vnc-remote-access): View and control remote displays through a VNC session in your browser. Users connect with a URL instead of installing a standalone VNC viewer or VPN client. - [How to SSH with Pangolin: Browser Access and Private CLI](https://pangolin.net/news/how-to-ssh-with-pangolin): SSH to private servers through Pangolin with a browser terminal or private CLI over a scoped tunnel. Automatic user provisioning via PAM, without opening port 22 or distributing static keys. - [Pangolin 1.19: Browser Remote Access - SSH, RDP, VNC & More](https://pangolin.net/news/1-19-release): Pangolin 1.19 adds browser-based remote access with SSH, RDP, and VNC in the browser, a simpler Pangolin SSH mode, automatic site updates, labels, and resource policies. - [What Are MCP Tunnels? Secure Private MCP Servers Explained](https://pangolin.net/news/what-are-mcp-tunnels): Learn what MCP tunnels are, how they connect AI agents to private Model Context Protocol servers over outbound-only connections, and why they matter for enterprise security. - [5 Remote Access Policy Examples for Secure Teams](https://pangolin.net/news/remote-access-policy-examples): Use these remote access policy examples to scope access for admins, contractors, OT systems, internal web apps, and emergency workflows. - [Secure Remote Access: Enterprise ZTNA Implementation Guide](https://pangolin.net/news/secure-remote-access): Learn how to modernize secure remote access with identity-driven ZTNA, resource-level policy, and reduced public exposure. - [Peer-to-Peer Alternative to Cloudflare Tunnels with Edge TLS Termination](https://pangolin.net/news/building-a-peer-to-edge-peer-reverse-proxy): How Pangolin built a peer-to-edge reverse proxy that keeps TLS termination and private application traffic on infrastructure you control. - [GitOps for Pangolin Blueprints: Access Control via CI/CD](https://pangolin.net/news/gitops-pangolin-blueprints-ci-cd): Manage Pangolin Blueprints with GitOps using declarative YAML, pull request review, and GitHub Actions automation. - [Templated Provisioning and Rollouts for the Edge](https://pangolin.net/news/templated-provisioning-and-rollouts-for-the-edge): Automate edge device rollouts with Pangolin provisioning keys, declarative blueprints, and golden-image workflows. - [Pangolin 1.18: HTTPS Private Resources, Multi-Site, & Alerts](https://pangolin.net/news/1-18-release): Pangolin 1.18 adds HTTPS private resources, multi-site routing, uptime tracking, alert rules, and wildcard resources. - [Pangolin Remote Nodes: Cloud Control Plane & Failover](https://pangolin.net/news/pangolin-remote-nodes-guide): Pangolin remote nodes let you keep the traffic edge on infrastructure you control while Pangolin Cloud handles DNS, certificates, health checks, and failover. - [Ignition Remote Access Without Open Ports](https://pangolin.net/news/ignition-remote-access-without-open-ports): Keep Ignition private while providing authenticated browser access and narrow engineering connectivity without open ports. - [IoT Provisioning at Scale with Golden Edge Images](https://pangolin.net/news/iot-device-provisioning-at-scale-with-golden-images-for-edge-fleets): Provision IoT edge fleets with golden images, first-boot assignment, Pangolin sites, and declarative blueprints. - [Remote PLC/SCADA Access Without Open Ports](https://pangolin.net/news/remote-plc-scada-access-without-open-ports): Secure remote PLC and SCADA access by keeping interfaces private, closing open ports, and scoping engineering access. - [Remote Access for Tridium Niagara Without Open Ports](https://pangolin.net/news/remote-access-for-tridium-niagara-without-open-ports): Provide Tridium Niagara remote access with authenticated browser access and narrow engineering paths without open ports. - [Pangolin 1.17 - Full RBAC, Site Provisioning Keys, Log Streaming](https://pangolin.net/news/1-17-release): Pangolin 1.17 improves roles, identity provider mapping, site provisioning, connection logs, and log streaming. - [What is an Identity-Aware Proxy (IAP)?](https://pangolin.net/news/what-is-an-identity-aware-proxy): Learn what an identity-aware proxy is, how it compares to VPNs and ZTNA, and how Pangolin protects private web apps. - [Modernizing Enterprise SSH Access](https://pangolin.net/news/modernizing-enterprise-ssh-access): Modernize enterprise SSH with identity-driven access, short-lived credentials, and private connectivity instead of static keys. - [How Does ZTNA Work? Unlocking the Secrets of Enhanced Security](https://pangolin.net/news/how-ztna-works): Learn how ZTNA works, why it differs from VPN-based remote access, and how identity, device posture, and policy combine to protect private applications. - [Pangolin for MSPs: Secure Remote Access Per Customer](https://pangolin.net/news/pangolin-for-msps): Pangolin helps MSPs replace VPN sprawl with a multi-tenant, identity-based remote access platform built to scale across client environments. - [What Is a Tunneled Reverse Proxy? Architecture & Uses](https://pangolin.net/news/tunneled-reverse-proxy): Learn how tunneled reverse proxies publish private apps through outbound tunnels without broad VPN access or exposed networks. - [Comparison - Pangolin vs. WireGuard](https://pangolin.net/news/pangolin-vs-wireguard): Compare WireGuard tunnels with Pangolin’s full remote access platform for identity, policy, automation, and browser access. - [Comparison - Pangolin vs. Teleport](https://pangolin.net/news/pangolin-vs-teleport): Compare Pangolin and Teleport across workforce access, engineering sessions, protocol coverage, and zero trust architecture. - [Comparison - Pangolin vs. Zscaler](https://pangolin.net/news/pangolin-v-zscaler): How a self-hostable open-source access platform and an enterprise cloud security suite differ in architecture, traffic routing, deployment, and fit. - [Pangolin 1.16 - Certificate Based SSH](https://pangolin.net/news/1-16-0-release): Pangolin 1.16 adds certificate-based SSH, short-lived credentials, and just-in-time user provisioning for private infrastructure. - [How Pangolin Punches Through NATs and Firewalls](https://pangolin.net/news/nat-holepunching): A deep dive into how Pangolin establishes direct peer-to-peer connections through NAT devices and firewalls without opening ports. - [Comparison - Pangolin vs. Cloudflare One](https://pangolin.net/news/pangolin-v-cloudflare): How an open-source, self-hostable remote access platform compares to Cloudflare One (ZTNA, WARP, Access, and Tunnel). - [Comparison - Pangolin vs. Pomerium](https://pangolin.net/news/pangolin-v-pomerium): How an identity-based remote access platform and an identity-aware reverse proxy differ in scope, layer, and deployment. - [Comparison - Twingate vs. NetBird](https://pangolin.net/news/twingate-v-netbird): How Twingate and NetBird are solving different problems in modern remote access. - [Comparison - Twingate vs. Tailscale](https://pangolin.net/news/twingate-v-tailscale): How Twingate and Tailscale are solving different problems in modern remote access. - [Pangolin SSO with Google, Microsoft & OAuth2/OIDC](https://pangolin.net/news/idp-support): You can now log in to Pangolin with your existing identity provider - including Google, Microsoft, and any OAuth2/OIDC compatible IdP. - [Comparison - Pangolin vs. Twingate](https://pangolin.net/news/pangolin-v-twingate): How two identity-based remote access platforms differ in architecture, web access, and deployment options. - [Comparison - Pangolin vs. NetBird](https://pangolin.net/news/pangolin-v-netbird): A comparison of two WireGuard-powered remote access solutions and their differences in architecture, permissions, and use cases. - [Comparison - Pangolin vs. Tailscale](https://pangolin.net/news/pangolin-v-tailscale): How two WireGuard-based tools for remote access differ in design, access control, and fit. - [Pangolin 1.15: Mobile Apps, Device Approvals & Posture](https://pangolin.net/news/1-15-0-release): Pangolin 1.15 adds iOS and Android apps, device approvals, posture tracking, fingerprinting, and stability improvements. - [Declarative Configuration with YAML and Docker Labels](https://pangolin.net/news/blueprints): Pangolin Blueprints let you manage resources as code with YAML or Docker labels, making configurations automated, consistent, and scalable. - [Pangolin Cloud is Now Available in Europe](https://pangolin.net/news/pangolin-cloud-eu): We've deployed dedicated points of presence in the EU for our European cloud users. - [Health Checks and Load Balancing on Targets for Resources](https://pangolin.net/news/health-check): Configure Pangolin health checks and target-level load balancing to improve resource availability. - [How to Geo-block with Pangolin](https://pangolin.net/news/how-to-geoblock): Learn how to use Pangolin rules to geo-block resources and limit access by country or region. - [Self-hosted Remote Nodes - What Are They, and Why Do They Exist?](https://pangolin.net/news/manage-self-hosted): Learn about our new remote node self-hosted offering, which combines the best of self-hosted and cloud solutions. ## Customer Stories - [Customer stories](https://pangolin.net/customers): See how organizations use Pangolin to connect and protect their workforce, AI agents, and infrastructure with an open and secure zero trust platform. - [Mozilla Secures Access to Kubernetes with Pangolin](https://pangolin.net/customers/mozilla-secures-k8s-with-pangolin): Mozilla builds open internet products like Firefox and Thunderbird that connect people. Using Pangolin, Mozilla gives engineers secure, zero-trust access and authenticated ingress to ephemeral development Kubernetes environments without the friction of legacy VPNs or vulnerability of public deployments. - [H&M & Gill Capital Use Pangolin to Provide SDWAN for Hundreds of Stores](https://pangolin.net/customers/hm-pos-backhaul-with-pangolin): Gill Capital is a leading fashion and lifestyle retail group, bringing excitement and energy to the retail scene through an impressive portfolio of vibrant global brands. Gill Capital and H&M have deployed Pangolin across their cloud infrastructure and fleet of point of sale systems to create a secure reliable network for backhaul connectivity and remote management of in store equipment. - [Fidelity Secures Remote Access To On Property Operational Technology With Pangolin](https://pangolin.net/customers/fidelity-building-management-with-pangolin): Fidelity and Smart Building Technologies are the industry leaders in building automation systems, energy management systems, facility monitoring services, critical systems monitoring, and smart lighting solutions. Using Pangolin, Fidelity and SBT provide remote access for engineers and contractors to properties they control using simple, sharable, and secure credentials. They were able to replace legacy vpn-in-a-box solutions no longer meeting their needs. - [Lumistry Manages Thousands of Remote Raspberry Pis with Pangolin](https://pangolin.net/customers/lumistry-iot-device-management): Lumistry builds a robust suite of patient engagement solutions for pharmacies. Using Pangolin, Lumistry provides secure SSH and HTTP remote access to thousands of embedded linux devices - Raspberry Pis - out in the field to their engineering and support teams. ## Downloads - [Downloads](https://pangolin.net/downloads): Download Pangolin clients for desktop and mobile platforms. - [macOS](https://pangolin.net/downloads/mac): Requires macOS Sonoma 14.0 or later. - [Windows](https://pangolin.net/downloads/windows): Requires Windows 10 or later. - [Linux](https://pangolin.net/downloads/linux): Available for most Linux distributions. - [iOS](https://pangolin.net/downloads/ios): Requires iOS 17.0 or later. - [Android](https://pangolin.net/downloads/android): Requires Android 7.0 or later. ## Legal - [Privacy Policy](https://pangolin.net/privacy): Fossorial Inc. privacy policy for Pangolin websites and services. - [Terms of Service](https://pangolin.net/tos): Fossorial Inc. terms of service for Pangolin. - [Data Processing Addendum](https://pangolin.net/dpa): Fossorial Inc. data processing addendum for Pangolin. GDPR and privacy obligations when Fossorial processes personal data on behalf of customers. - [Service Level Agreement](https://pangolin.net/sla): Fossorial Inc. service level agreement for Pangolin Enterprise services. - [Fossorial Commercial License](https://pangolin.net/fcl): Fossorial Inc. commercial license for Pangolin software. - [Partner Program Agreement](https://pangolin.net/partners/agreement): Reference copy of the Fossorial partner program agreement for Pangolin. Apply at pangolin.net/partners to receive a signing form. ## External Sesources - [Documentation](https://docs.pangolin.net/): Pangolin product documentation and self-hosting guides. - [How Pangolin Works](https://docs.pangolin.net/about/how-pangolin-works): How Pangolin connects sites, resources, identity, and policy. - [Sign Up](https://app.pangolin.net/auth/signup): Create a Pangolin Cloud account. - [Status](https://status.pangolin.net): Pangolin service status and uptime. - [Trust Center](https://trust.pangolin.net): Security, compliance, and trust documentation. - [GitHub](https://github.com/fosrl/pangolin): Open-source Pangolin repository. ## Optional - [Full Documentation](https://pangolin.net/llms-full.txt): Complete inline content for all pages in one file. - [Sitemap](https://pangolin.net/sitemap.xml): XML sitemap of all indexable pages. - [Robots](https://pangolin.net/robots.txt): Crawler directives.