zrok

zrok shares local services, files, and network resources over the internet without opening firewall ports. Built on OpenZiti's zero-trust networking fabric. Fully self-hostable ngrok alternative.

Network InfrastructureOpen sourceSelf-hosted
Visit official website

Published Updated

CategoryNetwork Infrastructure
AccessSelf-hosted
PricingFreemium
APIAvailable
Overview

What is zrok?

zrok is developed by NetFoundry on top of OpenZiti, an open-source zero-trust networking SDK that embeds end-to-end encrypted overlay networking into applications. Unlike ngrok, which routes traffic through a central cloud proxy, zrok uses the OpenZiti fabric for cryptographic identity and routing - no traffic touches a shared proxy unless you configure it to.

Read the full overview

The tool supports public URL sharing for webhooks and demos, private peer-to-peer sharing for secure internal access, and file or directory sharing. The self-hosting path is fully documented and gives complete control over relay infrastructure.

Why teams use it

Key capabilities

  • Public tunnels - expose a local HTTP service to a stable public URL for webhooks or demos.
  • Private sharing - share a resource only with authenticated zrok identities, no public exposure.
  • File and directory sharing - peer-to-peer file transfer over the OpenZiti fabric without a cloud intermediary.
  • Self-hosted deployment - run your own zrok controller and OpenZiti router on any infrastructure.
  • Firewall traversal - connects through restrictive environments with no inbound port requirements.
  • Go SDK - embed tunnel creation in tooling or CI pipelines programmatically.
Core areas
  • Local service exposure - webhook testing, sharing in-progress work, demo environments without deployment.
  • Zero-trust access - identity-verified peer-to-peer connectivity without VPN or firewall changes.
  • Data-sovereign tunneling - traffic stays within your own OpenZiti fabric when self-hosted.
  • Developer workflow integration - CLI and Go SDK for embedding tunnel creation in tooling or CI pipelines.
Positioning

zrok competes with ngrok and Cloudflare Tunnel for the expose-localhost use case, but wins on privacy and self-hosting depth. The tradeoff is operational complexity: zrok requires running or connecting to an OpenZiti network, whereas ngrok is a single binary with a cloud backend. Choose zrok when data sovereignty or zero-trust architecture requirements matter more than setup simplicity.

Why it matters

Every team that uses webhooks eventually asks how to test locally without deploying. Most reach for ngrok, not realising their tunnel sends all traffic through a shared US-based proxy they do not control. zrok provides the same developer experience while keeping traffic on cryptographically-authenticated paths. For security-conscious teams or regulated industries, that distinction matters significantly.

Deployment & technical details

Technical details

Access
Self-hosted
Source model
Open source
Founded
2022
Headquarters
US (NetFoundry / OpenZiti)
Pricing model
Freemium
API
Available
Published release
Stable — CLI client and self-hosted controller 0.4.44 ↗ (checked )
Check with the publisher

Official resources

Community experience

Reviews of zrok

No published reviews yet.

Loading review form…