What is zrok?
zrok is developed by NetFoundry on top of OpenZiti, an open-source zero-trust networking SDK that embeds end-to-end encrypted overlay networking into applications. Unlike ngrok, which routes traffic through a central cloud proxy, zrok uses the OpenZiti fabric for cryptographic identity and routing - no traffic touches a shared proxy unless you configure it to.
Read the full overview
The tool supports public URL sharing for webhooks and demos, private peer-to-peer sharing for secure internal access, and file or directory sharing. The self-hosting path is fully documented and gives complete control over relay infrastructure.
Key capabilities
- Public tunnels - expose a local HTTP service to a stable public URL for webhooks or demos.
- Private sharing - share a resource only with authenticated zrok identities, no public exposure.
- File and directory sharing - peer-to-peer file transfer over the OpenZiti fabric without a cloud intermediary.
- Self-hosted deployment - run your own zrok controller and OpenZiti router on any infrastructure.
- Firewall traversal - connects through restrictive environments with no inbound port requirements.
- Go SDK - embed tunnel creation in tooling or CI pipelines programmatically.
- Local service exposure - webhook testing, sharing in-progress work, demo environments without deployment.
- Zero-trust access - identity-verified peer-to-peer connectivity without VPN or firewall changes.
- Data-sovereign tunneling - traffic stays within your own OpenZiti fabric when self-hosted.
- Developer workflow integration - CLI and Go SDK for embedding tunnel creation in tooling or CI pipelines.
zrok competes with ngrok and Cloudflare Tunnel for the expose-localhost use case, but wins on privacy and self-hosting depth. The tradeoff is operational complexity: zrok requires running or connecting to an OpenZiti network, whereas ngrok is a single binary with a cloud backend. Choose zrok when data sovereignty or zero-trust architecture requirements matter more than setup simplicity.
Every team that uses webhooks eventually asks how to test locally without deploying. Most reach for ngrok, not realising their tunnel sends all traffic through a shared US-based proxy they do not control. zrok provides the same developer experience while keeping traffic on cryptographically-authenticated paths. For security-conscious teams or regulated industries, that distinction matters significantly.
Technical details
- Access
- Self-hosted
- Source model
- Open source
- Founded
- 2022
- Headquarters
- US (NetFoundry / OpenZiti)
- Pricing model
- Freemium
- API
- Available
- Published release
- Stable — CLI client and self-hosted controller 0.4.44 ↗ (checked )
- Website
- zrok.io ↗
Official resources
Reviews of zrok
No published reviews yet.
Loading review form…