Clientless access for remote workers.
Browser-based VPN with zero trust principles. No client software needed. Identity-verified, encrypted tunnel for any application.
None needed
Client
Per-session
Auth
Passkey
MFA
WireGuard
Protocol
VPN, reimagined.
Clientless. Passkey auth. WireGuard tunnels.
Clientless access
Browser-based access. No software install.
Per-session auth
Re-authenticate for each session.
Passkey MFA
FIDO2 passkeys and WebAuthn.
WireGuard tunnels
High-performance WireGuard® encryption.
Split tunneling
Route only corporate traffic through tunnel.
Session recording
Record sessions for compliance.
Getting started
Launch your first instance in three steps. CLI, console, or API — your choice.
ur security zt-vpn create prod-gw \
--protocol=wireguard \
--auth=passkey,totpZT-VPN patterns.
Remote access and BYOD.
Suggested configuration
Clientless · Passkey · WireGuard
Estimate your costs
Create detailed configurations to see exactly how much your architecture will cost. Pay for what you use, down to the second.
Configuration 1
Zero Trust VPN
Processing Volume
Add-ons
Cost details
Modern VPN replacement with identity-based access.
Works seamlessly with
Frequently asked questions
VPN, reimagined.
Clientless. Passkey auth. WireGuard tunnels.