OSS Tanbou

Defguard — zero-trust access combining WireGuard, identity, and MFA

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
2,846
Primary language
Rust
License
Not determined
Repository last updated
Sep 18, 2026

Overview

Defguard is a self-hosted remote-access platform combining WireGuard VPN, identity and access management, SSO, MFA, and network policies, including connection-level MFA and user/group access control.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Manage WireGuard connectivity and identity from one control plane

Multiple WireGuard locations can be combined with user and group management and per-location access rules.

Sources: [2][3]

Add OIDC, MFA, and firewall policy around network access

Defguard includes internal/external OIDC, TOTP, WebAuthn/FIDO2, and real-time firewall policy controls.

Sources: [2][3]

For organizations self-hosting VPN, SSO, and MFA together

It fits environments that want network access and identity policy under one self-managed platform instead of several disconnected tools.

Sources: [2]

Separate evaluation deployment from production and Community from Enterprise

The one-line installer is intended for evaluation, while production requires a fuller deployment design. Enterprise code also carries a separate license.

Sources: [2][4]

Official sources

  1. [1]DefGuard/defguard repository(2026-09-20)
  2. [2]Defguard README(2026-09-20)
  3. [3]Defguard documentation(2026-09-20)
  4. [4]Defguard dual license(2026-09-20)
Supplemental curator note

Defguard combines VPN and identity controls so connection-level MFA and user/group policies can be managed together. Open-core code is AGPL-3.0, while `crates/defguard_core/src/enterprise` uses a separate Enterprise License.

Try it in 3 steps

  1. 1

    Get the source

    git clone --depth 1 https://github.com/DefGuard/defguard.git
  2. 2

    Enter the repository

    cd defguard
  3. 3

    Check the official steps

    Continue with the commands in the README Installation, Quick Start, or Getting Started section.

    find . -maxdepth 1 -iname 'README*' -exec sed -n '1,220p' {} \; -quit
Check the official README

Growth

Growth trends · Last 30 days

2,846 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
23
Open PRs
9

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • multifactor-authentication
  • openid
  • openid-connect
  • vpn
  • wireguard
  • yubikey
  • authentication
  • forwardauth
  • oauth
  • oauth-provider
  • oauth2-server
  • oidc
Stars
2,846
Forks
114
Watchers
18
Open issues
301
Contributors
16
Primary language
Rust
License
Not determined
Repository last updated
Sep 18, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.