Skip to main content
Pangolin is an open-source SASE platform with one mission: connect and protect your users, wherever they are. It treats networking and security as a single system. Identity, sites, access control, privileged access, and an identity-aware AI gateway share one policy model. The idea is the same as platforms like Cloudflare One, Zscaler, and Prisma Access, but Pangolin is open, self-hostable, and built to stay light enough that administrators actually enjoy running it.
Pangolin Dashboard

Screenshot of resources page from the Pangolin Dashboard.

Why Pangolin Exists

Legacy SASE platforms got the idea right: connectivity and security belong together. They delivered it as a heavyweight, closed, cloud-locked stack. Pangolin does that unification in the open, on infrastructure you control, and simple enough to deploy yourself.
  • Open source and auditable. You can see how traffic is handled and how access decisions get made.
  • Networking and security as one platform. Connecting users and protecting them happen together, with one identity and policy model.
  • Lightweight by design. The control plane runs on a modest server. A user-space connector sits in your private networks.
  • Zero trust from day one. Access is granted per resource, with identity providers, roles, and audit logs.
  • Run it your way. Self-host or use Pangolin Cloud.

Core Concepts

Pangolin is organized around a few pieces you will use everywhere:
  1. A server is the control plane. It holds identity, policy, and coordination. You can use Pangolin Cloud or self-host the same software.
  2. Sites connect the networks where your applications and infrastructure live.
  3. Resources are the specific things users are allowed to reach: web apps, SSH, desktops, private hosts, and AI providers.
  4. Clients give devices a private path to those resources.

How Pangolin Works

Learn the fundamentals: server, sites, resources, clients, and how they fit together.

Explore the Platform

Sites

Connect private networks with lightweight connectors so authorized users can reach what lives there.

Resources

Define the apps, hosts, SSH sessions, desktops, and AI endpoints users can access.

Identity and Access

Use built-in users or your identity provider. Grant roles per resource and keep an audit trail.

AI Gateway

Put identity, budgets, and session history in front of cloud and self-hosted model APIs.

Keep Reading

Cloud vs. Self-Hosted

Choose a managed control plane or run the same software on your own infrastructure.

Pangolin vs. Proxy vs. VPN

How Pangolin relates to traditional reverse proxies and VPNs, and what it does beyond either.

Pangolin vs. Bifrost vs. LiteLLM

How Pangolin’s identity-aware AI Gateway compares to dedicated LLM gateways.

System Architecture

A technical picture of the control plane, nodes, connectors, and how traffic moves.

Deployment Options

See Cloud vs. Self-Hosted for the differences, including remote nodes as a hybrid.

Pangolin Cloud

A managed control plane. Install sites and clients, then define resources. Optionally self-host a node to keep traffic on your network.

Self-host Pangolin

Run a fully isolated Pangolin server. Install Community Edition or Enterprise Edition with the quick installer.