{"repo":"DefGuard/defguard","free":true,"listed":false,"github":"https://github.com/DefGuard/defguard","clone":"git clone https://github.com/DefGuard/defguard.git","description":"Zero-Trust access management with true WireGuard® 2FA/MFA","language":"Rust","stars":2805,"topics":["multifactor-authentication","openid","openid-connect","vpn","wireguard","yubikey","authentication","forwardauth","oauth","oauth-provider"],"license":null,"category":"networking-infra","readme_excerpt":"Defguard is a self-hosted secure remote access platform that combines WireGuard VPN, identity and access management, multi-factor authentication, and network access control in a single solution. Built with a security-first architecture, Defguard helps organizations securely manage access to infrastructure, applications, and private networks while maintaining full control over their environment. Why Defguard? Modern organizations often rely on multiple disconnected tools to manage identity, VPN access, authentication, and network permissions. Defguard brings these capabilities together into a unified platform designed for security, transparency, and operational simplicity. Key principles behind Defguard: - 📖 Open-source core (AGPL), open-code Enterprise components - 🏠 Fully self-hosted — no external dependencies or data leaving your infrastructure - 🔒 Security-first: Zero-Trust VPN with connection-level MFA, architecture designed to minimize attack surface - 🔍 Transparency: published SBOMs, penetration test reports, architecture decision records For detailed security information see the secure-by-design documentation. Core Capabilities - 🌐 WireGuard VPN — multiple locations with per-location access control, MFA per connection, self-service device setup, kernel and userspace support - 👥 Identity & Access Management — internal OIDC provider for SSO, external OIDC (Google, Microsoft, custom), LDAP/AD sync, remote enrollment, user self-service - 🔑 Multi-Factor Authenticatio","default_branch":null,"files":null,"tree":[],"storefront":"/r/DefGuard","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/DefGuard/defguard/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}