Zero Trust access,
two minutes to deploy.
A WireGuard-encrypted mesh with identity-based ABAC policies and continuous device posture. JIT access with approvals, and audit-ready evidence bundles. Free forever for up to 5 users.
curl -fsSL https://login.quickztna.com/install.sh | ZTNA_AUTH_KEY=tskey-auth-xxx sh
Built on open standards · Audited WireGuard crypto · No proprietary tunnel protocol
The platform
One control plane. Every layer of access.
Mesh networking, identity, ZTNA policy, and access governance — unified in a single agent.
Prove who had access, and why
Standing access is the audit finding. Engineers request time-bounded elevation, an approver signs off, and the grant auto-revokes — every step in the audit log. Run periodic access-review campaigns, roll any ACL back to a prior version in one click, and export the evidence bundle your auditor asks for.
WireGuard P2P with DERP fallback
Direct peer-to-peer tunnels wherever NAT allows. Two global DERP relays (Bangalore + Frankfurt) cover CGNAT and symmetric-NAT peers automatically.
JIT access
Request · approve · auto-revoke.
ABAC policies
Rules keyed on user, tag, device posture, time of day, country, protocol, and port. Evaluated per connection.
MagicDNS & subnet routes
Every device reachable at <name>.<org>.zt.net. Advertise subnet routes · exit nodes.
Remote shell
Browser-based remote shell for diagnostics, from the same agent, on every plan.
SSO + SCIM 2.0
Google, GitHub, OIDC. SCIM provisioning for Okta, Azure AD. TOTP MFA. Device-bound refresh tokens.
Private app & data access
Reach internal web apps, PostgreSQL/MySQL/Mongo, and Kubernetes through the mesh — brokered, identity-scoped, audited.
Terraform + API
57 REST endpoints. Full Terraform provider for machines, ACLs, DNS, users. GitOps your network state.
Setup
Two minutes, not two quarters.
No bastion hosts. No certificates to rotate. No firewall-change requests. No public IPs exposed. Bring your identity provider, run one command, ship.
Read quickstartIssue one auth key
In the dashboard, create a reusable auth key that covers every device you want to enrol. Set an expiry, optional tags, and that's it.
ztna auth-key create --reusable Pipe the installer everywhere
One command on Linux, macOS, and Windows. Works from shell, Ansible, Intune, Jamf, cloud-init. Detects OS, installs service, auto-connects.
curl ... | ZTNA_AUTH_KEY=tskey-auth-xxx sh You're on the mesh
Every device joins your tailnet over a WireGuard mesh tunnel. Reachable by MagicDNS name. ABAC policies + device posture enforced on every connection.
ssh prod-db.acme.zt.net Zero-trust access for remote workforces. Free forever for up to 5 users.
Built for the founder, the indie ops team, the YC batch, the Fortune 500 pilot. Every feature is free for up to 5 users — upgrade to Business ($10 per user /mo) only when you need more seats and machines.
- No credit card · no time limit
- Self-serve SSO + SCIM
- Free SSH on every tier
FAQ
Common questions about QuickZTNA
Short, factual answers — same content as our docs and blog, summarized.