meshp
Self-hostable private networking built on WireGuard. One device can hold live memberships in many networks at once — which is the part nobody else does.
Pre-alpha. Do not put this in front of anything you cannot lose.
The largest gap is that every packet goes through a relay — there are no direct peer-to-peer paths yet, so throughput and latency are worse than any mature mesh, and a self-hoster pays for that bandwidth. There are no mobile clients. Access policy is enforced on Linux only. If you need something that works this afternoon, use Tailscale or NetBird — we mean that.
One device, many networks
A technician supporting forty customers should not need forty laptops, and those customers should not be able to tell they share one. Each membership carries its own address and its own WireGuard key, so nothing correlates the same device across two networks.
What it is
Every device runs an agent and gets a stable private address. A control plane decides what should be true — who may reach what, which machine provides egress — and every agent converges toward it. You run the control plane.
What people use it for
Supporting customers without a laptop per customer
One machine joins every customer network at once and keeps them separate. Revoking a device from one network takes its key out of that network and leaves the others alone, so an engineer leaving one account does not mean re-keying the rest.
Reaching a LAN that has no public address
One machine on the far side advertises the prefixes behind it, and every device in the network routes to them — no port forwarding, no static IP at the site, nothing exposed to the internet. Several machines can advertise the same prefix, and devices pick between them on health.
Leaving through an address somebody has allowlisted
A vendor that permits one source IP is a common reason to need an exit node and a bad reason to need a single point of failure. Gateways and exit nodes are one primitive: a set of prefixes with ordered, health-checked advertisers. A device leaves a dead one on its own evidence, without a round trip to the control plane — which matters most during the outage that took the control plane with it.
Full-tunnel egress that cannot leak
When a device sends everything through the tunnel, traffic that would leave any other way is refused — and those rules are firewall state, so they survive the agent crashing. A dropped tunnel cannot quietly put a real address back on the wire. When something is blocked, meshp doctor explains why on a machine with no internet access at all.
What works, per platform
| Linux | macOS | Windows | |
|---|---|---|---|
| Encrypted tunnel, packets cross | yes | yes | yes |
| Private DNS for network names | yes | yes | yes |
| Full-tunnel egress that fails closed | yes | yes | yes |
| Uses a LAN gateway or exit node | yes | yes | yes |
| Acts as a LAN gateway or exit node | yes | no | no |
| Enforces access policy on the device | yes | no | no |
Each of the three is exercised on a real runner of that operating system in CI, not cross-compiled and hoped for. Where a device cannot enforce policy, the control plane refuses to place it in a network that has one, rather than letting it join and quietly ignore the rules.
Honest comparison
| meshp | Tailscale | Headscale | NetBird | |
|---|---|---|---|---|
| Self-hostable control plane | yes | no | yes | yes |
| Control plane open source | yes | no | yes | yes |
| Device in several networks at once | yes | no | no | no |
| Automatic exit-node failover | yes | no | no | partial |
| Stable egress IP across failover | yes | n/a | n/a | no |
| Direct peer-to-peer paths | no | yes | yes | yes |
| Mobile clients | no | yes | yes | yes |
| Production ready today | no | yes | yes | yes |
The last three rows are where we are years behind, and no amount of architecture makes up for it yet.
Download
v0.2.2 — SHA-256 checksums alongside every archive, which the install script verifies for you. The archives are not signed yet. All releases.
| macOS | Apple silicon | meshp_v0.2.2_darwin_arm64.tar.gz |
| macOS | Intel | meshp_v0.2.2_darwin_amd64.tar.gz |
| Linux | x86-64 | meshp_v0.2.2_linux_amd64.tar.gz |
| Linux | arm64 | meshp_v0.2.2_linux_arm64.tar.gz |
| Windows | x86-64 | meshp_v0.2.2_windows_amd64.zip |
| Checksums | all platforms | SHA256SUMS |
Or install it on a device joining a network
curl -fsSLO https://raw.githubusercontent.com/meshpnet/meshp/main/scripts/install.sh
less install.sh && sudo MESHP_VERSION=v0.2.2 sh install.shIt verifies the download against the release checksums, installs the agent and its service unit, and stops before starting anything — joining needs a token, and that is your decision to make. The version is named on purpose: run without it and the script refuses, because there is no stable release yet and piping an unready one to sh is not a thing it will do quietly. Linux and macOS; on Windows take the archive above.
Read before you trust it
The documentation is here rather than only in the repository: a quickstart, self-hosting for the version you would put in front of real devices, and route groups, which is the thing meshp is actually for.
If you are evaluating this, read the decision records instead. There are thirty-two of them and they say why things are the way they are, including the parts that are wrong — ADR-0002 is why every packet still goes through a relay, and ADR-0011 is why a device with a dropped tunnel refuses traffic rather than quietly putting a real address back on the wire. If you disagree with one, that is worth more to us than a patch.
Open, and how far
Apache 2.0, and commercial use is permitted — including running it as a service. Every line that touches a packet is open source: the agent, the control plane, the relay, policy, route groups and failover. Redundancy is not a paid feature.
What is not open is the multi-tenant layer we operate ourselves. It is operated rather than distributed, so there is no on-premise build of it and no licence key — a self-hosted meshp is a complete single-tenant deployment, not a trial of one. See ADR-0009.