meshp

Self-hostable private networking built on WireGuard. One device can hold live memberships in many networks at once — which is the part nobody else does.

Pre-alpha. Do not put this in front of anything you cannot lose.

The largest gap is that every packet goes through a relay — there are no direct peer-to-peer paths yet, so throughput and latency are worse than any mature mesh, and a self-hoster pays for that bandwidth. There are no mobile clients. Access policy is enforced on Linux only. If you need something that works this afternoon, use Tailscale or NetBird — we mean that.

One device, many networks

A technician supporting forty customers should not need forty laptops, and those customers should not be able to tell they share one. Each membership carries its own address and its own WireGuard key, so nothing correlates the same device across two networks.

One laptop holding three separate memberships, each with its own address and key, in three customer networks that cannot see each other. acme10.42.1.0/24globex10.43.7.0/24initech10.44.2.0/2410.42.1.12key A10.43.7.4key B10.44.2.31key Cone laptopthree keys, three addresses
Three memberships on one machine. Each is a separate interface with its own key — not three routes on one tunnel.

What it is

Every device runs an agent and gets a stable private address. A control plane decides what should be true — who may reach what, which machine provides egress — and every agent converges toward it. You run the control plane.

What people use it for

Supporting customers without a laptop per customer

One machine joins every customer network at once and keeps them separate. Revoking a device from one network takes its key out of that network and leaves the others alone, so an engineer leaving one account does not mean re-keying the rest.

Reaching a LAN that has no public address

One machine on the far side advertises the prefixes behind it, and every device in the network routes to them — no port forwarding, no static IP at the site, nothing exposed to the internet. Several machines can advertise the same prefix, and devices pick between them on health.

Leaving through an address somebody has allowlisted

A vendor that permits one source IP is a common reason to need an exit node and a bad reason to need a single point of failure. Gateways and exit nodes are one primitive: a set of prefixes with ordered, health-checked advertisers. A device leaves a dead one on its own evidence, without a round trip to the control plane — which matters most during the outage that took the control plane with it.

Full-tunnel egress that cannot leak

When a device sends everything through the tunnel, traffic that would leave any other way is refused — and those rules are firewall state, so they survive the agent crashing. A dropped tunnel cannot quietly put a real address back on the wire. When something is blocked, meshp doctor explains why on a machine with no internet access at all.

What works, per platform

LinuxmacOSWindows
Encrypted tunnel, packets crossyesyesyes
Private DNS for network namesyesyesyes
Full-tunnel egress that fails closedyesyesyes
Uses a LAN gateway or exit nodeyesyesyes
Acts as a LAN gateway or exit nodeyesnono
Enforces access policy on the deviceyesnono

Each of the three is exercised on a real runner of that operating system in CI, not cross-compiled and hoped for. Where a device cannot enforce policy, the control plane refuses to place it in a network that has one, rather than letting it join and quietly ignore the rules.

Honest comparison

meshpTailscaleHeadscaleNetBird
Self-hostable control planeyesnoyesyes
Control plane open sourceyesnoyesyes
Device in several networks at onceyesnonono
Automatic exit-node failoveryesnonopartial
Stable egress IP across failoveryesn/an/ano
Direct peer-to-peer pathsnoyesyesyes
Mobile clientsnoyesyesyes
Production ready todaynoyesyesyes

The last three rows are where we are years behind, and no amount of architecture makes up for it yet.

Download

v0.2.2 — SHA-256 checksums alongside every archive, which the install script verifies for you. The archives are not signed yet. All releases.

macOSApple siliconmeshp_v0.2.2_darwin_arm64.tar.gz
macOSIntelmeshp_v0.2.2_darwin_amd64.tar.gz
Linuxx86-64meshp_v0.2.2_linux_amd64.tar.gz
Linuxarm64meshp_v0.2.2_linux_arm64.tar.gz
Windowsx86-64meshp_v0.2.2_windows_amd64.zip
Checksumsall platformsSHA256SUMS

Or install it on a device joining a network

curl -fsSLO https://raw.githubusercontent.com/meshpnet/meshp/main/scripts/install.sh
less install.sh && sudo MESHP_VERSION=v0.2.2 sh install.sh

It verifies the download against the release checksums, installs the agent and its service unit, and stops before starting anything — joining needs a token, and that is your decision to make. The version is named on purpose: run without it and the script refuses, because there is no stable release yet and piping an unready one to sh is not a thing it will do quietly. Linux and macOS; on Windows take the archive above.

Read before you trust it

The documentation is here rather than only in the repository: a quickstart, self-hosting for the version you would put in front of real devices, and route groups, which is the thing meshp is actually for.

If you are evaluating this, read the decision records instead. There are thirty-two of them and they say why things are the way they are, including the parts that are wrong — ADR-0002 is why every packet still goes through a relay, and ADR-0011 is why a device with a dropped tunnel refuses traffic rather than quietly putting a real address back on the wire. If you disagree with one, that is worth more to us than a patch.

Open, and how far

Apache 2.0, and commercial use is permitted — including running it as a service. Every line that touches a packet is open source: the agent, the control plane, the relay, policy, route groups and failover. Redundancy is not a paid feature.

What is not open is the multi-tenant layer we operate ourselves. It is operated rather than distributed, so there is no on-premise build of it and no licence key — a self-hosted meshp is a complete single-tenant deployment, not a trial of one. See ADR-0009.