Firezone logo light

Firezone Pricing & Plans

Pick a plan that best suits your needs. No credit card required to sign up.

MonthlyAnnualSave 17%

Starter

Free

Secure remote access for individuals and small groups.

No credit card required.

  • Up to 6 users
  • Access your homelab or VPC from anywhere
  • Native clients for Windows, Linux, macOS, iOS, Android
  • Authenticate via email or OpenID Connect (OIDC)
  • Load balancing and automatic failover
  • Port and protocol traffic restrictions
  • Audit Logs
  • No firewall configuration required
  • Community Support

Team

$5$4.16 per user/month

Zero trust network access for teams and organizations

  • Everything in Starter
  • plus

  • Up to 500 users
  • Full-tunnel routing
  • Conditional access policies
  • Customize your account slug
  • Priority email support

Enterprise

30-day trial

Contact us

Compliance-ready security for large organizations

  • Everything in Starter and Team
  • plus

  • Unlimited users
  • Directory sync for Google, Entra ID, and Okta
  • Log Sinks
  • Dedicated Slack support channel
  • Uptime SLAs
  • Access to our SOC2 and pentest reports
  • Roadmap acceleration
  • White-glove onboarding
  • Annual invoicing

Trusted by organizations like

Compare plans

StarterTeamEnterprise
UsersIncludes both admins and end-users of your Firezone account6500Unlimited
Service AccountsMachine accounts used to access Resources without a user present10100Unlimited
SitesSites are a collection of Gateways and Resources that share the same network connectivity context. Typically a subnet or VPC.10100Unlimited
AdminsUsers with account-wide access to deploy Gateways, manage billing, and edit users, Sites, or other configuration110Unlimited
PoliciesPolicies control access to Resources (e.g. Group “A” may access Resource “B”)UnlimitedUnlimitedUnlimited
ResourcesAnything you wish to manage access to (e.g. database, VPC, home network, web server, SaaS application)UnlimitedUnlimitedUnlimited
Connected ClientsAny device or machine that the Firezone Client connects from3 per user5 per userUnlimited
Networking Features
NAT hole punchingConnect to Resources without opening inbound firewall ports
Native Firezone ClientsNative client apps for all major platforms
Split tunnelingRoute traffic to Resources through Firezone leaving other traffic unaffected
IPv4 and IPv6 ResourcesConnect to Resources over IPv4 or IPv6
Automatic NAT64Connect to IPv6-only Resources from IPv4-only networks and vice-versa
DNS-based routingRoute traffic through Firezone based on DNS matching rules
Secure DNSResolve queries for non-Firezone Resources using popular DNS-over-HTTPS providers
Gateway load-balancingSpread traffic across multiple Gateways within a Site
Automatic Gateway failoverClients automatically switch from unhealthy Gateways to healthy ones
Full-tunnel routingRoute all traffic from select Clients through Firezone
Authentication & Authorization
Resource-level access policiesControl access to Resources based on user identity and group
Email (OTP) authenticationAuthenticate users with a one-time code sent to their email
OpenID Connect authenticationAuthenticate users with any OIDC-compatible provider
Conditional access policiesAllow access based on source IP, authentication method, time of day, or country.
Custom account slugCustomize the sign-in URL for your account. E.g. https://app.firezone.dev/your-organization
Google Workspace directory syncAutomatically sync users and groups from Google Workspace to Firezone
Microsoft Entra ID directory syncAutomatically sync users and groups from Microsoft Entra ID to Firezone
Okta directory syncAutomatically sync users and groups from Okta to Firezone
Security Features
Session-based key rotationRotate WireGuard encryption keys each time a user signs in
Client verificationRequire Clients to be marked as verified in the admin portal before they can access Resources
GeoIP MappingShow where your users are connecting from
Audit LogsStructured, immutable records of every configuration change, session, connection, and API call in your account.
Traffic restrictionsRestrict access to specific ports and protocols
Log SinksStream audit logs directly to Splunk, Datadog, Elastic, and other destinations
Firezone service compliance reportsIndependent audit reports of Firezone's service for compliance with industry standardsSOC 2
Firezone service pentest reportsPenetration testing for security vulnerabilities in Firezone's service conducted by a third party firm
Support & Customer success
Community Forums
Community Discord
Priority Email
Dedicated Slack
Roadmap accelerationShape the product roadmap with customized features and integrations
White-glove onboardingGet personalized deployment support and training for your team
Uptime SLAGuaranteed uptime for your Firezone service99.9%
Billing & payment
Payment by credit cardPay for your subscription using a credit card
Payment by ACH transferPay for your subscription using an ACH transfer
Payment by wire transferPay for your subscription using a wire transfer
Annual invoicingPay for your subscription annually

FAQ

A simple deployment takes less than 10 minutes and can be accomplished with by installing the Firezone Client and deploying one or more Gateways. Visit our docs for more information and step by step instructions.

The WireGuard® solution for Enterprise.