{"slug": "show-hn-pangolin-sso-and-wireguard-instead-of-api-keys-for-llm-access", "title": "Show HN: Pangolin – SSO and WireGuard instead of API keys for LLM access", "summary": "Pangolin, an open-source zero-trust network access suite, launched a new AI gateway that replaces API keys with WireGuard tunnels authenticated via existing identity providers such as Okta, Azure, and Google. The gateway supports self-hosted and on-prem models equally, offering session logging, budgets, usage analytics, and governance, with a free Community Edition and a fully hosted Pangolin Cloud.", "body_md": "You have seen Pangolin ([https://github.com/fosrl/pangolin](https://github.com/fosrl/pangolin)) on here before for our open-source zero-trust network access suite of tools. We are launching a new AI gateway that takes a different approach to auth. Rather than authenticating requests to AI providers with API keys, it authenticates the network connection itself via a desktop app.\n\nEach user gets a WireGuard tunnel back to the gateway, established after they log in through their existing identity provider (Okta, Azure, Google, etc) via a desktop app. That tunnel is the auth, so there is no key to generate, embed, rotate, or leak, because the gateway already knows who's on the other end of the connection. Compare that to most AI gateways, which are really just a proxy in front of static bearer tokens you'd get from OpenAI or Anthropic directly.\n\nThis tunnel-based approach also means self-hosted and on-prem models aren't an afterthought bolted onto the gateway. They work the same way public cloud models do. Drop a lightweight tunnel connector inside your cluster (even a DGX Spark) and it joins the same network, so on-prem models show up in the gateway next to public cloud ones. Users switch between them without changing endpoints or juggling separate credentials for internal infrastructure.\n\nFor machines or users who can't run the desktop client, we still support traditional virtual keys, plus the usual gateway features: session logging, budgets, usage analytics, and governance.\n\nIt’s fully self-hostable. Community Edition is free for everyone. Enterprise Edition is free for individuals and small businesses. There is also Pangolin Cloud which is fully hosted.\n\nComments URL: [https://news.ycombinator.com/item?id=49549747](https://news.ycombinator.com/item?id=49549747)\n\nPoints: 3\n\n# Comments: 1", "url": "https://wpnews.pro/news/show-hn-pangolin-sso-and-wireguard-instead-of-api-keys-for-llm-access", "canonical_source": "https://github.com/fosrl/pangolin", "published_at": "2026-09-03 13:35:01+00:00", "updated_at": "2026-09-03 13:53:13.720205+00:00", "lang": "en", "topics": ["ai-infrastructure", "ai-tools", "ai-safety"], "entities": ["Pangolin", "WireGuard", "Okta", "Azure", "Google", "OpenAI", "Anthropic", "DGX Spark"], "alternates": {"html": "https://wpnews.pro/news/show-hn-pangolin-sso-and-wireguard-instead-of-api-keys-for-llm-access", "markdown": "https://wpnews.pro/news/show-hn-pangolin-sso-and-wireguard-instead-of-api-keys-for-llm-access.md", "text": "https://wpnews.pro/news/show-hn-pangolin-sso-and-wireguard-instead-of-api-keys-for-llm-access.txt", "jsonld": "https://wpnews.pro/news/show-hn-pangolin-sso-and-wireguard-instead-of-api-keys-for-llm-access.jsonld"}}