0trust.services is the private access plane: always-on VPN for devices, and Shield for privacy DNS and secure egress. Identity and passkeys live on 0trust.cloud.
Always-on L3 for people and devices. Clients dial published PoPs.
Warm resume after sleep, network change, or radio blip so private routes stay ready.
Human login on 0trust.cloud. Session tickets tied to the device, not a pasteable cookie alone.
Clients dial known endpoints. Control plane at vpn.0trust.services.
Grants and routes apply when the VPN session opens — entitlements follow identity.
Node policy agent enforces grants on the host while VPN carries L3.
Use VPN for private routes; use Shield for encrypted DNS and egress on the same identity.
Control https://vpn.0trust.services\n Identity https://0trust.cloud (passkeys)\n Data regional PoPs — client dials only
Privacy DNS and optional secure CONNECT egress through the services edge — session gated, not an open resolver.
https://dns.0trust.services/dns-query — private mesh labels plus public recursion.
HTTP CONNECT through the edge so apps leave on an encrypted path.
Passkey + DBSC required for production DoH and CONNECT — not a public open relay.
Endpoints, client tips, and status for privacy DNS and egress.
Policy-gated HTTP paths for private apps — same identity as VPN and Shield.
Reach private apps through policy-gated paths with the control-plane identity stack.
Human traffic requires passkey login and a device-bound session before proxying.
Operator protocol paths on the same identity and policy model.
OIDC and WebAuthn on 0trust.cloud. Services enforces — it does not re-issue identity.
Resolve mesh-accessible names while you stay on the private plane (via Shield DoH).