Clientless Zero Trust Access for Web Applications
Not every user needs a network tunnel.
For private HTTP and HTTPS applications, ZTXGate can enforce access through its clientless proxy so authorized users can reach approved web resources without installing WireGuard connectivity software on the endpoint.
Clientless access is available as a licensed ZTXGate capability.
What Is Clientless ZTNA?
Clientless ZTNA provides access to supported private applications through a browser-based path rather than a network tunnel installed on the endpoint.
With ZTXGate, the clientless access path is designed for HTTP and HTTPS applications.
The proxy accepts the incoming web connection, evaluates access, and establishes a separate connection to the protected application when policy allows it.
This keeps the protected application behind ZTXGate rather than turning it into a generally reachable public service.
When a Client Is Not Necessary
Installing endpoint connectivity software makes sense when users need access to network protocols or multiple non-web resources.
It may be unnecessary when the requirement is simply:
Give this user access to this private web application.
Clientless access can be useful for:
- contractors
- consultants
- business partners
- temporary users
- browser-based administrative tools
- unmanaged or lightly managed endpoints where tunnel software is undesirable
For broader network-resource access, ZTXGate's WireGuard-based client model remains available.
Application-Level Visibility
Because the ZTXGate clientless proxy terminates the incoming HTTP/HTTPS connection and creates the authorized outbound connection to the application, it operates at the application layer rather than merely forwarding opaque network traffic.
That gives ZTXGate visibility into the web access path and allows HTTP-aware policy enforcement where supported by the configured product policy.
The exact policy controls available should be selected according to the protected application's requirements and the ZTXGate configuration.
Identity Before Application Access
Clientless access is still Zero Trust access.
A browser reaching the proxy is not automatically entitled to reach the protected application.
ZTXGate can use identity and access policy to determine whether the user should be allowed through to the resource. Connected deployments can use supported identity-provider integrations, while isolated deployments use the identity services available within their environment.
Step-Up Authentication
Sensitive web applications can require additional verification according to policy.
ZTXGate supports step-up authentication options including integrated ZTXBAS biometric approval and, in connected deployments, supported cloud authentication services such as Okta Verify and Duo.
When licensed with ZTXGate, ZTXBAS is tightly integrated as a library and works across connected, on-premises, and fully air-gapped deployment models without requiring a separate ZTXBAS server.
Clientless vs WireGuard-Based Access
The two models address different access requirements.
| Requirement | Clientless HTTP/HTTPS access | WireGuard-based access |
|---|---|---|
| Endpoint software | No WireGuard client required | WireGuard-based connectivity required |
| Supported resource type | Private HTTP/HTTPS applications | Authorized network resources and protocols |
| Browser-only workflow | Yes | Not required |
| Application-layer visibility | Yes, for proxied web traffic | Depends on resource/protocol |
| Good fit for contractors | Often | When broader protocol access is required |
| Good fit for managed employee devices | Yes for web apps | Yes for broader access |
Organizations can use both models rather than choosing one for every user and application.
Reduce Exposure for Private Web Applications
A private web application does not need broad network reachability simply because an external user must access it.
Clientless ZTNA lets the organization put the access decision in front of the application.
The user reaches ZTXGate, ZTXGate evaluates access, and only authorized traffic is connected onward to the protected resource.
This can be especially useful for internal business applications, administrative web interfaces, and temporary third-party access.
Contractor and Third-Party Access
Contractor access is one of the clearest clientless use cases.
If a contractor only needs a private web application, requiring network-level connectivity can provide more access capability than the task requires.
Clientless ZTNA allows the organization to provide access to the specific application instead.
Combine that with temporary access windows and request-and-approve workflows to limit both the scope and duration of third-party access.
Managed and Unmanaged Endpoints
Clientless access removes the need to install WireGuard connectivity software, but it does not make endpoint risk disappear.
An unmanaged device may provide fewer posture signals than an enrolled corporate endpoint. Access policy should reflect that difference.
For example, an organization might permit an unmanaged contractor endpoint to reach one low-risk web application while requiring enrolled devices for more sensitive resources.
The appropriate policy depends on the sensitivity of the resource and the controls available around the endpoint.
Auditability
Clientless access remains visible through the ZTXGate access path.
Authentication, access, and policy records can support operational review and investigation. Relevant events can also be exported to supported SIEM environments where connectivity exists.
This provides a central record of access rather than relying solely on each protected application's individual logs.
Deployment Flexibility
The clientless proxy is part of the ZTXGate deployment, which can be operated by the customer or an MSP.
It can be used with:
- on-premises ZTXGate deployments
- customer- or MSP-operated cloud deployments
- hybrid environments
- air-gapped environments for HTTP/HTTPS applications available within the isolated network
Core operation does not require a CoreZT-hosted cloud control plane.
What Clientless Access Does Not Replace
Clientless ZTNA is intentionally scoped to web applications.
If a user needs protocols or resources outside HTTP/HTTPS, use the appropriate ZTXGate client-based access model instead.
We do not describe the clientless proxy as a general-purpose browser gateway for arbitrary SSH, RDP, VNC, or TCP protocols unless a specific supported mechanism exists for that resource.
This keeps the access model clear and predictable.
Frequently Asked Questions
Does a clientless user install WireGuard?
No. For the clientless HTTP/HTTPS path, the user accesses the protected web application through the browser-facing ZTXGate proxy.
Is clientless access only for contractors?
No. It can be used by employees, administrators, partners, and other users whenever browser-based access is appropriate.
Can clientless and WireGuard access coexist?
Yes. An organization can use clientless access for web applications and WireGuard-based access for users or resources that require broader protocol support.
Can clientless access work in an air-gapped environment?
Yes, for HTTP/HTTPS applications and supporting identity/authentication services available within that environment.
Does clientless access mean unmanaged devices are trusted?
No. Clientless access removes the tunnel-client requirement; it does not imply that an unmanaged endpoint should receive the same permissions as a managed device.
Give Web Users Only the Access They Need
Provide browser-based access to private web applications without giving every user network-level connectivity.
Compare Clientless Access Models
See how deployment and browser-access models differ in ZTXGate vs Cloudflare Access, ZTXGate vs Zscaler Private Access, and ZTXGate vs Tailscale.