IT Buyers Guide · Concept · 13 min read

Open Source RMM, and What Each Project’s License Actually Allows

Most lists of open source RMM tools mix genuinely open source projects with a source-available one, an abandoned fork, and monitoring tools that are not RMM at all. This reads each license and each pricing page at source.

Written by Marko Ristic, Editor Updated Sep 11, 2026
$55a month for Tactical RMM’s Mac and Linux agents, self-hosted Tier 1
25devices in NetLock RMM’s free Community Edition
2017the year MeshCentral went public, the oldest project here
4 GBof RAM, the minimum in Tactical RMM’s server guide
Short answer

Open source RMM is remote monitoring and management software published under a license that lets you run, study, change and share it. MeshCentral (Apache 2.0), Breeze (AGPL-3.0) and the NetLock RMM core (AGPL-3.0) qualify.

Tactical RMM, the tool most lists put first, publishes its source under a license that states it is not an open source license, and its Mac and Linux agents need a paid sponsorship. Free, self-hosted and open source are three separate claims.

  • MeshCentral: Apache 2.0, server and agent, remote access and management
  • NetLock RMM: AGPL-3.0 core, free Community Edition up to 25 devices
  • Breeze: AGPL-3.0, unlimited devices self-hosted, public since January 2026
  • Tactical RMM: source-available, Mac and Linux agents from $55 a month
  • Zabbix and Nagios are monitoring tools, not RMM
On this page

The definitionsOpen source, free and self-hosted are three different claims

Search for open source RMM software and the results mix three things together, and the difference decides what you can legally do with the tool.

Open source is a license question. The Open Source Initiative's definition is the one the industry uses, and its sixth rule is the one that matters here: the license must not restrict anyone from using the program in a specific field of endeavor, and its own example is that it may not restrict the program from being used in a business.

A license that lets you read the code but forbids some commercial use is source-available. That is a legitimate model, and it is not open source.

Free is a price question. Plenty of commercial RMM products have a free tier, which is a price the vendor can change, attached to software whose source you will never see. A free RMM and an open source RMM overlap only when the software is both.

Self-hosted is a deployment question. Every open source RMM on this page runs on your own server, and several also sell a hosted version. A self-hosted RMM can be closed source, and an open source one can be rented from the vendor.

The reason any of this matters for remote monitoring and management in particular is the agent. An RMM agent runs as SYSTEM on Windows and root on Linux on every machine it manages, which is what makes RMM useful and dangerous at once.

Being able to read exactly what that agent does, and to build it yourself, is the strongest argument for open source RMM, stronger than the price.

The second is data: with a self-hosted RMM the inventory, the scripts and the monitoring data for every client stay on a server you control, which is a real answer when a client asks where their data lives.

The projectsThe projects that are genuinely RMM, read at source

Every license below was read in the project's own repository, and every price on the vendor's own pricing page, on September 11, 2026.

MeshCentral. Licensed under Apache 2.0, one of the most permissive licenses there is. The project describes itself as a full computer management web site: you run your own server, install an agent on each machine, and get web-based remote desktop, terminal and file management.

The agent is compiled for Windows, many Linux distributions, macOS and FreeBSD, on processors from x86 to ARM and MIPS. Its server and its agent are both Apache 2.0, and it is the oldest project in this group, public since 2017, with about 7,200 stars on GitHub and a release in August 2026.

Think of it as the remote access and remote control layer; on its own it is not organized around automated checks, alerting and patch policy the way an MSP platform is, which is why other projects build on it.

Tactical RMM. Built with Django and Vue, with an agent written in Go, and it integrates MeshCentral for remote desktop. Its feature list covers remote shell, file browser, registry editor, script execution in PowerShell, Python and other languages, event log and services management, Windows patch management, automated checks with email, SMS or webhook alerting, software installation through Chocolatey, and hardware and software inventory.

It is the project most often compared with commercial RMMs, often written TacticalRMM, public since 2019, and the details below are the ones the lists leave out.

NetLock RMM. A platform written in C# and .NET, with agents for Windows, Linux and macOS, monitoring with hundreds of sensors including SNMP, patch management for Windows, Linux and macOS, software deployment through winget and Chocolatey, multi-tenancy and single sign-on. The repository is licensed AGPL-3.0.

Its README says that in 2026 the project moved to an open-core model: the core stays open under the AGPL, public commits are paused, and not every feature's source is published. Its remote screen control is listed for Windows and Linux.

Breeze. Licensed AGPL-3.0, and it describes itself as an RMM and PSA in one system, covering monitoring, patching, remote access, scripting, network discovery, ticketing and invoicing, with an AI operator built in.

The self-hosted Community edition is free for unlimited devices, the README says every module ships in every plan, and it lists working agents for macOS, Windows and Linux, where remote desktop requires root.

The GitHub repository was created on January 14, 2026, which makes it months old rather than years. Breeze also publishes one of the highest-ranking guides to open source RMM tools, which is worth knowing when you read it.

OpenRPort. An MIT-licensed community fork of rport, a remote access and inventory tool. Its license file credits portions of the code to CloudRadar in 2020 and to RealVNC in 2023, the two companies the original project passed through.

The fork's latest release is 0.9.14, from November 14, 2023. It still appears on lists of the best open source RMM software, and a project with no release in almost three years is not one to put agents on client machines with.

The gapsWhat the free versions leave out

Open source does not always mean the whole product is free, and the gaps are specific.

Tactical RMM's license. The first section of the Tactical RMM License Version 1.0 states that it is not an open-source software license. It permits hosting and using the software to monitor and manage in-house networks and customer networks, so an MSP can run it for its clients.

It forbids making its functionality available as part of any other commercial or for-profit service without written approval from AmidaWare, and the list it gives includes a SaaS product, a managed hosting service, and the offering of installation and configuration services.

Anyone who plans to sell a service built around the tool, rather than simply use it, should read that section before deploying.

Tactical RMM's agents. The free build gives you the Windows agent. The project lists these as sponsorship features: Mac and Linux agents, code-signed Windows agents, the customizable reporting module and single sign-on.

The documentation says access to code-signed agents, which also includes the Linux and macOS agents, requires at least a Tier 1 sponsorship.

On the pricing page that tier is $55 a month or $600 a year, self-hosted, for 0 to 199 endpoints, and on the self-hosted plans the reporting module starts at the next tier. The documentation is candid that code signing helps with antivirus products flagging the agent and does not guarantee it will stop.

NetLock's device cap. The self-hosted Community Edition costs nothing and covers up to 25 devices, with all features and code-signed Windows agents. The Pro plan removes the cap for €55 a month, VAT included. The code is AGPL, the free edition is a product tier, and both statements are true at once.

MeshCentral's scope. MeshCentral publishes both the server and the agent under Apache 2.0, and its scope is remote access and management rather than a full MSP stack. The patch policy, automated checks and reporting that an MSP expects come from what you build around it, or from a project like Tactical RMM that builds on it.

Not RMMThe tools the lists add that are not RMM

Most rankings of open source RMM tools pad the list, and the padding falls into three groups.

Monitoring platforms. Zabbix, Nagios Core, Icinga, Checkmk Raw, Netdata and OpenNMS appear on several lists. They are excellent at the monitoring half: they collect metrics, watch services and raise alerts. They are not built to patch machines, deploy software or give a technician a remote desktop, which is the management half and the reason RMM is a separate category.

Remote desktop tools. RustDesk is licensed AGPL-3.0 and is a good self-hosted replacement for commercial remote support, with your own relay server. Remote access is one feature of an RMM, not the product.

Device management and query tools. Fleet, built on osquery, is MIT licensed outside its enterprise directory and manages and queries devices at scale. It sits closer to MDM and endpoint visibility than to an MSP's RMM console.

Commercial products with a free tier appear too. A free tier is a price, not a license, and the source is not published.

Self-hostingWhat self-hosting actually takes

The license fee disappears, and the work does not. Tactical RMM's installation guide is a useful measure because it is specific.

A server. A fresh Linux virtual machine running Debian 11, Debian 12 or Ubuntu 22.04 with at least 4 GB of RAM. The guide says one core is fine for fewer than 200 agents with limited checks and tasks, and disk space depends on how long you keep history.

A domain and certificates. Tactical RMM needs three subdomains, for the frontend, the backend API and MeshCentral, with DNS records pointing at the server and Let's Encrypt certificates, or your own. Port 443 has to be reachable by every agent and every technician.

Backups and upgrades. The server holds the agent keys, the scripts and the whole configuration. Losing it without a backup means reinstalling agents on every machine. Upgrading it is your job, on your schedule.

Support. With a commercial RMM, support is part of the price. With open source RMM software it is a community, usually a Discord server, unless you pay for more. Tactical RMM's self-hosted plans include community support, and a support response time appears only from Tier 3, at 72 hours; its hosted plans carry one on every tier.

NetLock's free edition comes with community Discord support, and Breeze's free edition with community support on Discord. For MSPs, the question is who answers when the RMM server itself fails at night, and on a free plan that answer is you.

The security of the console. This is the part that matters most. An RMM server is a remote execution channel to every managed endpoint, and with a self-hosted RMM nobody else is watching it.

Enforce multi-factor authentication on every technician account, keep the server patched, restrict who can run scripts against which clients, and send the audit log somewhere the RMM cannot delete it. Tactical RMM's installation guide lists a TOTP authenticator app as a requirement, which is the right default.

The cost comparison that holds up is time against money. A commercial RMM is usually priced per endpoint per month, so the cost grows with every device on the network, and the MSP software ranking shows what the main platforms charge.

An open source RMM costs a small virtual machine or VPS and the hours of a person who can run Linux, DNS and certificates, and who will be on call when the server is down.

For MSPs with a few thousand endpoints the saving is real; for a company with 40 endpoints and no Linux skills in-house, the free tool can easily cost more than the paid one.

ChoosingChoosing an open source RMM

Four questions narrow it down quickly.

Which operating systems do you manage? For Windows-only estates, Tactical RMM's free build covers the core. For macOS and Linux, Tactical RMM needs a sponsorship, while NetLock, Breeze and MeshCentral ship those agents in the free version.

Do you need the full RMM, or remote access? If the job is reaching machines and fixing them by hand, MeshCentral alone is enough and fully open.

If the job is monitoring, automation, alerting and patch management across many clients, look at NetLock, Breeze or Tactical RMM, and compare their features against the list of what your technicians actually do every week.

Are you an MSP selling the service? Using Tactical RMM to manage client networks is permitted; building a hosted or installation service around it is not, without approval. The AGPL projects allow commercial use, and if you modify them and let users interact with the modified version over a network, you must offer those users its source.

How much history does the project have? MeshCentral and Tactical RMM have years of releases and large communities. NetLock's open-source version was released at the end of 2024. Breeze's repository dates from January 2026.

A young project can be excellent, and it has less of a track record on the one thing an RMM cannot get wrong, which is the security of the agent channel.

PitfallsWhere people go wrong

Calling Tactical RMM open source. Its own license says it is not. It is a capable tool with its source published, and the difference matters to anyone building a commercial service around it.

Assuming the Mac agent is free. In Tactical RMM it is a sponsorship feature. Discovering that after rolling out the Windows side is a common surprise.

Choosing a monitoring tool as an RMM. Zabbix will tell you a disk is full and will not patch the machine or let a technician onto its desktop.

Deploying an abandoned project. A fork with no release since 2023 is still on several best-of lists. Check the latest release date before installing an agent anywhere.

Leaving the console exposed without MFA. Every argument for open source RMM is undone by a self-hosted console with a password as its only protection. This is the most important control on the whole system.

Expecting vendor support. The free editions come with community support. If your MSP needs a guaranteed response time, that is a paid tier or a commercial RMM.

Forgetting the server is now yours to patch. A commercial vendor patches its own platform. With self-hosted RMM, the update to the RMM itself is on your list, alongside the updates it pushes to everyone else.

THE SAME LIST, FOUR DIFFERENT LICENSESOPEN SOURCEOSI license, any useMeshCentralApache 2.0BreezeAGPL-3.0OpenRPortMIT, last release 2023OPEN COREcore open, rest notNetLock RMMAGPL-3.0 coreFree editionup to 25 devicesSOURCE-AVAILABLEread it, limited useTactical RMMits own licenseMac and Linuxagents from $55/moNOT RMMon the lists anywayZabbix, Nagiosmonitoring onlyRustDeskremote desktop onlyLicenses read in each project’s repository and prices on its own pricing page, September 11, 2026.
The tools listed as open source RMM, placed by what their licenses actually say. The first column is open source in full; NetLock publishes its core under the AGPL and keeps some features closed.

ComparisonOpen source RMM projects, compared on license, agents and scope

CriterionMeshCentralTactical RMMNetLock RMMBreeze
LicenseApache 2.0Tactical RMM License, source-availableAGPL-3.0 core, open coreAGPL-3.0
Open source by the OSI definitionYesNoCore, yesYes
Free Windows agentYesYesYes, up to 25 devicesYes
Free Mac and Linux agentsYesNo, sponsorship from $55 a monthYes, up to 25 devicesYes
Patch managementNot its scopeWindowsWindows, Linux, macOSOS and applications
Automated checks and alertingNot its scopeYesYesYes
Remote desktopYesThrough MeshCentralWindows and LinuxYes, root on Linux
Hosted version sold by the projectNone on its siteYesYesBeta
GitHub stars, September 2026About 7,200About 4,500About 400About 100
Public since20172019End of 2024January 2026

Read the second and fourth rows first. They are where Tactical RMM differs from the lists that rank it as the leading free, open source option, and where the other three differ from each other less than their marketing suggests.

FAQFrequently asked questions

Is there a truly open source RMM?

Yes. MeshCentral is Apache 2.0, Breeze is AGPL-3.0, and NetLock RMM's core is AGPL-3.0. Tactical RMM publishes its source under its own license, which states it is not an open-source license.

Is Tactical RMM open source?

No, by its own license. The Tactical RMM License Version 1.0 says it is not an open-source software license, and it restricts commercial services built around the software, such as SaaS, managed hosting and installation or configuration services, without written approval. Using it to manage your own or your customers' networks is permitted.

Is Tactical RMM free?

The self-hosted server and the Windows agent are free. Mac and Linux agents, code-signed Windows agents and single sign-on need a sponsorship, which starts at $55 a month or $600 a year, self-hosted, for up to 199 endpoints. The reporting module starts at the next tier.

What is the best open source RMM?

It depends on the estate. For remote access alone, MeshCentral. For a full RMM with Mac and Linux agents in the free version, NetLock or Breeze, bearing in mind NetLock's free edition stops at 25 devices and Breeze is a 2026 project. For Windows-heavy MSP work with years of community use, Tactical RMM, under its license terms.

Is MeshCentral an RMM?

It covers the remote management side: agents on Windows, Linux, macOS and FreeBSD, remote desktop, terminal and file management through your own server. It is not built around automated checks and patch policy, which is why Tactical RMM uses it as its remote access layer.

What does self-hosted RMM cost?

No license fee for the open source projects, and a server, a domain, certificates, backups and an administrator's time. Tactical RMM's own guide asks for a Linux virtual machine with at least 4 GB of RAM and three subdomains.

Is NetLock RMM free?

The self-hosted Community Edition is free for up to 25 devices with all features included. The Pro plan, at €55 a month including VAT, removes the device limit.

Is open source RMM secure?

The code can be audited, which is a real advantage for software that runs as SYSTEM everywhere. The deployment is only as secure as you make it: MFA on every account, a patched server, scoped script permissions and an audit log kept outside the RMM.

Can an MSP use open source RMM for clients?

Yes. The AGPL and Apache projects allow commercial use. Tactical RMM's license explicitly permits managing customer networks and forbids selling hosted, installation or configuration services built around it without approval.

Is Zabbix an RMM?

No. Zabbix is a monitoring platform, and a very good one. It watches and alerts, and it does not patch machines, deploy software or provide remote desktop, which are the management half of an RMM.

What happened to RPort?

The original rport's code passed through CloudRadar and RealVNC, according to the license file of OpenRPort, the MIT-licensed community fork. OpenRPort's latest release is 0.9.14, from November 2023.

Does an open source RMM include a PSA?

Most do not. Breeze includes ticketing, quotes and invoicing in the same system. With the others, tickets and billing live in a separate PSA, integrated through webhooks or an API.

Read next · Managed IT What RMM Is, and What the Agent Can Actually Do What the agent and the console do, before choosing whose code runs them. Open this next9 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.