A comparison of overlay networks: Pilot Protocol, Tailscale, ZeroTier, and Nebula. They create virtual addresses, encrypt traffic, and traverse NATs, but are designed for different use cases, such as networking for agents versus VPN mesh for humans.
Overview
Pilot Protocol, Tailscale, ZeroTier, and Nebula are all overlay networks. They create virtual addresses, encrypt traffic, and traverse NATs. The difference is who they are built for.
Pilot Protocol - An overlay network built for autonomous AI agents. Provides virtual addresses, port-based services, a bilateral trust model, peer discovery with tags, and built-in application services (data exchange and pub/sub). Pure Go, statically linked, with a small dependency set.
Tailscale - A VPN mesh built on WireGuard for connecting human users and servers. Manages device access through an admin console, integrates with SSO/OIDC, and provides Magic DNS.
ZeroTier - A virtual Ethernet switch that creates flat L2 networks. Devices join a network ID and get an IP. Managed through a central controller.
Nebula - Slack's overlay network for connecting servers at scale. Certificate-based identity, firewall rules in config files, designed for infrastructure teams.
libp2p - A modular networking stack for peer-to-peer applications. Provides transport, discovery, and pubsub primitives. Used by IPFS, Ethereum, and Filecoin.
vs Tailscale
Tailscale is a WireGuard-based mesh VPN with NAT traversal and an administrative interface. It is designed for connecting users and servers under centralized access control. Pilot Protocol is designed for autonomous agents that generate their own identity and negotiate trust without an administrator. They can coexist in the same deployment.
The key difference is the management model. Tailscale is built for human-managed networks with an identity provider and admin-defined ACL policies. Pilot Protocol is built for agent-managed networks where agents generate their own cryptographic identity and negotiate trust directly with peers. Pilot tunnels can run over a Tailscale link.
vs ZeroTier
ZeroTier creates virtual Ethernet segments (L2). Any device can join a network by ID and get an IP. Pilot Protocol operates at L3/L4 with port-based service multiplexing and agent-native features.
The key difference is the level of abstraction. ZeroTier emulates Ethernet, providing a flat network on which other services are built. Pilot Protocol provides a complete agent networking stack, including addressing, transport, discovery, trust, and application-layer services.
vs Nebula
Nebula is Slack's overlay network for infrastructure. It uses certificate-based identity and config-file firewall rules. Pilot Protocol uses dynamic trust negotiation and agent-driven discovery.
The key difference is identity management. Nebula requires a PKI setup with a certificate authority to sign and distribute certificates for each node. Pilot Protocol agents generate their own identity and negotiate trust at runtime. This makes Pilot suited for dynamic agent populations, while Nebula is suited for static infrastructure with known hosts.
vs libp2p
libp2p is a modular networking toolkit used by IPFS, Ethereum, and Polkadot. It provides building blocks, whereas Pilot Protocol provides a complete, opinionated stack.
The key difference is scope. libp2p is a toolkit that requires choosing and assembling transports, discovery mechanisms, and security protocols. Pilot Protocol is an opinionated and complete stack with a small dependency set, built-in services, and a trust model designed for agents.
Feature matrix
Agent-native design: Yes (Pilot), No (Tailscale, ZeroTier, Nebula, libp2p)
Account required: No (Pilot, Nebula, libp2p), Yes (Tailscale, ZeroTier)
PKI/CA required: No (Pilot, Tailscale, ZeroTier, libp2p), Yes (Nebula)
Pure-Go implementation: Yes (Pilot, Tailscale, Nebula, libp2p), No (ZeroTier)