Facebook’s open-source TLS 1.3 library is Fizz, a reusable C++14 implementation of the protocol that Meta developed for network services—not a consumer app or a standalone security product. It provides client and server protocol components, asynchronous interfaces, and APIs intended to support integrations such as QUIC. Its fit depends on your C++ environment, Folly-based networking stack, required TLS modes, and current project support.
What Fizz is—and what it is not
Fizz is an open-source C++14 library for implementing TLS 1.3 connections. The project repository contains protocol components for both clients and servers, along with an example command-line tool. It is intended to be embedded in software, rather than installed and used like a consumer VPN or browser extension. Fizz on GitHub
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Teacher Record Book | $4.89 | Buy on Amazon |
| 2 |
|
The Little Lost Library (A Secret, Book and Scone Society Novel) | $9.23 | Buy on Amazon |
| 3 |
|
The Standards Real Book, C Version | $47.00 | Buy on Amazon |
| 4 |
|
The Eerie Book | $21.49 | Buy on Amazon |
| 5 |
|
Lost Library Collected Short Stories | $3.99 | Buy on Amazon |
TLS is the protocol that protects data in transit between communicating applications. Fizz supplies TLS 1.3 functionality to a program; using the library does not by itself configure an application, secure every network path, or guarantee that a deployment is correctly operated.
How Fizz is designed for network services
The project organizes protocol behavior around explicit client and server state machines. Configuration is handled through FizzClientContext and FizzServerContext, while FizzClient and FizzServer provide application-facing interfaces. Asynchronous wrappers connect the library to Folly transport abstractions.
#1 Best Overall
- Keep track of everything from attendance to test scores
- Spiral bound
- Measures 8-1/2" x 11"
The README describes its typed state-and-action design as a way to make invalid transitions compile-time errors. That is a design goal, not proof that the implementation is free of defects or that every application integration is safe.
Fizz also describes zero-copy APIs and exported keying material, capabilities that can matter when integrating TLS with transports such as QUIC. Whether a particular API or feature is usable depends on the release, code path, and configuration in question.
Protocol features listed by the project
The repository lists several handshake and integration capabilities. Treat these as project documentation, not a guarantee that every option is enabled or supported in every build:
- PSK resumption: supports resuming sessions using pre-shared keys.
- Early data: provides a TLS 1.3 early-data mode; applications still need to account for the security and replay considerations of early data.
- Client authentication: includes handshakes in which the client authenticates to the server.
- HelloRetryRequest: lists support for the server’s TLS 1.3 retry mechanism.
- Exported keying material and zero-copy APIs: provide integration points for applications and transports, including QUIC-related use cases.
- Asynchronous APIs: are designed to work with Folly networking abstractions.
Because the README can change, verify a needed feature against the specific release and configuration you plan to deploy rather than assuming that a broad feature list applies to your build.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsRank #3
- Used Book in Good Condition
Dependencies and build approach
The project documents Folly, OpenSSL, and libsodium as dependencies. Those requirements make Fizz most straightforward to evaluate in a C++ environment that can accommodate its dependencies and, for the asynchronous integration, Folly’s abstractions.
The repository documents two build approaches: using getdeps.py or using CMake for a conventional build and installation. Consult the current README for exact commands, supported dependency versions, compiler requirements, and release-specific build instructions; these can change over time. Current Fizz build documentation
Rank #4
What Meta reported about deploying Fizz
In an August 6, 2018 engineering post, Meta said it had deployed Fizz and TLS 1.3 across its mobile apps, Proxygen, load balancers, internal services, and QUIC library. Meta reported that Fizz handled millions of TLS 1.3 handshakes per second and that more than 50 percent of its internet traffic was then secured with TLS 1.3. These are Meta’s figures for its own deployment at that time, not current measurements or independent benchmarks. Meta Engineering: Fizz
In the same 2018 post, Meta said synthetic load-balancer benchmarks showed approximately 10 percent higher throughput than its previous stack. That result is specific to Meta’s synthetic tests and historical comparison; it does not establish that Fizz will outperform another TLS implementation on a different workload.
Best Value
Meta’s later post-quantum work
In a May 22, 2024 engineering account, Meta described extending Fizz with hybrid key exchange: post-quantum mechanisms from liboqs used alongside classical mechanisms. The post named Kyber768 as the intended default and Kyber512 for situations in which the larger parameterizations had prohibitive performance impact. Those were Meta’s described design choices at publication, not a universal Fizz default or a guarantee about present deployments. Meta Engineering: Post-quantum cryptography
When Fizz may be a fit
Fizz is worth evaluating when an application is written in C++ and its networking design aligns with Folly, or when its specific TLS modes and integration APIs meet a concrete requirement. Before adopting it, check:
- Whether the current project release supports the TLS features and configuration your application requires.
- Whether your build and deployment environments can maintain Folly, OpenSSL, and libsodium dependencies.
- How the asynchronous interfaces fit your transport, event loop, and application architecture.
- What project maintenance, security updates, and operational support are available for the release you intend to use.
- How candidate implementations perform under your own workload and test conditions; Meta’s historical synthetic result is not a substitute for that measurement.
The repository and Meta’s engineering posts establish Fizz’s intended scope and describe Meta’s use of it. They do not, on their own, establish current maintenance cadence, suitability for every deployment, or comparative performance on a reader’s system.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

