Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Facebook’s open-source TLS 1.3 library is Fizz, a reusable C++14 implementation of the protocol that Meta developed for network services—not a consumer app or a standalone security product. It provides client and server protocol components, asynchronous interfaces, and APIs intended to support integrations such as QUIC. Its fit depends on your C++ environment, Folly-based networking stack, required TLS modes, and current project support.

What Fizz is—and what it is not

Fizz is an open-source C++14 library for implementing TLS 1.3 connections. The project repository contains protocol components for both clients and servers, along with an example command-line tool. It is intended to be embedded in software, rather than installed and used like a consumer VPN or browser extension. Fizz on GitHub

TLS is the protocol that protects data in transit between communicating applications. Fizz supplies TLS 1.3 functionality to a program; using the library does not by itself configure an application, secure every network path, or guarantee that a deployment is correctly operated.

How Fizz is designed for network services

The project organizes protocol behavior around explicit client and server state machines. Configuration is handled through FizzClientContext and FizzServerContext, while FizzClient and FizzServer provide application-facing interfaces. Asynchronous wrappers connect the library to Folly transport abstractions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Teacher Record Book
  • Keep track of everything from attendance to test scores
  • Spiral bound
  • Measures 8-1/2" x 11"

The README describes its typed state-and-action design as a way to make invalid transitions compile-time errors. That is a design goal, not proof that the implementation is free of defects or that every application integration is safe.

Fizz also describes zero-copy APIs and exported keying material, capabilities that can matter when integrating TLS with transports such as QUIC. Whether a particular API or feature is usable depends on the release, code path, and configuration in question.

Protocol features listed by the project

The repository lists several handshake and integration capabilities. Treat these as project documentation, not a guarantee that every option is enabled or supported in every build:

  • PSK resumption: supports resuming sessions using pre-shared keys.
  • Early data: provides a TLS 1.3 early-data mode; applications still need to account for the security and replay considerations of early data.
  • Client authentication: includes handshakes in which the client authenticates to the server.
  • HelloRetryRequest: lists support for the server’s TLS 1.3 retry mechanism.
  • Exported keying material and zero-copy APIs: provide integration points for applications and transports, including QUIC-related use cases.
  • Asynchronous APIs: are designed to work with Folly networking abstractions.

Because the README can change, verify a needed feature against the specific release and configuration you plan to deploy rather than assuming that a broad feature list applies to your build.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
The Standards Real Book, C Version
  • Used Book in Good Condition

Dependencies and build approach

The project documents Folly, OpenSSL, and libsodium as dependencies. Those requirements make Fizz most straightforward to evaluate in a C++ environment that can accommodate its dependencies and, for the asynchronous integration, Folly’s abstractions.

The repository documents two build approaches: using getdeps.py or using CMake for a conventional build and installation. Consult the current README for exact commands, supported dependency versions, compiler requirements, and release-specific build instructions; these can change over time. Current Fizz build documentation

What Meta reported about deploying Fizz

In an August 6, 2018 engineering post, Meta said it had deployed Fizz and TLS 1.3 across its mobile apps, Proxygen, load balancers, internal services, and QUIC library. Meta reported that Fizz handled millions of TLS 1.3 handshakes per second and that more than 50 percent of its internet traffic was then secured with TLS 1.3. These are Meta’s figures for its own deployment at that time, not current measurements or independent benchmarks. Meta Engineering: Fizz

In the same 2018 post, Meta said synthetic load-balancer benchmarks showed approximately 10 percent higher throughput than its previous stack. That result is specific to Meta’s synthetic tests and historical comparison; it does not establish that Fizz will outperform another TLS implementation on a different workload.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Meta’s later post-quantum work

In a May 22, 2024 engineering account, Meta described extending Fizz with hybrid key exchange: post-quantum mechanisms from liboqs used alongside classical mechanisms. The post named Kyber768 as the intended default and Kyber512 for situations in which the larger parameterizations had prohibitive performance impact. Those were Meta’s described design choices at publication, not a universal Fizz default or a guarantee about present deployments. Meta Engineering: Post-quantum cryptography

When Fizz may be a fit

Fizz is worth evaluating when an application is written in C++ and its networking design aligns with Folly, or when its specific TLS modes and integration APIs meet a concrete requirement. Before adopting it, check:

  • Whether the current project release supports the TLS features and configuration your application requires.
  • Whether your build and deployment environments can maintain Folly, OpenSSL, and libsodium dependencies.
  • How the asynchronous interfaces fit your transport, event loop, and application architecture.
  • What project maintenance, security updates, and operational support are available for the release you intend to use.
  • How candidate implementations perform under your own workload and test conditions; Meta’s historical synthetic result is not a substitute for that measurement.

The repository and Meta’s engineering posts establish Fizz’s intended scope and describe Meta’s use of it. They do not, on their own, establish current maintenance cadence, suitability for every deployment, or comparative performance on a reader’s system.

Quick Recap

Bestseller No. 1
Teacher Record Book
Teacher Record Book
Keep track of everything from attendance to test scores; Spiral bound; Measures 8-1/2" x 11"
$4.89
Bestseller No. 3
The Standards Real Book, C Version
The Standards Real Book, C Version
Used Book in Good Condition
$47.00
SaleBestseller No. 4

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.