Secure tunnels and remote access
for every machine.
A persistent public URL for anything you run.
Private access to every device you deploy.
Built on security and privacy.
Public URLs for local services and private access to deployed devices, with access you control.
Tunnels
A persistent public URL for anything you run
Share any local app or service, or receive webhooks, on a URL that stays the same.
- HTTP, TCP and TLS
- Automatic HTTPS
- Custom domains
- One webhook URL for your whole team
Remote Access
Private access to every device you deploy
Reach kiosks, gateways and servers on any network. Only the people and machines you authorize can connect.
- No open ports, no VPN
- Per-device permissions
- Instant revocation
- Access logs
Security and privacy
Security your team can verify
The agent on your machine is open source. We don't log what you send and we don't hold your private keys.
- Open-source agent
- Traffic content never logged
- Keys stay on the device
- EU data residency
Public URLs over HTTP, TCP and TLS.
Put your app, API, local LLM or game server online with one command. You control who can reach it.
- Custom subdomain
- Set your own subdomain name
- Custom domain
- Your own domain or a wildcard, with automatic SSL
- Reserved ports
- A fixed port for TCP and TLS tunnels
- Region
- EU, US or Asia Pacific
- IP allowlist
- Limit access to the IP addresses you list
- Basic auth
- Password protection for HTTP tunnels
- Header authentication
- Set header rules every request must match
- Signature verification
- Verify Stripe, GitHub, Shopify and Slack webhooks
Manage every device from one dashboard.
Remote Access is included in the Pro, Business and Enterprise plans.
Add devices, see their live status and set the ports allowed on each one.
- Easy setup
- One command on each device
- Auto-join
- New devices join the fleet when they first connect
- Live status
- Online state, uptime and traffic
- Allowed ports
- SSH, VNC, a web interface or any service
- Works behind NAT
- CGNAT, cellular and customer networks
One webhook URL for your whole team.
Change a tunnel's delivery mode to Fanout. Every developer on the team receives each webhook on their own machine.
- Any HTTP tunnel
- Webhooks, APIs and other HTTP traffic
- Delivered to every device
- Each connected device receives every request
- One primary device
- Its response goes back to the sender
- HTTP protection
- Signatures, header rules and basic auth
Privacy by design.
Traffic content is not logged, private keys stay on your devices and traffic stays in the region you choose.
- Traffic content is not logged
- Your traffic is forwarded and not stored.
- Keys stay on the device
- Private keys are never sent to us.
- Traffic stays in your region
- EU, US or Asia Pacific, set for each tunnel.
- EU data residency
- Account data and backups are stored in the European Union.
Get your first tunnel running.
-
Create a tunnel in the dashboard.
Give it a name and pick a region.
-
Install the agent.
-
Run the command from the dashboard.
Your tunnel's token is already in it.
Every plan starts with a trial. Cancel any time.
- macOS
- Linux
- Windows
- Docker
- Raspberry Pi
Inspect what runs on your machine.
The Localport agent is open source under Apache 2.0. Read the code on GitHub and verify the signature on every release.
- One binary, no dependencies
- Runs on a laptop, a server or a Raspberry Pi.
- Works behind NAT and firewalls
- Outbound connections only.
- Automatic reconnection
- Reconnects after a network change or sleep, on the same address.
- Runs as a service
- Starts at boot with systemd or launchd.
One flat price for your whole team.
Plans are priced per team, with no per-seat fees and no usage bills. Team members are included in every plan.