Skip to content

One tool. Every protocol.

HTTP, TCP, TLS, and mutual TLS tunnels with automatic HTTPS, reserved addresses, IP allow lists, and password protection. The agent is open source, we never read your traffic, and your tunnels stay in the region you choose.

  • Open-source agent
  • No payload inspection
  • EU data residency
  • Works behind CGNAT

Built to run in production.

Flat team pricing, no per-seat fees and nothing metered by usage. The same capabilities cover a weekend project and a fleet in the field, and each card below says when a plan gates it.

Access control

Secure Remote Access using mTLS

Devices answer only certificates you issued. Revoke one to cut its live connections. Pro and Enterprise.

IP Allowlist

Limit a tunnel to the addresses and ranges you trust. Everyone else is refused.

Password Protection

A username and password in front of any HTTP tunnel. No code changes.

Header Authentication

Require an API key or header on every request. Calls without it are refused.

Webhook Verification

Check signatures from GitHub, Stripe, Shopify, Slack, or a provider you configure.

Force HTTPS

Send every visitor to the https:// address. One toggle.

Account and team security

Two-Factor Authentication

Passkeys or an authenticator app. Admins can require it across the team.

Session Management

Every browser, phone, and CLI signed in. Sign one out and its access stops.

Audit Log

Every config change: who, from where, when, allowed or refused. Pro and Enterprise.

Access Log

Every connection to your devices. Traffic is never inspected. Pro and Enterprise.

Addresses and encryption

Custom Domains

Point your own domain at a tunnel with one CNAME. Wildcards included.

Automatic HTTPS

A real certificate every browser trusts, issued and renewed for you.

Static Subdomains

Reserve a subdomain so your URL survives every restart.

Reserved Ports

TCP and TLS tunnels keep a dedicated port, so clients reconnect to the same address.

Network and operations

Multi-Region

Pick the region per tunnel. Traffic stays there.

EU Data Residency

Account, billing, and tunnel data are stored in the EU.

Auto Reconnect

The agent reconnects after a network drop and reclaims its address.

Live Dashboard

Connections, bytes, and request counts per tunnel, in real time.

Team Management

Organise tunnels by team, invite members, control who reaches what.

Cross-Platform

One binary for macOS, Linux, and Windows. Intel, Apple Silicon, ARM.

Protocol support

Tunnel anything you run.

Web apps, databases, game servers, encrypted sockets. Pick the protocol that fits and keep the same command.

HTTP & HTTPS

Most used

Web apps and APIs, live in one command.

Every HTTP tunnel gets a real TLS certificate that browsers trust, issued automatically. You get the HTTP and the HTTPS address out of the box. Works with React, Next.js, Django, Rails, Flask, and anything that speaks HTTP.

https://myapp.eu.localport.dev
Client demosWebhook testingOAuth callbacksCI/CD previewsMobile QA

TCP

Anything that speaks raw TCP.

Databases, game servers, SSH, Redis, MQTT, custom protocols. Reserve a dedicated port and clients reconnect to the same address after every restart, no raw IP exposed.

tcp://myapp.eu.localport.dev:47266
Game serversDatabase accessSSHHome automation

TLS

End-to-end encrypted passthrough.

Traffic reaches your service still encrypted. Localport never sees the plaintext. Use it when your service owns its certificates, runs its own mTLS, or has compliance rules to meet.

tls://myapp.eu.localport.dev:47266
Own your certsZero trustComplianceService fleet

Remote Access

Name who reaches which device. Pro

A fleet refuses every caller until you say otherwise. Give access to a teammate, a role, or a machine, and name what it reaches: one device, a pattern, or the whole fleet. The grant is written against the identity, so it survives a certificate rotation, and taking it back closes the connections it covered.

Member, role or machineSurvives certificate rotationRemoval closes live sessions
localport
Deployment server Firmware update
localport
Jane's laptop Refused SSH session
Search Give access
Identity Kind Can reach
Developers Role kiosk-*
deploy-server Machine Every device
metrics-collector Machine line-*
Jane Cooper Member line-* +1
Type Member Change
Role Member Machine
Who Jane Cooper Change
Search people Jane Cooper Alex Morgan
Access
Search devices or add pattern line-*
line-* 30 devices kiosk-04 line-7-plc line-* line-7-hmi line-*

Reaching no devices yet Reaching 1 of 180 devices Reaching 31 of 180 devices

Give access to Jane Cooper
kiosk-04 line-* 149 more devices

Shared

One URL that reaches every teammate at once.

Register the webhook once and never touch it again. A fanout tunnel hands your whole team one permanent URL, so every teammate receives the same request the moment it lands. No per-developer tunnels, and no replaying events to chase.

One permanent URLSame payload to everyoneLive for every teammate
Learn more
POST /webhooks/payment
https://mywebhook.eu.localport.dev Disconnect all
alice-mac Disconnect
bob-pc Set Primary Disconnect
chad-linux Set Primary Disconnect
localport
Alice's terminal Webhook received
localport
Bob's terminal Webhook received
localport
Chad's terminal Webhook received

Read every line that touches your network.

The Localport agent is the binary that runs on your machine and tunnels your traffic. Its source lives on GitHub, so you can read it, build it from scratch, and audit the protocol before it ever connects.

When a tool sits between your machine and the internet, transparency matters. We run the hosted side as a managed service so your tunnels just work.

View on GitHub
$ git clone https://github.com/localport/agent
$ cd agent && make build
Single binary. Zero runtime dependencies. Reproducible builds.

Common questions.

Still deciding? The docs go deeper, or talk to us.

Does Localport work behind CGNAT, NAT, or a firewall?

Yes. The agent makes one outbound connection on port 443, so it works anywhere your browser does: behind NAT, CGNAT, double NAT, corporate firewalls, and cellular hotspots. No port forwarding and no router changes.

Which protocols can I tunnel?

HTTP and HTTPS for web apps and APIs, raw TCP for databases, SSH, and game servers, and TLS passthrough for services that own their certificates. Add a fleet on Pro when the endpoint has to answer only callers you trust.

Is the Localport agent really open source?

Yes. The binary that runs on your machine lives on GitHub. Read it, build it from scratch, and audit the protocol before it ever connects. We run the hosted side as a managed service so your tunnels just work.

Do you inspect or log my traffic?

No. We never read your payloads, log them, or train on them. Traffic passes straight through and stays in the region you choose. With TLS passthrough we never see the plaintext at all.

Can I use my own domain?

Yes. Point your domain at a tunnel with one CNAME record and get automatic HTTPS, wildcards included. Reserved subdomains and ports keep your address stable across restarts.

How is Localport different from ngrok?

Flat team pricing instead of per-seat fees and metered bandwidth, an open-source agent, and fleets and Fanout that ngrok does not offer. Same protocols, more in the box, no usage surprises.

Can I try it before paying?

Start with a free trial and cancel any time. Plans are flat from $5/mo billed yearly, with mutual TLS and higher limits on Pro.

Put it all to work.

Open-source agent. Flat team pricing from $5/mo billed yearly. Upgrade to Pro when you need mutual TLS or higher limits. Start with a free trial, cancel any time.