Skip to content

Remote access for every device you run.

SSH, VNC or any port on any device, from anywhere. Private by default, with every connection logged.

Reach devices on networks you don't control.

Kiosks, gateways and servers behind NAT, CGNAT or a customer's firewall. No open ports and no VPN.

Easy setup

Install the agent and run one command on each device.

  • One binary, no dependencies
  • New devices join automatically
  • Works behind NAT and CGNAT
Learn more

Any port on any device

Open SSH, VNC, a web interface or your own service.

  • TCP and HTTP ports
  • Opened from the dashboard
  • Changes apply in seconds
Learn more

One dashboard for the fleet

Every device and its live status in one place.

  • Online and offline devices
  • Uptime and traffic
  • Remove a device instantly
Learn more

Manage every device from one dashboard.

Remote Access is included in the Pro, Business and Enterprise plans.

See which devices are online, how long they have been up and how much traffic they carry, live.

Easy setup
One command on each device
Auto-join
New devices add themselves to your fleet
Live status
Online state, uptime and traffic
Any port
SSH, VNC, a web interface or your own service
Works behind NAT
CGNAT, cellular and customer networks
Learn more
157 of 159 online 157 of 160 online 158 of 160 online
Search devices... Create device
chg-ams-0231 3 412 reqs Online 31d 4h chg-ams-0231.edge.acme.com Access
farm-ber-017 3 2.4K reqs Online 8d 17h farm-ber-017.edge.acme.com Access
kiosk-0142 3 1.1K reqs Online 95d 2h kiosk-0142.edge.acme.com Access
sign-lis-0086 2 sign-lis-0086.edge.acme.com Connect
sign-lis-0091 2 Offline sign-lis-0091.edge.acme.com Connect
sign-lis-0091 2 0 reqs2 reqs4 reqs5 reqs7 reqs9 reqs11 reqs12 reqs14 reqs16 reqs18 reqs20 reqs22 reqs24 reqs25 reqs26 reqs28 reqs30 reqs32 reqs34 reqs35 reqs37 reqs38 reqs40 reqs42 reqs43 reqs44 reqs45 reqs47 reqs48 reqs49 reqs sign-lis-0091.edge.acme.com Access
kiosk-0142 sign-lis-0091 158 more devices

Decide who reaches what.

Devices are private until you grant access.

  • People, roles and machines
  • One device or a whole group
  • Instant revocation
Learn more
team:* *
Everyone on the team, new members included
role:developer kiosk-*
Every developer, every kiosk
user:<username> kiosk-0142
One person, one device
deploy-server sign-*
One machine, every signage player

Credentials for people and machines.

No shared passwords. Private keys never leave the machine that holds them.

Setup keys

A machine redeems it once, then renews itself.

  • Single use
  • Self-renewing
  • No lasting secret
Learn more

CI/CD with OIDC

CI pipelines connect with no stored secret.

  • GitHub Actions
  • Any OIDC provider
  • 15-minute certificates
Learn more

Member sign-in

People connect as themselves.

  • localport login
  • Browser approval
  • Expires on its own
Learn more

See every connection and every change.

Know who connected to a device and who changed what.

Access log

Every connection to every device.

  • Who, device and port
  • Allowed or refused
  • Traffic content never logged
Learn more

Audit log

Every change to fleets, grants and team.

  • Who, where, when
  • Every change recorded
  • Configurable retention
Learn more

Common questions.

The docs go deeper, or talk to us.

What is a fleet?

A fleet is a group of devices that only the people and machines you grant can reach. You choose which ports each device opens.

Do devices need a public IP or open ports?

No. The agent connects outbound, so devices work behind NAT, CGNAT and firewalls with nothing to open.

Which ports can I reach on a device?

Any TCP or HTTP port you open for that device in the dashboard, such as SSH, VNC or a web interface. A device can open up to 32 ports.

What happens when someone leaves the team?

Their access ends on every fleet and their open connections close.

Does Localport update or manage software on my devices?

No. Localport gives you a private connection to every device. Use SSH, Ansible or your own tools over it.

How does someone connect to a device?

They run localport access with the device's address and a port. The port opens on their own machine and they connect to it like any local service, SSH included.

Do you hold our private keys?

No. Every certificate starts as a request made on the holder's machine, including in the dashboard. The private key never leaves it.

Can we use our own certificate authority?

Yes. Register your CA with its revocation list and its identities work alongside the ones Localport issues, each in its own namespace.

Bring your fleet online.

Create a fleet and connect your first device.