Remote access for every device you run.
SSH, VNC or any port on any device, from anywhere. Private by default, with every connection logged.
Reach devices on networks you don't control.
Kiosks, gateways and servers behind NAT, CGNAT or a customer's firewall. No open ports and no VPN.
Easy setup
Install the agent and run one command on each device.
- One binary, no dependencies
- New devices join automatically
- Works behind NAT and CGNAT
Any port on any device
Open SSH, VNC, a web interface or your own service.
- TCP and HTTP ports
- Opened from the dashboard
- Changes apply in seconds
One dashboard for the fleet
Every device and its live status in one place.
- Online and offline devices
- Uptime and traffic
- Remove a device instantly
Manage every device from one dashboard.
Remote Access is included in the Pro, Business and Enterprise plans.
See which devices are online, how long they have been up and how much traffic they carry, live.
- Easy setup
- One command on each device
- Auto-join
- New devices add themselves to your fleet
- Live status
- Online state, uptime and traffic
- Any port
- SSH, VNC, a web interface or your own service
- Works behind NAT
- CGNAT, cellular and customer networks
Decide who reaches what.
Devices are private until you grant access.
- People, roles and machines
- One device or a whole group
- Instant revocation
Credentials for people and machines.
No shared passwords. Private keys never leave the machine that holds them.
Setup keys
A machine redeems it once, then renews itself.
- Single use
- Self-renewing
- No lasting secret
CI/CD with OIDC
CI pipelines connect with no stored secret.
- GitHub Actions
- Any OIDC provider
- 15-minute certificates
Member sign-in
People connect as themselves.
- localport login
- Browser approval
- Expires on its own
See every connection and every change.
Know who connected to a device and who changed what.
Access log
Every connection to every device.
- Who, device and port
- Allowed or refused
- Traffic content never logged
Audit log
Every change to fleets, grants and team.
- Who, where, when
- Every change recorded
- Configurable retention
Common questions.
The docs go deeper, or talk to us.
What is a fleet?
A fleet is a group of devices that only the people and machines you grant can reach. You choose which ports each device opens.
Do devices need a public IP or open ports?
No. The agent connects outbound, so devices work behind NAT, CGNAT and firewalls with nothing to open.
Which ports can I reach on a device?
Any TCP or HTTP port you open for that device in the dashboard, such as SSH, VNC or a web interface. A device can open up to 32 ports.
What happens when someone leaves the team?
Their access ends on every fleet and their open connections close.
Does Localport update or manage software on my devices?
No. Localport gives you a private connection to every device. Use SSH, Ansible or your own tools over it.
How does someone connect to a device?
They run localport access with the device's address and a port. The port opens on their own machine and they connect to it like any local service, SSH included.
Do you hold our private keys?
No. Every certificate starts as a request made on the holder's machine, including in the dashboard. The private key never leaves it.
Can we use our own certificate authority?
Yes. Register your CA with its revocation list and its identities work alongside the ones Localport issues, each in its own namespace.
Bring your fleet online.
Create a fleet and connect your first device.