🚀 Maximize your product's SEO. Submit to 240+ directories in 1-click with DirSubmit. Launch Now
tunnl.gg logo

tunnl.gg

Stable localhost URLs over SSH with no installs

2026-10-08

Product Introduction

  1. Definition: tunnl.gg is an open-source, SSH-based reverse tunnel service that provides a public HTTPS URL for a localhost server. It operates as a secure shell (SSH) server (proxy.tunnl.gg) that users connect to from their local machine using the standard SSH client.
  2. Core Value Proposition: It exists to simplify and secure the process of exposing local development servers to the internet, eliminating the need for complex port forwarding, VPNs, or installing proprietary client software. Its primary value lies in offering persistent, stable URLs tied to SSH keys without requiring an account, making it ideal for testing webhooks, OAuth callbacks, and sharing live demos.

Main Features

  1. SSH-Powered Tunneling: The core technology uses the SSH protocol's reverse port forwarding (-R flag). Users execute a single command (ssh -t -R 80:localhost:<port> proxy.tunnl.gg) to establish an outbound, encrypted connection. This method requires no inbound firewall rules, router configuration, or background daemons, leveraging the SSH client present on virtually all development machines.
  2. Stable URL Generation: By connecting as the user stable ([email protected]), the service generates a deterministic subdomain (e.g., brave-fox-7c41e09b.tunnl.gg) derived from the user's public SSH key via HMAC-SHA256 with a server-side secret. This provides a permanent, reusable public endpoint without user registration, key uploads, or authentication tokens.
  3. Integrated HTTPS & Edge Processing: Every tunnel is served over HTTPS using a wildcard TLS certificate for *.tunnl.gg. The tunnl.gg edge network handles TLS termination, applies phishing protection (a one-time interstitial warning for new browser visitors), enforces configurable rate limits, and proxies requests down the established SSH connection to the user's local application.

Problems Solved

  1. Pain Point: The complexity and instability of exposing localhost for testing third-party integrations like payment webhooks (Stripe), OAuth providers (Google, GitHub), or CI/CD pipelines, which require a publicly accessible, HTTPS-enabled callback URL.
  2. Target Audience: Software Developers & DevOps Engineers testing webhooks and APIs; Frontend Developers sharing hot-reloading dev servers with clients or teams; QA Testers validating applications on real mobile devices over cellular networks; Indie Hackers & Startup Teams needing a simple, free tunnel for prototyping.
  3. Use Cases: Webhook Development: Receiving Stripe payment events or GitHub commit hooks directly on a local Node.js/Spring Boot server. Mobile Testing: Scanning a QR code from the terminal to open a local React Native build on an iOS/Android device. Client Demos: Sharing a live, interactive prototype of a Next.js or Vite application with a stakeholder without deployment.

Unique Advantages

  1. Strengths & Limitations (Pros & Cons):

    • Pros: Zero installation (uses system SSH); No account or sign-up required; Free stable URLs via SSH key; Fully open-source (MIT license) server for self-hosting; Built-in QR code and live request log in terminal; Native WebSocket support.
    • Cons: TLS is not end-to-end encrypted (terminates at tunnl.gg edge); Cannot choose custom subdomain names on the free tier; Tunnel stability depends on the SSH connection; Advanced features like raw TCP tunneling or reserved IPs are not available.
  2. Key Alternatives & Differentiation:

    • vs. ngrok: tunnl.gg differentiates by requiring no proprietary agent or account for core functionality (stable URLs are free), and its server is open-source. ngrok offers more features (TCP tunnels, custom domains on free tier, dashboard) but requires installing its binary and an account for most useful configurations.
    • vs. Cloudflare Tunnel (cloudflared): Cloudflare's solution is powerful for exposing services to its global network but requires installing the cloudflared daemon and is primarily designed for permanent infrastructure, not ephemeral development tunnels. tunnl.gg is simpler and faster for one-off sharing and testing.
    • vs. localhost.run: Both are SSH-based and require no install. tunnl.gg's key differentiator is its free, account-less stable URL feature tied to an SSH key, whereas localhost.run's persistent URLs are a paid feature.

Frequently Asked Questions (FAQ)

  1. Is tunnl.gg a secure alternative to ngrok for webhook testing? Yes, for HTTPS webhook testing, tunnl.gg provides a secure, free alternative. It uses standard SSH encryption for the control channel, serves traffic over HTTPS, and offers stable URLs without an account. However, for use cases requiring end-to-end TLS or TCP tunnels, ngrok's paid plans may be more suitable.
  2. How does tunnl.gg generate a stable URL without an account? tunnl.gg uses your public SSH key as a unique identifier. The server computes an HMAC-SHA256 hash of your public key combined with a private server secret to deterministically generate your stable subdomain. No key registration or account database is needed.
  3. Can I use tunnl.gg with a development server that has strict host header validation (like Vite or Next.js)? Yes, but you must configure your dev server. Either add the host=localhost parameter to your tunnel command (-R 80:localhost:3000,host=localhost) so your app receives "localhost" as the host header, or configure your framework's allowed hosts list to include *.tunnl.gg.
  4. What happens to my data and traffic when using tunnl.gg? According to its privacy policy, tunnl.gg does not store the content of your HTTP traffic (headers, bodies). It retains transient connection logs (source IPs, timestamps, bandwidth) for up to 30 days for abuse prevention and operational monitoring. Traffic is encrypted via TLS from the visitor to the tunnl.gg edge.
  5. Why would I upgrade to tunnl.gg Pro? The Pro plan is for professional use where reliability and branding are critical. It removes the 2-hour idle/24-hour maximum tunnel limits, eliminates the phishing warning page for visitors, and allows you to reserve and use custom subdomain names (e.g., myapp.tunnl.gg) instead of generated ones.

Submit to 240+ Directories with 1-Click

Maximize your product's SEO and drive massive traffic by automatically submitting it to over 240 curated startup directories using DirSubmit.

Related Products

Subscribe to Our Newsletter

Get weekly curated tool recommendations and stay updated with the latest product news