Secure tunnels for local development
Your local service, on a public URL.
One command gives localhost a real HTTPS address — automatic Let's Encrypt certificates, a per-tunnel subdomain, and a request inspector with replay.
$ curl -fsSL https://ntunn-releases-006064026372.s3.us-east-1.amazonaws.com/install.sh | bash$ ntun config add-authtoken <your-key> $ ntun http 3000 → https://your-app.tunnel.makewithpaul.com
Quickstart
Running in three commands
A single binary. No sudo, no runtime dependencies. Auth is an API key from your dashboard.
Install the CLI
$ curl -fsSL https://ntunn-releases-006064026372.s3.us-east-1.amazonaws.com/install.sh | bashAdd your API key
Create a key under API Keys in the dashboard, then:
$ ntun config add-authtoken <your-key>
Expose a port
HTTP on Pro and above gets named subdomains; raw TCP (databases and the like) is a Max feature.
$ ntun http 3000 → https://your-app.tunnel.makewithpaul.com $ ntun tcp 5432 → tcp://tunnel.makewithpaul.com:10432 # Max plan
What you get
Everything a tunnel needs, nothing it doesn't
Each feature is tagged with the plan it ships on — no fine print.
Automatic HTTPS
All plansReal Let's Encrypt certificates, issued and renewed for every tunnel. No cert tooling on your side.
Per-tunnel subdomains
All plansEvery tunnel gets its own tunnel.makewithpaul.com subdomain. Named subdomains instead of random ones on Pro.
Request inspection
All plansEvery captured request — headers, body snippet, status, timing — in the dashboard inspector.
Request replay
ProReplay any captured request back to your local service with one click while you debug.
TCP tunnels
MaxExpose raw TCP — databases, SSH, game servers — with ntun tcp 5432.
Access controls
MaxRestrict tunnels by IP allowlist (CIDRs) or gate them with HTTP basic auth.
Plans
Start free, upgrade when you outgrow it
Basic is free forever. Paid plans are monthly, cancel any time.
- TCP tunnels
- IP allowlists
- HTTP basic auth on tunnels
- Everything in Pro
Roadmap
Not shipped yet
Being built, in no guaranteed order. If one of these blocks you, the health page is the honest source of what exists today.
- OIDC tunnel protection
- Webhook verification
- Traffic policies
- Kubernetes operator
- Reserved domains