Secure tunnels for local development

Your local service, on a public URL.

One command gives localhost a real HTTPS address — automatic Let's Encrypt certificates, a per-tunnel subdomain, and a request inspector with replay.

$ curl -fsSL https://ntunn-releases-006064026372.s3.us-east-1.amazonaws.com/install.sh | bash
$ ntun config add-authtoken <your-key>
$ ntun http 3000

→ https://your-app.tunnel.makewithpaul.com

Quickstart

Running in three commands

A single binary. No sudo, no runtime dependencies. Auth is an API key from your dashboard.

1

Install the CLI

$ curl -fsSL https://ntunn-releases-006064026372.s3.us-east-1.amazonaws.com/install.sh | bash
2

Add your API key

Create a key under API Keys in the dashboard, then:

$ ntun config add-authtoken <your-key>
3

Expose a port

HTTP on Pro and above gets named subdomains; raw TCP (databases and the like) is a Max feature.

$ ntun http 3000
→ https://your-app.tunnel.makewithpaul.com

$ ntun tcp 5432
→ tcp://tunnel.makewithpaul.com:10432 # Max plan

What you get

Everything a tunnel needs, nothing it doesn't

Each feature is tagged with the plan it ships on — no fine print.

Automatic HTTPS

All plans

Real Let's Encrypt certificates, issued and renewed for every tunnel. No cert tooling on your side.

Per-tunnel subdomains

All plans

Every tunnel gets its own tunnel.makewithpaul.com subdomain. Named subdomains instead of random ones on Pro.

Request inspection

All plans

Every captured request — headers, body snippet, status, timing — in the dashboard inspector.

Request replay

Pro

Replay any captured request back to your local service with one click while you debug.

TCP tunnels

Max

Expose raw TCP — databases, SSH, game servers — with ntun tcp 5432.

Access controls

Max

Restrict tunnels by IP allowlist (CIDRs) or gate them with HTTP basic auth.

Plans

Start free, upgrade when you outgrow it

Basic is free forever. Paid plans are monthly, cancel any time.

Basic
$0
1 endpoint
  • Random subdomain
  • Automatic HTTPS
  • Request inspection dashboard
Start with Basic
Pro
$20/mo
10 endpoints
  • Named subdomains
  • Request inspection + replay
  • Everything in Basic
Start with Pro
Max
$50/mo
Unlimited endpoints
  • TCP tunnels
  • IP allowlists
  • HTTP basic auth on tunnels
  • Everything in Pro
Start with Max

Roadmap

Not shipped yet

Being built, in no guaranteed order. If one of these blocks you, the health page is the honest source of what exists today.

  • OIDC tunnel protection
  • Webhook verification
  • Traffic policies
  • Kubernetes operator
  • Reserved domains

Run one command. Get a public URL.