Your Localhost.
Exposed Globally.
A pure-Rust tunneling client that gives any local service a public URL or port. HTTP, TCP, and UDP — with self-healing reconnection, daemon persistence, and zero maintenance.
A pure-Rust tunneling client that gives any local service a public URL or port. HTTP, TCP, and UDP — with self-healing reconnection, daemon persistence, and zero maintenance.
A single static binary. No runtimes, no dependencies, no config files to babysit.
$curl -fsSL https://router.direct/install.sh | shThen create a tunnel in the dashboard and run router install --server 77.42.121.237:2333 --token sk_live_… --subdomain myapp
No router config, no public IP, no moving parts you have to watch.
Pick a subdomain or reserve a TCP/UDP port in the dashboard and copy the generated API key.
One command connects your machine to the relay over TLS and authenticates with your key.
Traffic arriving at your public endpoint is piped straight to your local service. Nothing else to configure.
Pure Rust. Native OS integration. Designed to install once and never think about again.
Exponential backoff reconnection, a 40-second watchdog, and relay heartbeats. If the link drops, the client recovers on its own — no intervention, ever.
One command installs a native system service — systemd or OpenRC on Linux, launchd on macOS, a scheduled task on Windows. Survives reboots and logouts.
A single memory-safe static binary built on tokio, handling thousands of concurrent streams at wire speed. No runtime to install.
Subdomain-routed HTTPS for web apps, dedicated public ports for SSH, databases, and VNC, plus UDP tunnels for WireGuard and game servers.
TLS on every control and data channel, HTTPS at the edge, API tokens validated against Redis with instant revocation, and per-IP rate limiting on auth.
No per-tunnel fees. Generate as many API keys and subdomains as you need and run concurrent tunnels to different local ports.
Give teammates and clients a live URL to the site running on your machine.
Receive inbound webhooks from Stripe, GitHub, or Slack against your local dev server.
Expose a WireGuard endpoint or game server through a dedicated public UDP port.
Reach SSH, databases, or VNC on a machine behind NAT — from anywhere.
Nothing. Create as many tunnels, subdomains, and API keys as you need — there are no per-tunnel fees.
No. The client dials out from your machine to the relay, so it works behind any NAT, firewall, or CGNAT — no port forwarding, no dynamic DNS.
The control and data channels between your machine and the relay are TLS-encrypted, public HTTP traffic is served over HTTPS at the edge, and UDP payloads travel inside the TLS data channel. No traffic is inspected or stored.
With `router install` the tunnel runs as a native system service that starts on boot and restarts on failure. The client also reconnects on its own with exponential backoff, a 40-second watchdog, and relay heartbeats.
Yes. Create multiple tunnels in the dashboard and install each with its own `--service-name`, e.g. one for your web app and one for SSH.
HTTP/HTTPS via subdomains, raw TCP (SSH, databases, VNC, game servers), and UDP (WireGuard, DNS, game protocols).
Delete the tunnel in the dashboard (revokes the key instantly), run `router uninstall` to remove the local service, or press Ctrl+C if you're running in the foreground.