Overview

Router.direct is a secure tunneling service that exposes your localhost to the internet. Install a small pure-Rust CLI, point it at a local port, and get a public URL or port on the Router.direct relay — with no router configuration, no port forwarding, and no public IP required.

How it works

  1. You create a tunnel in the dashboard. The web app stores it in PostgreSQL, generates an API key ( sk_live_…), and mirrors the key into Redis so the relay can validate it instantly.
  2. The CLI dials the relay over a TLS-encrypted control connection to 77.42.121.237:2333 and authenticates with your API key.
  3. Traffic flows: for each incoming public connection the relay tells the CLI to open a second TLS data channel, then pipes bytes in both directions to your local service.
router.direct — traffic flow
You (public visitor)                     Your machine (behind NAT)
        │                                          │
        │  https://myapp.router.direct             │
        ▼                                          │
 ┌─────────────┐      ┌──────────┐     ┌──────────────────────┐
 │   Nginx     │─────▶│  Relay   │────▶│  router CLI (TLS)    │──▶ 127.0.0.1:3000
 │ edge :443   │ 8080 │  :2333   │ ctrl│  control + data ch.  │
 └─────────────┘      └──────────┘     └──────────────────────┘

Tunnel types

HTTP

A public https://yourname.router.direct URL routed by the Host header to a local web server.

TCP

A dedicated public port on the relay (10000–20000 range) for SSH, databases, VNC, or any raw TCP service.

UDP

A dedicated public UDP port for WireGuard, game servers, DNS, or any datagram service.

What makes it different

  • Daemon persistence — router install registers a native service (systemd, OpenRC, launchd, or a Windows scheduled task) so your tunnel survives reboots and logouts.
  • Self-healing reconnection — dropped connections are retried with exponential backoff (capped at 60s), with a 40-second watchdog and 30-second heartbeats to detect dead links fast.
  • Zero maintenance — the CLI checks for updates on startup and can self-update with router update.
  • Instant revocation — deleting a tunnel removes its key from Redis immediately; the relay rejects it on the next connection attempt.
  • Pure Rust — a single static binary per platform, memory-safe, no runtime dependencies.

Where to go next

NoteQuestions or issues? The quickest path is the quickstart, which covers the most common mistakes (missing --server, wrong --local format, subdomains that are already taken).