Expose local services to the internet in seconds. Download the demo build, run one command, and share a public URL — no signup, no config.
Public beta · macOS, Linux & Windows · Open source
❯ gotunnel http 3000 --server gotunnel.bakaredev.site
❯
$ gotunnel deploy --mode [self-hosted|managed]
› resolving deployment target▊
// two modes. same binary protocol. same stream multiplexing. same TLS.
// choose based on ownership preference — not capability.
Run the same GoTunnel binary as your own server on any Linux VPS. You own the infrastructure, the certs, and the data — no database, Redis, or email required. Built for teams who can't send traffic through third-party servers.
❯gotunnel server --auth-tokens SECRET
GoTunnel Server v1.0.1
Tunnel port :9000
Auth 1 token
Ready for connections
# then, on your machine:
❯gotunnel --server your-vps:9000 --local localhost:3000 --token SECRET
Connect to GoTunnel's managed infrastructure in one command. No server to provision, no certs to manage. Get a live public URL in under five seconds — perfect for demos, webhooks, and rapid iteration.
❯gotunnel http 3000 --server gotunnel.bakaredev.site
Connected to managed server
Forwarding https://xyz.gotunnel.bakaredev.site → localhost:3000
Status connected ✓
Latency 12ms
Streams 4 active
Uptime 00:04:31
Both modes use the same binary protocol with stream multiplexing and TLS encryption end-to-end.
$ gotunnel inspect --capabilities
› loading feature manifest▊
// engineered from the protocol layer up — not bolted on after.
// custom binary protocol · stream multiplexing · TLS 1.3 · single binary.
Handle multiple concurrent connections over a single secure tunnel without overhead.
End-to-end encrypted tunnel traffic using TLS. Custom certs or auto-generated.
Gate tunnel access with secure token validation. Rate limiting and lockout built in.
Exponential backoff reconnect loop recovers from network drops without manual intervention.
Tunnel any TCP-based service — HTTP, HTTPS, SSH, Postgres, Redis, and beyond.
Track latency, active streams, bandwidth, and connection health via Prometheus export.
Run multiple tunnel clients simultaneously with independent stream pools and auth.
Ships as a single compiled Go binary. No runtime, no containers, no package manager.
$ gotunnel trace --session current
› resolving packet path▊
// traffic enters the public internet and exits at your localhost.
// encrypted end-to-end. no port forwarding. no firewall rules.
Run the GoTunnel client and point it at your local service port. One command — no config files, no firewall rules.
❯gotunnel http 3000 --server gotunnel.bakaredev.site
› resolving gotunnel.bakaredev.site
$ gotunnel query --use-cases
› scanning workflow registry▊
// from webhook testing to remote debugging — GoTunnel keeps your development moving.
// 6 registered workflows · all environments · zero config.
Receive third-party callbacks from payment gateways, CI pipelines, or any external API without deploying your app.
Share working applications with clients instantly using secure public links — no staging environment needed.
Connect iOS and Android apps to local APIs without cloud deployment or ngrok subscriptions.
Access services running behind firewalls securely from any remote location without VPN complexity.
Expose services running inside restricted, embedded, or air-gapped networks without opening firewall ports.
Safely share dashboards, admin panels, and development tools across distributed teams in real time.
$ gotunnel benchmark --output metrics
› running perf suite▊
// benchmarked on reference hardware under sustained load · single binary · no sidecar.
// optimized for speed, scalability, and reliable connections.
Minimal added latency across tunnel connections under sustained load.
High-speed data transfer across active tunnels.
Simultaneous connections per server instance.
Efficient resource usage per active session.
Automatic reconnection with exponential backoff — no manual restart.
$ gotunnel audit --security-model
› loading security manifest▊
// secure connections, controlled access, and reliable session protection.
// designed for production · no plaintext · no shared sessions.
All tunnel traffic is encrypted end-to-end using TLS 1.3. Custom certificates or auto-generated — zero plaintext in transit.
Clients authenticate using secure access tokens before a tunnel session is established. Invalid tokens are rejected at the handshake layer.
Each tunnel session runs in an isolated stream context. Traffic from one client cannot bleed into another session.
Persistent heartbeat checks detect dropped or stale connections. Dead sessions are terminated and cleaned up automatically.
Define authentication policies per tunnel — token-based, JWT, or API key. Unauthorized connections are dropped before proxying begins.
Configurable payload size limits and connection rate controls reduce exposure to abuse and bandwidth exhaustion attacks.
$ gotunnel http 3000▊
Download the build for macOS, Linux, or Windows, run one command, and get a public URL. Use the managed beta, or self-host the same binary on your own VPS — both are free.
public beta · what you download is a beta build · open source
❯gotunnel http 3000
Connected to managed server
Forwarding https://xyz.gotunnel.bakaredev.site → localhost:3000
Status connected ✓ latency: 11ms