HTTP · WS · TCP · UDP / streaming end-to-end / MCP-native / MIT / self-hostable

The tunnel built for developers and their AI agents.

Localhost to a public URL in one command. Your agent drives it over MCP. Local LLMs and MCP servers, shared behind keys.

Sign in to the console
Fig. 1 One tunnel, three stories: a webhook fails, the agent replays it, a local LLM streams tokens. Hex is the real frame header — version, type, flags, reserved, stream id.
  1. Stripe POST /webhooks/stripe
  2. OPEN #7 http POST
  3. RESPONSE #7 500
  4. 500 to Stripe
  5. Agent: explain_request → customer_email is null
  6. Agent fixes code, replay_request #7 200
  7. Scanner POST /api/pull 404 at edge
  8. POST /v1/chat/completions key sk-tnx-…
  9. OPEN #9 llm
  10. RESPONSE #9 200 SSE
  11. DATA #9 " time." ×8
  12. DATA #9 FIN

client ← #9 Tunnels carry tokens, one frame at a time.

  1. 01

    Agent-native

    An MCP server ships in the box. Claude Code, Cursor and other agents open tunnels, wait for webhooks, replay and mock on their own.

  2. 02

    Share AI safely

    tunnex llm publishes a local model with keys, an endpoint allowlist, streaming and per-key usage. tunnex mcp expose makes any stdio MCP server remote.

  3. 03

    Understand traffic

    The inspector explains failed requests with AI, infers OpenAPI from traffic, searches in plain English and mocks a backend that's down.

  4. 04

    Secure by default

    Accounts, owned subdomains, edge policies — basic auth, keys, IP, email SSO, paths — and an interstitial for anonymous tunnels.

Your agent can drive it.

Other tunnels are built for humans clicking in a web inspector. Tunnex gives agents tools — and sees tunnels you started yourself.

12 MCP tools

start_tunnel
expose a port
stop_tunnel
close it
list_tunnels
what's running
list_requests
captured traffic
get_request
full exchange
wait_for_request
block until it arrives
replay_request
resend, optionally edited
send_request
call through the tunnel
set_mock
fake a response
clear_mock
stop faking
explain_request
AI diagnosis
get_openapi
spec from traffic

The webhook loop

  1. > Fix the Stripe webhook.
  2. start_tunnel 3000 → myapp.tunnex.org
  3. wait_for_request → POST /webhooks/stripe 500
  4. explain_request → customer_email is null
  5. edits the handler
  6. replay_request → 200

No copy-pasted payloads. The real event, replayed until it passes.

Share local AI. Not your machine.

tunnex llm

A local model, published properly

Ollama, LM Studio, vLLM or llama.cpp, auto-detected, behind an OpenAI-compatible URL.

Raw model port versus tunnex llm
ConcernRaw porttunnex llm
AuthNone. Exposed Ollama is actively scanned for.API keys, checked at the edge
Admin API/api/pull, /api/delete open to anyoneInference paths only; the rest is 404
UsageUnknown, uncappedTokens per key and model; per-key limits
StreamingBreaks on buffering tunnelsToken by token, no time cap
from openai import OpenAI

client = OpenAI(
    base_url="https://myllm.tunnex.org/v1",
    api_key="sk-tnx-...",
)

tunnex mcp expose

A stdio MCP server, made remote

claude.ai and ChatGPT connectors need HTTPS and Streamable HTTP. Most MCP servers speak stdio. Tunnex bridges them.

$ tunnex mcp expose -- npx -y \
    @modelcontextprotocol/server-filesystem ~/docs

remote MCP URL
https://files.tunnex.org/mcp/<secret>
  • Paste the URL into a claude.ai or ChatGPT connector.
  • One subprocess per MCP session; idle ones are reaped.
  • Auth by secret URL, or an edge-enforced bearer key.
  • Every call shows in the inspector by tool name.

Traffic that explains itself.

Every request lands in the local inspector at 127.0.0.1:4040.

POST /webhooks/stripe 500

Summary
Stripe sent checkout.session.completed; the handler crashed reading the email.
Cause
customer_email is null for guest checkouts. The last 200 had it set.
Fix
Read customer_details.email; handle null.

Explain this request — illustrative

Explain this request
Cause and fix, compared with the last good call. One-click replay patch.
Plain-English search
“POSTs from Telegram with errors in the last 10 minutes.”
OpenAPI from traffic
Inferred offline from what went through. JSON or YAML.
Offline mock
Backend down? Recorded or schema-consistent responses, marked X-Tunnex-Mock.
Replay & edit
Resend any request, as is or modified.
Code export
curl, Python, JavaScript, pytest.

AI: Claude, or a local model via Ollama — then traffic never leaves your machine. Secrets are redacted before any prompt.

Secure by default.

Policies are CLI flags, enforced at the edge. Rejected traffic never reaches your laptop.

Edge access policy flags
FlagEffect
--basic-auth demo:secretBrowser password prompt.
--key autoGenerates an API key: Authorization: Bearer or X-Api-Key.
--allow-ip 203.0.113.0/24CIDR allowlist for HTTP, WS, TCP and UDP.
--allow-email @company.comEmail SSO with verified addresses. Account required.
--allow-path /apiEverything outside the prefix is 404.

Filters must all pass; credentials are alternatives — keys for machines and SSO for browsers on one URL.

Owned subdomains
tunnex login is a device flow, like gh auth login. Your name is yours; nobody can take over a live tunnel.
Anonymous interstitial
Browsers see a notice before an anonymous tunnel. API clients don't.
Identity headers
Your app gets X-Tunnex-Email. Incoming X-Tunnex-* headers are dropped.

Under the hood.

Every frame: an 8-byte header, then payload. Shown: DATA, FIN, stream 9.
Multiplexed binary frames
Many streams, one connection.
Per-stream flow control
Credit windows: one slow download can't stall the rest.
True streaming
SSE, LLM tokens, large downloads. Nothing buffered.
Disconnect propagation
Caller leaves, the local request is cancelled.
PostgreSQL
Accounts, domains, request metadata with retention.
Prometheus
Metrics, health endpoint, Grafana dashboard.
Self-hostable
Your server, your domain, Docker Compose.

Free either way.

No sign-up to start. Sign in for your own name, SSO and raw ports. No paid tier.

Anonymous versus free account
FeatureAnonymousAccount
PriceFreeFree
SubdomainRandom, sticky 24 hYour choice, reserved (3)
InterstitialYesNo
PoliciesAuth, keys, IP, paths+ email SSO
TCP / UDP—Yes, stable ports
Rate limit120 req/min1,200 req/min
Tunnels3 per IP10

Defaults on tunnex.org. Self-hosted instances set their own limits.

Two lines to a public URL.

Public URL https://myapp.tunnex.org Inspector http://127.0.0.1:4040

Recipes

Command recipes
GoalCommand
Sign in
Own name, password
Database
Game server
Local LLM
Agent tools

Click a command to copy it.

Tunnex vs alternatives.

Feature comparison of Tunnex, ngrok, Cloudflare Tunnel and localtunnel
Feature Tunnex ngrok Cloudflare Tunnel localtunnel
MCP server for agentsYes———
Local LLM with keys & usageYesPartialPartial—
stdio MCP → remote MCPYes———
AI request explanationYes———
OpenAPI from trafficYes———
Email SSO, free planYesPartialYes—
TCP & UDPYesTCPPartial—
Open source, self-hostableYes—PartialYes

— not built in, as far as we know. Partial: with limits, extra products or paid plans. Comparison reflects our understanding as of October 2026. Wrong? Tell us.

Give your agent a tunnel.

Sign in