Outbound only
The CLI opens one outbound, authenticated TLS connection. Nothing listens on your machine, so nothing on your machine has to explain itself to security.
One command opens a very polite, very outbound-only connection from behind your NAT to a stable HTTPS name. No inbound ports. No ticket to IT. No credit card either.
127ohoh1 expose http://127.0.0.1:3000
No signup to try it. No calendar invite to talk pricing.
No agents to install on your router. No inbound firewall rule to justify in the next audit. Just one outbound connection, doing its one job well.
The CLI opens one outbound, authenticated TLS connection. Nothing listens on your machine, so nothing on your machine has to explain itself to security.
Endpoints belong to an Ed25519 key you hold — not a username, not a password you'll forget by Tuesday. An account is optional, and only manages paid names and notifications.
Reserved names are paid over HTTP 402 with USDC. No credit card, no subscription you forgot to cancel, no small talk with a sales rep.
Request bodies passing through your tunnel are never stored, and URLs and query strings are never logged. What it carries is between you and whoever you handed the link to.
One line picks the right build for your machine and checks it against our signed release:
curl -fsSL https://127ohoh1.com/install.sh | sh
Linux and macOS. Windows, or rather read it first? See the docs.
Run one command. That's the entire setup ceremony.
Share it, embed it, forget your router exists.
$ 127ohoh1 expose http://127.0.0.1:3000
✓ tunnel established
→ https://sturdy-otter-4821.127ohoh1.com (example name)
One command. No inbound rule. No drama.