HTTP · WebSocket · raw TCP

Reach any service on any network. No open ports.

Run one agent per machine and manage every endpoint from your browser. Or expose something in a single command. Both ends dial out — nothing listens on the public internet.

Start free
Architecture

Both ends dial out.

There is no inbound port on your side and nothing to forward on your router. Your agent holds an outbound WebSocket to the relay; visitors arrive at the relay, get authenticated, and ride that same connection home.

Two front doors

Pick the one that matches the job.

Quick share

one-off

One tunnel, configured on the command line. Stops when you press Ctrl+C.

shell
$ hle expose --service http://localhost:8123 --label ha
✓ Live at https://ha-x7k.hle.world

Agent

persistent

Install once. Every endpoint after that is a form in the dashboard.

shell
$ curl -fsSL https://get.hle.world | sh -s -- --agent
✓ Enrolled · service installed · starts at boot
hle exposehle agent
Tunnels per processOneMany
Configured inThe command lineThe dashboard
Changing a tunnelRestart the commandTakes effect in seconds
CredentialAPI key hle_…Agent token hlea_…
Unlocks firepuncherYes
Service discoveryYes — Kubernetes & Docker
Who it's for

Homelabs, real infra, and works in progress.

Homelab

Home Assistant, Jellyfin, Plex, Grafana — reachable from your phone with SSO in front, WebSockets intact, no VPN client to install.

Self-hosted infra

Proxmox, Unraid, TrueNAS, a k8s cluster in the basement. One agent per box, endpoints declared centrally, plus SSH and Postgres over firepuncher.

Local development

Share the thing you're building, receive real webhooks against your laptop, hand a client a URL that works — without deploying anything.

See the full breakdown →

Two gigabytes free, every month.

No card, no trial clock. Install the agent, declare an endpoint, and see whether it fits.