Automatic HTTPS
Issued and renewed automatically for every served app. Assigned URLs are yours forever.
Fast, open source, and entirely under your control.
3 tunnels · 2 serving
A public edge server serves your domain and runs
every firewall rule and auth check.
Your app stays on
localhost, reached only through a tunnel it dials
out to.
Choose who can reach each app: people, teams, passwords, API keys, or trusted networks. Everything else stops at the edge.
Block exploit probes, abusive requests, and sensitive paths with reusable HTTP rules before requests reach your machine.
Challenge suspicious traffic at the edge to prevent programatic access. Set a challenge level per app, from invisible browser proof to a strict human check.
Four challenge levels are available per app: Off, Light adds an invisible browser proof, Standard adds browser-coherence checks, and Strict adds a human reaction test.
See bandwidth, service health, and blocked requests in one place. Know what is happening without assembling another stack.
Inspect live request and response bodies without sending payloads to a third party. Captures stay on your machine.
Attach your own domains to any tunnel and balance traffic across several connectors. DNS, certificates, and failover are handled at the edge.
Leave behind the hidden headaches of traditional reverse tunnel tools.
Issued and renewed automatically for every served app. Assigned URLs are yours forever.
WSS support by default, upgrade requests pass through without special proxy rules.
Durable SSE, live updates and AI responses stay connected from first event to last.
If it listens on a local HTTP port, it is ready for Uplink.
Uplink is the missing piece for the stack you've already built.
Your tailnet, compose files, and services stay exactly as they are.
Your laptop, phone, and home server are meshed together inside a private Tailscale network. Docker keeps running the apps on the server. The published app on port 8080 leaves through a single device-bound Uplink tunnel, encrypted with QUIC and TLS 1.3, serving app-41km3m.uplink.computer. The Uplink edge stands between it and the outside world as a security boundary: a friend invited by email and an IoT sensor holding an API key get in, while an unauthorized stranger and a bot are cut off at the edge. Postgres, Redis, and everything unpublished stay private.
Open source. MIT license. Host on your hardware or utilize our managed network.
Run your own edge on your own hardware.
Bring your own domain name, DNS configuration, and TLS certificates.
No built-in SSO authentication, bot protection, or advanced analytics.
Preconfigured with seamless SSO authentication and Clickhouse-powered observability.
Bring people in on top of any paid plan. Invite teammates and share your tunnels with the whole team in one click. No extra cost.
Seats are free. You only pay for the plan underneath.
For teams and businesses.
A modern open source transport protocol for secure, high-performance tunnels.
Install Uplink, point it at a local HTTP port, and publish. That's it.