Ship a marketing site, docs, or a full app framework straight from your machine.
Bring your apps online
Fast, open source, and entirely under your control.
3 tunnels · 2 serving
Serve local apps
without exposing your network.
A public edge server serves your domain and runs
every firewall rule and auth check.
Your app stays on
localhost, reached only through a tunnel it dials
out to.
An alternative to datacenter deployment
with the privacy and low cost of self hosting.
Leave behind monthly cloud server costs and use your own hardware.
Serve any local port as a URL, no local NAT or router configuration required.
Expose a JSON backend to webhooks, mobile clients, or an API-keyed integration.
Share an internal tool or metrics view — gated behind sign-in, never left wide open.
Open-weight models run on computers you already own. Uplink gives that machine a public URL, a guard at the door, and a stream that holds — no third-party inference, no per-token bill.
An inference runtime — Ollama, LM Studio, llama.cpp, vLLM, ComfyUI or Gradio — runs on your own GPU. Uplink carries it out to an edge that requires sign-in, checks for bots and rate limits callers, and holds the server-sent-event stream open so an answer arrives token by token without dropping.
Zero-Trust Access Control
Choose who can reach each app: people, teams, passwords, API keys, or trusted networks. Everything else stops at the edge.
Web Application Firewall
Block exploit probes, abusive requests, and sensitive paths with reusable HTTP rules before requests reach your machine.
Bot Protection
Challenge suspicious traffic at the edge to prevent programatic access. Set a challenge level per app, from invisible browser proof to a strict human check.
Four challenge levels are available per app: Off, Light adds an invisible browser proof, Standard adds browser-coherence checks, and Strict adds a human reaction test.
Custom Domains & Load Balancing
Attach your own domains to any tunnel and balance traffic across several connectors. DNS, certificates, and failover are handled at the edge.
- RTX 5090 PC · New York :8080 34%
- Mac Studio · Toronto :8080 33%
- DGX Spark · London :8080 33%
Traffic Inspector
Inspect live request and response bodies without sending payloads to a third party. Captures stay on your machine.
Observability & Analytics
See bandwidth, service health, and blocked requests in one place. Know what is happening without assembling another stack.
Pairs perfectly
with Tailscale and Docker.
Uplink is the missing piece for the stack you've already built.
Your tailnet, compose files, and services stay exactly as they are.
Your laptop, phone, and home server are meshed together inside a private Tailscale network. Docker keeps running the apps on the server. The published app on port 8080 leaves through a single device-bound Uplink tunnel, encrypted with QUIC and TLS 1.3, serving app-41km3m.uplink.computer. The Uplink edge stands between it and the outside world as a security boundary: a friend invited by email and an IoT sensor holding an API key get in, while an unauthorized stranger and a bot are cut off at the edge. Postgres, Redis, and everything unpublished stay private.
Seamless support
for modern web protocols
Leave behind the hidden headaches of traditional reverse tunnel tools.
Automatic TLS 1.3
HTTPS certificates issued and renewed automatically. Assigned URLs are yours forever.
HTTP/2 and HTTP/3
Faster page loads for every visitor, and steady speed on patchy mobile connections.
WebSockets
WSS support by default, upgrade requests pass through without special proxy rules.
Server-Sent Events
Durable SSE, live updates and AI responses stay connected from first event to last.
Verified compatibility with popular apps
If it listens on a local HTTP port, it is ready for Uplink.
-
ComfyUI
-
Ollama
-
LM Studio
-
OpenCode
-
Pi
-
Jupyter
-
Gradio
-
Express
-
FastAPI
-
Next.js
-
Vite
-
Astro
-
vLLM
-
Nextcloud
-
Home Assistant
-
Jellyfin
-
Immich
-
Grafana
-
Gitea
-
n8n
-
WordPress
-
Plex
-
Portainer
Your app gets a URL.
Your machine doesn't.
The URL points at an edge server, not at the machine running your app.
- Your app
- SSH
- Database
- Your LAN
The address is your machine. Your firewall is the only thing between the internet and everything else on it.
- TLS
- Auth
- Firewall
- DDoS
- Your app
The address is the edge. From there, the only path is the tunnel your machine opened — and only your app is on it.
The OpenTunnels Protocol.
A modern open source transport protocol for secure, high-performance tunnels.
Use our infrastructure
or run your own.
Open source. MIT license. Host on your hardware or utilize our managed network.
Self-Hosted Edge Server
Free · Open source
Run your own edge on your own hardware.
Bring your own domain name, DNS configuration, and TLS certificates.
No built-in SSO authentication, bot protection, or advanced analytics.
Managed Edges
Preconfigured with seamless SSO authentication and Clickhouse-powered observability.
Free
- Unlimited HTTPS encrypted apps
- 1 GB bandwidth / month
- Up to 10 Mbps transfer speeds
- Reserved internal subdomains
Dev
- Everything in Free
- 50 GB bandwidth / month
- Up to 100 Mbps transfer speeds
- Link 3 custom domain names
Pro
- Everything in Dev
- 1 TB bandwidth / month
- Up to 1 Gbps transfer speeds
- Link 20 custom domain names
Add a Team
Bring people in on top of any paid plan. Invite teammates and share your tunnels with the whole team in one click. No extra cost.
- Invite teammates & manage access
- Roles & permissions
- Audit logs & security events
- Shared apps and settings
Seats are free. You only pay for the plan underneath.
For teams and businesses.
Dedicated Edge Cluster
- Dedicated compute and bandwidth for your team
- Up to 10 Gbps transfer speeds
- Uncapped bandwidth (5TB included, then $0.05/gb)
- Link up to 10,000 custom domain names
- Advanced analytics and security features.
- Priority support & SLAs
Enterprise
- Deploy a multi-site edge fleet
- Use your own on-prem and/or cloud infrastructure
- LDAP, SAML, and custom SSO providers
- Priority support & dedicated onboarding
- Custom DPA & data-residency controls
- Compliance reporting & audit support
Full featured and reliable,
open source and self-hostable.
Uplink combines the generous free tier, production controls, team pricing, and ownership the other options split across limits, add-ons, and closed edges.
Swipe to compare →
| Compare | Uplink | ngrok | Cloudflare Tunnels | Tailscale Funnel |
|---|---|---|---|---|
| Limits & pricing | ||||
| Published apps / endpoints | Unlimited Free plan | 3 Free plan | 1,000 Routes per account | Not published Funnel |
| Monthly HTTP requests | Uncapped Free plan | 20,000 Free plan | Uncapped No request quota | Uncapped No request quota |
| Team / access users | $0 / member All included on paid plans | 1 free PAYG: 3, then +$5/user | 50 free Access: then $7/user | 6 free Standard: $8/user |
| Firewall rules | Included No action metering | 5 rules Free Some actions metered | 5 · 1 · 10 Free WAF · rate limit · redirects | None No HTTP rule engine |
| Analytics & inspection | ||||
| HTTP traffic analytics | ✓ Requests, bandwidth, blocks | ✓ Rates + response times | ✓ Requests + bandwidth | × No Funnel HTTP analytics |
| Live request inspector | ✓ Local-only inspector | ✓ Local or cloud inspector | × Connector logs only | × No request inspector |
| Request + response bodies | ✓ Never leaves your device | ✓ Cloud mode retains 24h | × No payload viewer | × Traffic stays opaque |
| Publishing | ||||
| Custom domains | ✓ From any DNS service | ✓ PAYG only | ✓ Requires Cloudflare DNS | × Only *.ts.net |
| Load-balanced domains | ✓ Built in | ✓ Metered pooling | ✓ Paid add-on | × Not available |
| Access control | ||||
| Shared-password gate | ✓ Built in | ✓ Basic Auth policy | × No simple password gate | × Funnel is public |
| Invite any email | ✓ Native email invite | × Requires OAuth / OIDC | ✓ Access email PIN | × Funnel has no login |
| Account-based login | ✓ Accounts + teams | ✓ OAuth / OIDC | ✓ Access identity providers | × Funnel has no login |
| API key / service token | ✓ Built in | ✓ JWT / Traffic Policy | ✓ Access service token | × No Funnel auth |
| Firewall | ||||
| Request matching rules | ✓ Path, method, header, IP | ✓ Traffic Policy | ✓ 5 custom rules Free | × No HTTP rule engine |
| Block rules | ✓ Block or monitor | ✓ Deny action | ✓ Custom Rules | × No HTTP rule engine |
| Rate-limit rules | ✓ Per IP or route | ✓ Metered action | ✓ 1 rule on Free | × No HTTP rule engine |
| Redirect rules | ✓ Uncapped | ✓ Metered action | ✓ 10 rules on Free | × No HTTP rule engine |
| Bot protection | ||||
| Basic bot / crawler filtering | ✓ Built in | ✓ User-agent policy | ✓ Bot Fight Mode | × Not built in |
| Managed browser challenge | ✓ Invisible + human checks | × No managed challenge | ✓ Managed Challenge | × Not available |
| Tools & ownership | ||||
| Desktop publishing UI | ✓ Native macOS app | × No native publisher | × No native publisher | × Funnel uses CLI |
| Command-line interface | ✓ uplink CLI | ✓ ngrok agent | ✓ cloudflared | ✓ tailscale funnel |
| Self-host the public edge | ✓ MIT licensed | × Managed edge only | × Cloudflare edge only | × No self-hosted Funnel |
Your first app online in minutes.
Install Uplink, point it at a local HTTP port, and publish. That's it.