Uplink Get started
Article 001 The internet should feel closer to home.

Bring your apps online

Fast, open source, and entirely under your control.

Uplink
3 tunnels · 2 serving
+ Add tunnel
admin-dashboard.ny.uplink.computerLive
localhost:3000Private
your-company.comLive
localhost:8080Public
How it works

Serve local apps without exposing your network.

A public edge server serves your domain and runs every firewall rule and auth check.
Your app stays on localhost, reached only through a tunnel it dials out to.

Internet
Edge
localhost
TLS Auth Firewall Encrypted tunnel

Zero-Trust Access Control

Choose who can reach each app: people, teams, passwords, API keys, or trusted networks. Everything else stops at the edge.

Invited accounts Sign in with a code sent to their email.
alex@example.com
Team access Share with your whole team in one click.
acme · 12 members
Password / API key Use a browser password or Authorization header.
•••••••• Replace
IP whitelist Only listed IPs and networks can connect.
203.0.113.0/24
Public access Open to anyone with the link

Web Application Firewall

Block exploit probes, abusive requests, and sensitive paths with reusable HTTP rules before requests reach your machine.

block-probes applies to: blog Block
where path contains /wp- · method is POST
block-secrets applies to: api Block
where path contains /.env
block-curl applies to: all tunnels Block
where header user-agent contains curl

Bot Protection

Challenge suspicious traffic at the edge to prevent programatic access. Set a challenge level per app, from invisible browser proof to a strict human check.

Managed Challenge Per-app challenge difficulty
JS proofCoherenceReaction

Four challenge levels are available per app: Off, Light adds an invisible browser proof, Standard adds browser-coherence checks, and Strict adds a human reaction test.

Signed clearance All regions · 30 minutes

Observability & Analytics

See bandwidth, service health, and blocked requests in one place. Know what is happening without assembling another stack.

last 24h 1.87m Requests
blocked 203.0.113.7 · POST /wp-login.php block-probes

Traffic Inspector

Inspect live request and response bodies without sending payloads to a third party. Captures stay on your machine.

POST /callbacks/billing 200 182 ms · local
Request body
{
  "event": "invoice.paid",
  "invoice": {…}
}

Custom Domains & Load Balancing

Attach your own domains to any tunnel and balance traffic across several connectors. DNS, certificates, and failover are handled at the edge.

vllm-15fg2.uplink.computer Distributing requests across 3 independent devices
Attached
  • RTX 5090 PC · New York :8080 34%
  • Mac Studio · Toronto :8080 33%
  • DGX Spark · London :8080 33%
Failover automatic Unhealthy connectors drop out

Seamless support for modern web protocols

Leave behind the hidden headaches of traditional reverse tunnel tools.

Automatic HTTPS

Issued and renewed automatically for every served app. Assigned URLs are yours forever.

WebSockets

WSS support by default, upgrade requests pass through without special proxy rules.

Server-Sent Events

Durable SSE, live updates and AI responses stay connected from first event to last.

Verified compatibility with popular apps

If it listens on a local HTTP port, it is ready for Uplink.

  • ComfyUI
  • Ollama
  • LM Studio
  • OpenCode
  • Pi
  • Jupyter
  • Gradio
  • Express
  • FastAPI
  • Next.js
  • Vite
  • Astro
  • vLLM
  • Nextcloud
  • Home Assistant
  • Jellyfin
  • Immich
  • Grafana
  • Gitea
  • n8n
  • WordPress
  • Plex
  • Portainer

Pairs perfectly with Tailscale and Docker.

Uplink is the missing piece for the stack you've already built.
Your tailnet, compose files, and services stay exactly as they are.

Your laptop, phone, and home server are meshed together inside a private Tailscale network. Docker keeps running the apps on the server. The published app on port 8080 leaves through a single device-bound Uplink tunnel, encrypted with QUIC and TLS 1.3, serving app-41km3m.uplink.computer. The Uplink edge stands between it and the outside world as a security boundary: a friend invited by email and an IoT sensor holding an API key get in, while an unauthorized stranger and a bot are cut off at the edge. Postgres, Redis, and everything unpublished stay private.

Docker runs the apps Use containers to sandbox your services
Tailscale meshes your devices Private Wireguard network for internal access
Uplink publishes & protects The safest way to serve local ports
Self-hosted AI

Your models, on your own hardware.

The best open-weight models now run on hardware you already own.
Uplink gives that machine a public URL, a guard at the door, and a stream that holds.

An inference runtime — Ollama, LM Studio, llama.cpp, vLLM, ComfyUI or Gradio — runs on your own GPU. Uplink carries it out to an edge that requires sign-in, checks for bots and rate limits callers, and holds the server-sent-event stream open so an answer arrives token by token without dropping.

Durable SSE Long answers arrive intact, no idle timeout mid-token
Guarded at the edge Every request is checked before it reaches your GPU
Weights stay home No third-party inference, no per-token bill
Pricing

Use our infrastructure or run your own.

Open source. MIT license. Host on your hardware or utilize our managed network.

Self-Hosted Edge Server

Free · Open source

Run your own edge on your own hardware.
Bring your own domain name, DNS configuration, and TLS certificates.

No built-in SSO authentication, bot protection, or advanced analytics.

Get started

Managed Edges

Preconfigured with seamless SSO authentication and Clickhouse-powered observability.

Free

$0 /mo
Kick the tires on a managed edge
  • Unlimited HTTPS encrypted apps
  • 1 GB bandwidth / month
  • Up to 10 Mbps transfer speeds
  • Reserved internal subdomains
Start free

Dev

$10 /mo
Gateway to your personal cloud
  • Everything in Free
  • 50 GB bandwidth / month
  • Up to 100 Mbps transfer speeds
  • Link 3 custom domain names
Start Developing

Pro

$50 /mo
Ship to production
  • Everything in Dev
  • 1 TB bandwidth / month
  • Up to 1 Gbps transfer speeds
  • Link 20 custom domain names
Go Pro

Add a Team

Bring people in on top of any paid plan. Invite teammates and share your tunnels with the whole team in one click. No extra cost.

  • Invite teammates & manage access
  • Roles & permissions
  • Audit logs & security events
  • Shared apps and settings
$0 / member

Seats are free. You only pay for the plan underneath.

Add your team

For teams and businesses.

Dedicated Edge Cluster

$250 /mo per node
Private high-performance networking stack
  • Dedicated compute and bandwidth for your team
  • Up to 10 Gbps transfer speeds
  • Uncapped bandwidth (5TB included, then $0.05/gb)
  • Link up to 10,000 custom domain names
  • Advanced analytics and security features.
  • Priority support & SLAs
Talk to us

Enterprise

Custom
Your infrastructure, infinite scale
  • Deploy a multi-site edge fleet
  • Use your own on-prem and/or cloud infrastructure
  • LDAP, SAML, and custom SSO providers
  • Priority support & dedicated onboarding
  • Custom DPA & data-residency controls
  • Compliance reporting & audit support
Contact sales
Next Gen Transport Layer

The OpenTunnels Protocol.

A modern open source transport protocol for secure, high-performance tunnels.

QUIC + TLS 1.3
Channel binding (RFC 9266)
Broad web compatibility
Enforced tenant isolation
No head-of-line blocking
Written in Rust
Why Uplink

The tunnel we always wanted, open source and self-hostable.

Uplink combines the generous free tier, production controls, team pricing, and ownership the other options split across limits, add-ons, and closed edges.

Swipe to compare →

Comparison of Uplink, ngrok, Cloudflare Tunnel, and Tailscale Funnel
Compare
Uplink
$0 Free
ngrok
$0 Free
Cloudflare
$0 Free
Tailscale
$0 Personal
Limits & pricing
Published apps / endpoints
Unlimited
Free plan
3
Free plan
1,000
Routes per account
Not published
Funnel
Monthly HTTP requests
Uncapped
Free plan
20,000
Free plan
Uncapped
No request quota
Uncapped
No request quota
Team / access users
$0 / member
All included on paid plans
1 free
PAYG: 3, then +$5/user
50 free
Access: then $7/user
6 free
Standard: $8/user
Firewall rules
Included
No action metering
5 rules Free
Some actions metered
5 · 1 · 10 Free
WAF · rate limit · redirects
None
No HTTP rule engine
Analytics & inspection
HTTP traffic analytics
Requests, bandwidth, blocks
Rates + response times
Requests + bandwidth
× No Funnel HTTP analytics
Live request inspector
Local-only inspector
Local or cloud inspector
× Connector logs only
× No request inspector
Request + response bodies
Never leaves your device
Cloud mode retains 24h
× No payload viewer
× Traffic stays opaque
Publishing
Custom domains
From any DNS service
PAYG only
Requires Cloudflare DNS
× Only *.ts.net
Load-balanced domains
Built in
Metered pooling
Paid add-on
× Not available
Access control
Shared-password gate
Built in
Basic Auth policy
× No simple password gate
× Funnel is public
Invite any email
Native email invite
× Requires OAuth / OIDC
Access email PIN
× Funnel has no login
Account-based login
Accounts + teams
OAuth / OIDC
Access identity providers
× Funnel has no login
API key / service token
Built in
JWT / Traffic Policy
Access service token
× No Funnel auth
Firewall
Request matching rules
Path, method, header, IP
Traffic Policy
5 custom rules Free
× No HTTP rule engine
Block rules
Block or monitor
Deny action
Custom Rules
× No HTTP rule engine
Rate-limit rules
Per IP or route
Metered action
1 rule on Free
× No HTTP rule engine
Redirect rules
301 / 302
Metered action
10 rules on Free
× No HTTP rule engine
Bot protection
Basic bot / crawler filtering
Built in
User-agent policy
Bot Fight Mode
× Not built in
Managed browser challenge
Invisible + human checks
× No managed challenge
Managed Challenge
× Not available
Tools & ownership
Desktop publishing UI
Native macOS app
× No native publisher
× No native publisher
× Funnel uses CLI
Command-line interface
uplink CLI
ngrok agent
cloudflared
tailscale funnel
Self-host the public edge
MIT licensed
× Managed edge only
× Cloudflare edge only
× No self-hosted Funnel

Your first app online in minutes.

Install Uplink, point it at a local HTTP port, and publish. That's it.

$ curl -fsSL https://uplink.computer/install.sh | sh
Linux x86_64 & arm64 · Apple Silicon macOS — desktop users: install from Settings