Uplink Get started
Open source · self-hosted

Bring your apps online

Fast, open source, and entirely under your control.

Uplink
3 tunnels · 2 serving
+ Add tunnel
admin-dashboard.ny.uplink.computerLive
localhost:3000Private
your-company.comLive
localhost:8080Public
How it works

Serve local apps without exposing your network.

A public edge server serves your domain and runs every firewall rule and auth check.
Your app stays on localhost, reached only through a tunnel it dials out to.

Internet
Edge
localhost
TLS Auth Firewall Encrypted tunnel

Zero-Trust Access Control

Choose who can reach each app: people, teams, passwords, API keys, or trusted networks. Everything else stops at the edge.

Invited accounts Sign in with a code sent to their email.
alex@example.com
Team access Share with your whole team in one click.
acme · 12 members
Password / API key Use a browser password or Authorization header.
•••••••• Replace
IP whitelist Only listed IPs and networks can connect.
203.0.113.0/24
Public access Open to anyone with the link

Web Application Firewall

Block exploit probes, abusive requests, and sensitive paths with reusable HTTP rules before requests reach your machine.

block-probes applies to: blog Block
where path contains /wp- · method is POST
block-secrets applies to: api Block
where path contains /.env
block-curl applies to: all tunnels Block
where header user-agent contains curl

Bot Protection

Challenge suspicious traffic at the edge to prevent programatic access. Set a challenge level per app, from invisible browser proof to a strict human check.

Managed Challenge Per-app challenge difficulty
JS proofCoherenceReaction

Four challenge levels are available per app: Off, Light adds an invisible browser proof, Standard adds browser-coherence checks, and Strict adds a human reaction test.

Signed clearance All regions · 30 minutes

Observability & Analytics

See bandwidth, service health, and blocked requests in one place. Know what is happening without assembling another stack.

last 24h 1.87m Requests
blocked 203.0.113.7 · POST /wp-login.php block-probes

Traffic Inspector

Inspect live request and response bodies without sending payloads to a third party. Captures stay on your machine.

POST /callbacks/billing 200 182 ms · local
Request body
{
  "event": "invoice.paid",
  "invoice": {…}
}

Custom Domains & Load Balancing

Attach your own domains to any tunnel and balance traffic across several connectors. DNS, certificates, and failover are handled at the edge.

vllm-15fg2.uplink.computer Distributing requests across 3 independent devices
Attached
  • RTX 5090 PC · New York :8080 34%
  • Mac Studio · Toronto :8080 33%
  • DGX Spark · London :8080 33%
Failover automatic Unhealthy connectors drop out

Seamless support for modern web protocols

Leave behind the hidden headaches of traditional reverse tunnel tools.

Automatic HTTPS

Issued and renewed automatically for every served app. Assigned URLs are yours forever.

WebSockets

WSS support by default, upgrade requests pass through without special proxy rules.

Server-Sent Events

Durable SSE, live updates and AI responses stay connected from first event to last.

Verified compatibility with popular apps

If it listens on a local HTTP port, it is ready for Uplink.

  • Nextcloud
  • Home Assistant
  • Jellyfin
  • Immich
  • Grafana
  • Gitea
  • n8n
  • WordPress
  • Plex
  • Portainer
  • Ollama
  • LM Studio
  • Jupyter
  • Gradio
  • Express
  • FastAPI
  • Next.js
  • Vite
  • Astro
  • vLLM

Pairs perfectly with Tailscale and Docker.

Uplink is the missing piece for the stack you've already built.
Your tailnet, compose files, and services stay exactly as they are.

Your laptop, phone, and home server are meshed together inside a private Tailscale network. Docker keeps running the apps on the server. The published app on port 8080 leaves through a single device-bound Uplink tunnel, encrypted with QUIC and TLS 1.3, serving app-41km3m.uplink.computer. The Uplink edge stands between it and the outside world as a security boundary: a friend invited by email and an IoT sensor holding an API key get in, while an unauthorized stranger and a bot are cut off at the edge. Postgres, Redis, and everything unpublished stay private.

Docker runs the apps Use containers to sandbox your services
Tailscale meshes your devices Private Wireguard network for internal access
Uplink publishes & protects The safest way to serve local ports
Pricing

Use our infrastructure or run your own.

Open source. MIT license. Host on your hardware or utilize our managed network.

Self-Hosted Edge Server

Free · Open source

Run your own edge on your own hardware.
Bring your own domain name, DNS configuration, and TLS certificates.

No built-in SSO authentication, bot protection, or advanced analytics.

Get started

Managed Edges

Preconfigured with seamless SSO authentication and Clickhouse-powered observability.

Free

$0 /mo
Kick the tires on a managed edge
  • Unlimited HTTPS encrypted apps
  • 1 GB bandwidth / month
  • Up to 10 Mbps transfer speeds
  • Reserved internal subdomains
Start free

Dev

$10 /mo
Gateway to your personal cloud
  • Everything in Free
  • 50 GB bandwidth / month
  • Up to 100 Mbps transfer speeds
  • Link 3 custom domain names
Start Developing

Pro

$50 /mo
Ship to production
  • Everything in Dev
  • 1 TB bandwidth / month
  • Up to 1 Gbps transfer speeds
  • Link 20 custom domain names
Go Pro

Add a Team

Bring people in on top of any paid plan. Invite teammates and share your tunnels with the whole team in one click. No extra cost.

  • Invite teammates & manage access
  • Roles & permissions
  • Audit logs & security events
  • Shared apps and settings
$0 / member

Seats are free. You only pay for the plan underneath.

Add your team

For teams and businesses.

Dedicated Edge Cluster

$250 /mo per node
Private high-performance networking stack
  • Dedicated compute and bandwidth for your team
  • Up to 10 Gbps transfer speeds
  • Uncapped bandwidth (5TB included, then $0.05/gb)
  • Link up to 10,000 custom domain names
  • Advanced analytics and security features.
  • Priority support & SLAs
Talk to us

Enterprise

Custom
Your infrastructure, infinite scale
  • Deploy a multi-site edge fleet
  • Use your own on-prem and/or cloud infrastructure
  • LDAP, SAML, and custom SSO providers
  • Priority support & dedicated onboarding
  • Custom DPA & data-residency controls
  • Compliance reporting & audit support
Contact sales
Next Gen Transport Layer

The OpenTunnels Protocol.

A modern open source transport protocol for secure, high-performance tunnels.

QUIC + TLS 1.3
Channel binding (RFC 9266)
Broad web compatibility
Enforced tenant isolation
No head-of-line blocking
Written in Rust

Your first app online in minutes.

Install Uplink, point it at a local HTTP port, and publish. That's it.

$ curl -fsSL https://uplink.computer/install.sh | sh
Linux x86_64 & arm64 · Apple Silicon macOS — desktop users: install from Settings