Stable & lightweight HTTP tunnel

Illuminate
localhost.

Expose a local development server through a public URL—free, registration-free, and ready from a browser tab or a simple native client.

The problem

What is an HTTP tunnel?

An HTTP tunnel connects a public internet address to a service running on your private computer.

PUBLIC VISITOR→WEBTNX RELAY⇄LOCAL AGENT→LOCALHOST

Why not expose a local IP directly?

01

No public IP

NAT and carrier-grade NAT often prevent inbound connections.

02

Router & firewall blocks

Inbound ports are closed by default.

03

Port forwarding limits

Manual port mapping is fragile and device-specific.

04

No HTTPS by default

A raw local service rarely includes trusted TLS.

05

Internet-wide scanning

Directly opened ports are quickly discovered.

06

Intranet exposure

A compromised service can expose nearby devices.

Under the glass

How WebTNX works

The relay is path-based and asynchronous.

STEP 01

Public request

A visitor requests your public tunnel path.

STEP 02

Memory queue

The relay queues the sealed request in memory.

STEP 03

Authenticated polling

The agent retrieves work using an ephemeral token.

STEP 04

Local call

The agent reconstructs the request on localhost.

STEP 05

Authenticated encryption

AES-256-GCM protects bodies over TLS.

STEP 06

Secure return

The complete response returns to the visitor.

Local setup

Three things to know

▶

Start your local app

Run the app first and note its port.

C

Enable CORS for Web Agent

Only the browser agent needs CORS.

∞

Keep the agent connected

Keep the agent running to forward traffic.

Choose the right route

WebTNX vs. traditional tunnels

FeatureWebTNX WebWebTNX NativeTraditional tunnel
InstallationNoneSingle EXE or PythonUsually required
AccountNot requiredNot requiredOften required
Browser CORSRequiredNot requiredNot required
Router changesNoneNoneNone
HTTPSAt relayAt relayUsually
Protocol scopeHTTP request/responseHTTP request/responseOften TCP/HTTP
Typical server footprintVery smallVery smallVaries
Privacy & boundaries

Transparent by design.

Requests and queues live in process memory.

  • AES-256-GCM authenticated payload encryption over TLS
  • Ephemeral agent tokens never appear in public URLs
  • The relay is trusted; this is not claimed as end-to-end encryption
  • Sensitive apps still need their own authentication