惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

MyScale Blog
MyScale Blog
量子位
宝玉的分享
宝玉的分享
爱范儿
爱范儿
云风的 BLOG
云风的 BLOG
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Recent Announcements
Recent Announcements
Apple Machine Learning Research
Apple Machine Learning Research
N
News and Events Feed by Topic
TaoSecurity Blog
TaoSecurity Blog
博客园 - 三生石上(FineUI控件)
小众软件
小众软件
Simon Willison's Weblog
Simon Willison's Weblog
Google DeepMind News
Google DeepMind News
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
aimingoo的专栏
aimingoo的专栏
Cloudbric
Cloudbric
Blog — PlanetScale
Blog — PlanetScale
Latest news
Latest news
S
Security @ Cisco Blogs
Last Week in AI
Last Week in AI
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Vercel News
Vercel News
W
WeLiveSecurity
M
MIT News - Artificial intelligence
P
Proofpoint News Feed
P
Proofpoint News Feed
P
Palo Alto Networks Blog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
T
The Blog of Author Tim Ferriss
腾讯CDC
大猫的无限游戏
大猫的无限游戏
Martin Fowler
Martin Fowler
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
V2EX
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Stack Overflow Blog
Stack Overflow Blog
IT之家
IT之家
有赞技术团队
有赞技术团队
Microsoft Security Blog
Microsoft Security Blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
美团技术团队
博客园 - 【当耐特】
D
DataBreaches.Net
I
InfoQ
G
GRAHAM CLULEY
S
SegmentFault 最新的问题
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
B
Blog

Show HN

GitHub - flightdeckhq/flightdeck: Observability and control plane for AI agents. CSP Radar GitHub - Light-Heart-Labs/DreamServer: Turn your PC, Mac, or Linux box into an AI server. LLM inference, chat UI, voice, agents, workflows, RAG, and image generation. GitHub - Diplomat-ai/diplomat-agent-ts: What can your TypeScript AI agent do to the real world? Scan your code. See which tool calls have zero checks Code Block Selector - Visual Studio Marketplace Prometheus dependency graph — interactive showcase | Riftmap Show HN: I made a vi-like modal keyboard plugin for Figma GitHub - run-llama/liteparse: A fast, helpful, and open-source document parser GitHub - dalemyers/Roar: A macOS CLI tool for notifications GitHub - district-solutions/open-agent-tools-coder: Enables small-to-large self-hosted ai models to use local source code when running tool-calling agentic workloads. We actively data mine 20,900+ (2+ TB) popular github repos using large and small ai models to create reuseable: json, markdown and parquet files for local-first tool-calling models. GitHub - progapandist/stripeek: A local TUI proxy for real-time Stripe API debugging, built for navigating complex payloads fast. GitHub - sir1st/hermes-desktop: All-in-one cross-platform desktop app for Hermes Agent — bundles Python + hermes-agent + hermes-web-ui GitHub - astefanutti/shaderbang: Shebang for Shaders Show HN: Generate Claude Code Workflows using Spec Driven Development approach GitHub - nixys/nxs-universal-chart: The Helm chart you can use to install any of your applications into Kubernetes/OpenShift Show HN: AI agents for UK GDAD PCF roles and their skills The Two Pillars: Mixer Mode and Meta-Software in the Reorganization of Software Work After AI GitHub - JaiCode08/teleport-env What 1,000+ Harness Experiments Taught Me About Self-Improving Agents Show HN: Liiists, a Markdown-first, iOS and CLI list app SwiperTab – Get this Extension for 🦊 Firefox (en-US) GitHub - kouhxp/fftext: Summarize, explain, fact-check, or translate any text, URL, or file. No GPU. No cloud. One command GitHub - sweetpad-dev/sweetpad: Develop Swift/iOS projects using VSCode GitHub - dogmaticdev/IRON: IRON a.k.a. Intermediate Representation Object Notation is a Interpreter/Database that is used to create Programming Languages. GitHub - sjhalani7/vaen: Package your AI coding harness into a portable .agent file, and share it across repos, teams, & the community without ever having to copy-paste instructions, skills, MCP config, or secrets. Show HN: Gandalf the Grader Show HN: Citadeld – replay any CI failure locally from a single file GitHub - tdortman/cuSBF: High-Performance GPU Super Bloom Filter coral-ai/claude-code-token-xray at main · Coral-Bricks-AI/coral-ai GitHub - ulyssestenn/funes: Funes is a Git-based framework for LLM-managed knowledge work: an AI Librarian ingests raw sources, builds an interlinked Markdown knowledge base, and uses it to produce cited reports, analyses, and other outputs. GitHub - ThatXliner/gah: Git Add Hunk, built for agents to use GitHub - harmont-dev/harmont-cli: Command-line client for the Harmont CI platform GitHub - brooksmcmillin/mcp-authflow: OAuth 2.0 Authorization Server framework for MCP servers GitHub - javaid-codes/audit-supply-chain-agents GitHub - amorey/gochan: A small library of common channel architectures for Go, inspired by Rust GitHub - arifozgun/OpenGem: Free, Open-Source AI API Gateway with Gemini, OpenAI & Anthropic Compatibility in 1 file GitHub - Pranesh950/BioPetals: 🌸 Run BIOxAI models at home, BitTorrent-style. Fine-tuning and inference up to 10x faster than offloading GitHub - cnguyen14/bounty-doctor: Diagnose a GitHub bounty issue before you waste hours: detects honeypot scam repos, AI-bot attempt swarms, and stale contests. Show HN: CoreMCP – MCP Server for On-Prem DBs Show HN: KittyHTML – Render HTML/CSS as an inline image in your terminal GitHub - bingud/filemat: Web-based file manager Show HN: TruthLens – Free multi-signal deepfake image detector GitHub - apexlocal-jz/claude-usage-tray: Windows system-tray app showing your Claude Code rate-limit usage at a glance. Zero deps, ~300 lines of PowerShell. Cross-IDE (works regardless of VS Code, Cursor, plain terminal). Release v0.1.2.1 · kouhxp/yapsnap GitHub - noopolis/moltnet: Self-hostable chat network for AI agents. Pre-built bridges for Claude Code, Codex, and the Claws. Rooms, DMs, history. No Slack bots, no Matrix, no glue code. GitHub - tamerh/enju: Coordinating Humans, AI Agents, and Compute as Peers on a Shared Workflow Graph Show HN: Continuity-auth – Respect-weighted rate limits for the open web GitHub - luml-ai/luml: AI lifecycle platform where engineers and agents track experiments, train models, and ship to production. GitHub - mrdanielcasper/CoreTex: A UNIX-inspired, biomimetic, flat-file AI harness and knowledge engine. GitHub - clemg/pierre-github: Pierre's diffs.com and trees.software for Github GitHub - lyriks-io/unspaghettit: Behavior-driven AI development without prompt spaghetti. GitHub - sofumel/claude-handoff-revive: Resume Claude Code work after rate/usage/context limits without replaying the prior transcript. Auto-saves at 90%/95% usage. Plugin-installable, 10 languages. GitHub - dotexorg/saferpc: Typed, end-to-end encrypted RPC over any bidirectional channel. GitHub - BeeZeeAgent/beezee: Agent harness orchestration Legato Next.js Boilerplate for Internal Tools · CoreUI GitHub - clark-labs-inc/clark-hash: Clark Hash, 32x smaller searchable sketches for embeddings GitHub - ZeroPointRepo/youtube-mcp: The fastest YouTube transcript + YouTube search MCP for AI agents. Try for free. Typing Mastery — climb toward 100+ WPM, deliberately GitHub - Andebugulin/Awareen GitHub - fayzan123/claude-workflow-composer: Visual desktop app for composing multi-agent coding workflows. Drag agents, attach skills and MCPs, wire handoffs, export to .claude/ GitHub - harshaneel/humanize: Best static AI text humanizer. Two research-grounded skills that work in any LLM (Claude, ChatGPT, Gemini, Codex): humanize beats perplexity-based detectors, ai-check produces forensic scoring with evidence-quoted flags. Nine levers, 50+ peer-reviewed sources, 2024-2026 detection literature. GitHub - StackOneHQ/stack-nudge GitHub - nodes-app/swift-markdown-engine: A native AppKit Markdown editor for macOS, built on TextKit 2 and bridged to SwiftUI. We hardened an LLM agent. Each defense we added made it more exploitable. GitHub - alkait/WhatsKept: Agent-queryable WhatsApp history from an iOS backup — a single Go binary. GitHub - octelium/cordium: Open-source, general-purpose sandbox platform for devs and AI agents that provides identity-based secure access to infrastructure without credentials. WAR.GOV/UFO Microfilm5 GitHub - scosman/videowright: Build animated explainer videos with your coding agent GitHub - dipankar/dscode: The code editor you can take apart. GitHub - zoharbabin/web-researcher-mcp: MCP server (Go) for AI assistants: web search, content extraction, academic/patent/news research. Multi-provider routing, 4-tier scraping, search lenses. Works with Claude, Cursor, and any MCP client. GitHub - ruvnet/RuView: π RuView turns commodity WiFi signals into real-time spatial intelligence, vital sign monitoring, and presence detection — all without a single pixel of video. GitHub - scanaislop/aislop: Catch the slop AI coding agents leave in your code: narrative comments, swallowed exceptions, as-any casts, dead code, oversized functions. 50+ rules across 7 languages (TypeScript, JavaScript, Python, Go, Rust, Ruby, PHP). Sub-second, deterministic, no LLM at runtime. MIT-licensed. GitHub - kouhxp/cheap-im: CPU-only voice agent approximating Thinking Machines' Interaction Models demo GitHub - unprovable/OrchidMantis: Orchid Mantis — standalone framework for Zero-Knowledge Proofs of eXploit (ZKPoX). GitHub - MarcellM01/TinySearch: Shrink the web for your local LLMs! GitHub - pileax-ai/pileax: PileaX is an all-in-one AI knowledge base system. 🍀 GitHub - TangibleResearch/Halgorithem: A Algo designed to detect AI Hallucitions GitHub - DO-SAY-GO/freelang: I love freelang GitHub - CarpseDeam/Aura-IDE: An AI coding harness that shaped itself - Planner/Worker agents, repo awareness, surgical edits, validation, recovery, and safe diff approvals. GitHub - chojs23/concord: A feature-rich TUI client for Discord GitHub - tommyjepsen/awesome-ux-skills: UX & AI Product designs skills you can use today in Claude Code GitHub - aerf-spec/aerf: Agent Evidence Receipt Format (AERF) — an open specification for tamper-evident, independently verifiable records of AI agent actions. GitHub - kklimuk/docx-cli: CLI for AI agents (Claude, Codex) to read, edit, and comment on .docx files with full format fidelity. GitHub - Jwrede/tokentoll: Catch LLM cost changes in code review. Infracost for LLM spend. GitHub - samchon/ttsc: A `typescript-go` toolchain for compiler-powered plugins and type-safe execution + 500x faster lint integrated into compiler GitHub - Higangssh/homebutler: 🏠 Manage your homelab from chat. Single binary, zero dependencies. GitHub - olalie/tapmap: See where your computer connects and what stands out on a live world map. GitHub - matisiekpl/neond: DX-focused control plane for Postgres dedicated to non-critical workloads. Your postgres:latest replacement 🐘 GitHub - Diplomat-ai/diplomat-agent: What can your AI agent do to the real world? Scan your code. See which tool calls have zero checks GitHub - Bajusz15/beacon: Open-source agent for secure remote access, monitoring, and deploys across home-lab and self-hosted machines like Raspberry Pi, N100, or any Linux server. Open web based TTY or tunnel Home Assistant and other local services securely without opening ports. BigTech AI News - Chrome 应用商店 GitHub - vinhnx/VTCode: VT Code is an open-source coding agent with LLM-native code understanding and robust shell safety. Supports multiple LLM providers with automatic failover and efficient context management. GitHub - michaelaz774/decision-engine: A decision operating system for startup founders, powered by Claude Code. Synthesizes wisdom from 25+ legendary founders and investors into interactive AI-driven decision frameworks. GitHub - Chrilleweb/dotenv-diff: Validate environment variable usage in your codebase GitHub - Lumen-Labs/brainapi2: BrainAPI is a knowledge graph–powered AI memory layer that transforms unstructured data into structured knowledge, enabling intelligent search, recommendations, and contextual memory for AI agents and applications. GitHub - familiar-software/familiar: Let AI watch you work. Familiar lets your AI update its memory, skills, and knowledge by watching your screen. GitHub - skorotkiewicz/rudo: A small, elegant dock for Wayland GitHub - muxshed/shed: One stream in, or many. Every destination, simultaneously. No cloud middleman, no per-channel fees, no limits. make sidebar/address bar rounded corner toggleable
GitHub - ahmetvural79/tunr: Expose your local server in 3 seconds.
ahvural · 2026-06-22 · via Show HN

$ tunr share --port 3000

  🚀 Tunnel active:  https://abc1x2y3.tunr.sh

  Ctrl+C to stop...

What is tunr?

tunr exposes your local development server to the internet in under 3 seconds — with automatic HTTPS and zero configuration. Browser WebSockets (e.g. Next.js / Vite HMR) are bridged over the same control channel as HTTP when you use the tunr relay + CLI; see Troubleshooting for Next.js allowedDevOrigins and edge cases.

It's a developer-first alternative to ngrok and Cloudflare Tunnel, built in Go as a single static binary that runs on macOS, Linux, and Windows (ARM64 included).

Install

# macOS (Homebrew) — recommended
brew install ahmetvural79/tap/tunr

# Linux / macOS (one-liner)
curl -sSL https://tunr.sh/install | sh

# npm (Node.js projects)
npx tunr@latest share --port 3000

# Docker
docker run --rm -it --network host ghcr.io/ahmetvural79/tunr:v0.4.0 share --port 3000

# Python SDK
pip install tunr

# Node.js SDK
npm install @tunr/cli

# Build from source
git clone https://github.com/ahmetvural79/tunr.git
cd tunr
go build -o tunr ./cmd/tunr

Requires Go 1.22+ to build from source.

Free forever. The CLI and all core features are open source. Cloud features (custom subdomains, team dashboards) require a tunr.sh account.


Quick Start

# 1. Start your dev server
npm run dev  # → http://localhost:3000

# 2. Share it
tunr share --port 3000

# That's it. You get:
#   🚀 https://abc1x2y3.tunr.sh

Commands

# Share a local port (foreground)
tunr share --port 3000
tunr share --port 8080 --subdomain myapp  # custom subdomain (Pro)

# Route paths to different ports
tunr share --route /=3000 --route /api=8080

# Password protection & expiration
tunr share -p 8080 --password "secret" --ttl 30m

# Vibecoder demo superpowers
tunr share -p 3000 --demo --freeze --inject-widget
tunr share -p 3000 --auto-login "Cookie: session=demo"

# Secure & debug (Pinggy-powered)
tunr share -p 3000 --qr                     # QR code for mobile scanning
tunr share -p 3000 --auth-token "my-secret" # Bearer token access control
tunr share -p 3000 --allow-ip "1.2.3.0/24"  # IP whitelist (CIDR)
tunr share -p 3000 --header-add "X-Debug: 1"
tunr share -p 3000 --x-forwarded-for --original-url
tunr share -p 3000 --cors-origin "https://myapp.com"

# Custom domain
tunr share -p 3000 --domain demo.client.com

# Machine-readable output for CI/CD
tunr share -p 3000 --json

# Daemon mode (runs in background)
tunr start --port 3000
tunr stop
tunr status

# Inspect & debug
tunr open           # Open HTTP inspector dashboard
tunr logs           # Stream request logs
tunr logs --follow  # Real-time log stream
tunr replay <id>    # Re-send a captured request

# System
tunr doctor         # System health check
tunr version
tunr update         # Self-update to latest release
tunr uninstall      # Remove tunr from your system

# Auth
tunr login
tunr logout

# Config
tunr config show
tunr config init    # Creates .tunr.json in cwd

# AI / MCP
tunr mcp            # Start MCP server (Claude, Cursor, Windsurf)

# TCP tunnels
tunr tcp --port 5432
tunr tcp --port 22 --qr
tunr tcp --port 6379 --allow-ip 10.0.0.0/8 --region ams

# UDP tunnels (v0.4.0)
tunr udp --port 53                          # DNS server
tunr udp --port 27015 --region ams           # Game server

# TLS tunnels — end-to-end encryption (v0.4.0)
tunr tls --port 8443                         # Zero-trust: relay can't read traffic

# Multi-tunnel from config (v0.4.0)
tunr up                                      # Start all tunnels from .tunr.json
tunr down                                    # Stop all daemon tunnels

# System service (v0.4.0)
tunr service install --port 3000             # Auto-start on boot
tunr service status
tunr service uninstall

# Corporate proxy (v0.4.0)
tunr share -p 3000 --proxy http://proxy:8080

Full CLI Reference

Command Description
tunr share -p PORT Expose local port with HTTPS URL
tunr share -p PORT -s NAME Custom subdomain (Pro)
tunr share --route /PATH=PORT Map specific URL paths to local ports
tunr share -p PORT --password "PASS" Enable Basic Authentication
tunr share -p PORT --ttl 1h Auto-close tunnel after duration
tunr share -p PORT --demo Read-only demo mode
tunr share -p PORT --freeze Freeze mode (cache-on-crash)
tunr share -p PORT --inject-widget Inject feedback widget into HTML
tunr share -p PORT --auto-login "Cookie: s=demo" Auto-inject auth cookie
tunr share -p PORT --domain HOST Use custom domain
tunr share -p PORT --json JSON output (CI/CD, scripting)
tunr share -p PORT --qr Display QR code for the tunnel URL
tunr share -p PORT --auth-token TOKEN Bearer token / API key protection
tunr share -p PORT --allow-ip CIDR IP whitelist (CIDR notation)
tunr share -p PORT --header-add "H: V" Add headers to forwarded requests
tunr share -p PORT --header-replace "H: V" Replace headers before forwarding
tunr share -p PORT --header-remove H Remove headers before forwarding
tunr share -p PORT --x-forwarded-for Inject X-Forwarded-For with client IP
tunr share -p PORT --original-url Inject X-Original-URL with public URL
tunr share -p PORT --cors-origin ORIGIN CORS preflight allowed origins
tunr start -p PORT Background daemon mode
tunr stop Stop daemon
tunr status Show active tunnels
tunr logs Stream HTTP request logs
tunr open Open inspector dashboard
tunr replay <id> Replay captured request
tunr doctor Diagnose issues
tunr login Authenticate (browser-based OAuth)
tunr update Self-update CLI binary
tunr uninstall Remove tunr from system
tunr mcp Start MCP server
tunr config init Create .tunr.json
tunr tcp -p PORT Expose local port via TCP tunnel
tunr tcp -p PORT --qr TCP tunnel with QR code
tunr tcp -p PORT --region REGION TCP tunnel in specific region (ams, sea, sin)
tunr udp -p PORT Expose local UDP port (DNS, game servers)
tunr tls -p PORT TLS tunnel with end-to-end encryption
tunr up Start all tunnels from .tunr.json
tunr down Stop all running daemon tunnels
tunr service install --port PORT Install as system service (auto-start)
tunr service uninstall Remove system service
tunr service status Check service status
tunr share -p PORT --proxy URL Connect through HTTP/SOCKS5 proxy
tunr share -p PORT --region REGION HTTP tunnel in specific region

Troubleshooting

Next.js: blank page over tunr share (port 3000)

Next.js dev blocks cross-origin access to dev-only endpoints unless you allow your tunnel host.

  1. Add allowedDevOrigins in next.config.js / next.config.ts (see Next.js docs — allowedDevOrigins):
/** @type {import('next').NextConfig} */
const nextConfig = {
  allowedDevOrigins: ['*.tunr.sh', 'tunr.sh'],
}
module.exports = nextConfig

Use your real tunnel domain pattern if you use a custom subdomain or self-hosted edge.

  1. For a stable public demo without HMR, prefer a production build:
npm run build && npm run start
tunr share --port 3000

“Chrome offline” / “This site can’t be reached” / dinosaur page when using --inject-widget

That page is the browser’s network error UI — the main HTML document never completed successfully (not the widget script failing in isolation).

WebSocket / HMR over the public URL

The tunr edge relay upgrades the public wss:// connection and streams frames to your CLI, which opens a local ws:// connection to your dev server. That gives you end-to-end HMR-style WebSockets without a separate tunnel product.

Still required for some frameworks: Next.js dev server may block cross-origin requests until you add your tunnel host to allowedDevOrigins in next.config (see above). If HMR still fails, fall back to next build && next start or test HMR on localhost.

Relay / edge: WebSocket bridging is implemented on the tunr relay; self-hosted edges must run a relay build that includes this feature.

Optional: for relay origin checks on the browser WebSocket handshake, set TUNR_WS_EXTRA_ALLOWED_ORIGIN_SUFFIXES (comma-separated hostname suffixes).


Vibecoder Demo Features

tunr ships with four proxy-level superpowers designed for freelancers and agencies demoing to clients:

❄️ Freeze Mode (--freeze)

If your local server crashes mid-demo, tunr serves the last successful response from memory. Your client never sees a broken page.

tunr share --port 3000 --freeze

🛡️ Read-Only Demo Mode (--demo)

Intercept destructive HTTP methods (POST, PUT, DELETE) at the proxy layer. The client can click "Place Order" — nothing actually writes to your database.

tunr share --port 3000 --demo

💬 Feedback Widget Injection (--inject-widget)

Injects a transparent overlay widget into every HTML page served through the tunnel. Clients can pin visual feedback and errors are forwarded to your terminal in real-time. Like Marker.io, but free and built-in.

tunr share --port 3000 --inject-widget

🔑 Auto-Login Bypass (--auto-login)

Inject an auth cookie so your client lands on the demo account automatically — no signup, no email verification.

tunr share --port 3000 --auto-login "Cookie: session=demo-token"

Combine them all for the ultimate demo setup:

tunr share --port 3000 --demo --freeze --inject-widget

Advanced Tunnel Features

🔒 Password Protected Tunnels (--password)

Add Basic Authentication to your public URL instantly without writing any code. Keep your development environments secure from unauthorized access while sharing with clients or third parties.

tunr share -p 8080 --password "secret"
# Or provide a specific username
tunr share -p 8080 --password "client:secret"

⏳ Auto-Expiring Tunnels (--ttl)

Forget to stop a tunnel exposing your local machine? Use a Time-To-Live (TTL). Once the duration expires, the tunnel daemon safely terminates the connection and shuts down the proxy.

tunr share -p 3000 --ttl 1h30m

🔀 Path Routing (--route)

Map different incoming URL paths to different upstream ports on your machine. This is perfect for testing microservices or serving your frontend and API from a single public proxy domain.

# Anything to / goes to 3000, /api goes to 8080
tunr share --route /=3000 --route /api=8080

🌐 Multi-Region Routing (--region)

Select a preferred relay region for lower latency to specific geographic areas.

# European relay (Amsterdam)
tunr share --port 3000 --region ams

# US West relay (Seattle)
tunr share --port 3000 --region sea

# Asia relay (Singapore)
tunr share --port 3000 --region sin

# TCP tunnel with region selection
tunr tcp --port 5432 --region ams

Currently available regions:

  • ams — Amsterdam, EU (Europe)
  • sea — Seattle, US West (Americas)
  • sin — Singapore (Asia-Pacific)

🔌 TCP Tunnels (tunr tcp)

Expose raw TCP services — databases, SSH, Redis, game servers — through secure tunnels without HTTP overhead.

# PostgreSQL
tunr tcp --port 5432

# SSH with QR code for mobile sharing
tunr tcp --port 22 --qr

# Redis with IP restriction
tunr tcp --port 6379 --allow-ip 10.0.0.0/8

# MySQL in specific region
tunr tcp --port 3306 --region ams

TCP tunnels forward raw bytes over the same WebSocket control channel — no HTTP parsing on the relay side. Perfect for any TCP-based service.


Programming APIs

Python SDK

from tunr import TunrClient, TunnelOptions

client = TunrClient()

# Simple tunnel
tunnel = client.share(port=3000)
print(tunnel.public_url)

# TCP / UDP / TLS tunnels (v0.4.0)
db_tunnel = client.tcp(port=5432)
dns_tunnel = client.udp(port=53)
tls_tunnel = client.tls(port=8443)

# With options
opts = TunnelOptions(
    subdomain="myapp",
    password="demo123",
    allow_ips=["10.0.0.0/8"],
    freeze=True,
    inject_widget=True,
    proxy="http://proxy:8080",
    ttl="2h",
)
tunnel = client.share(port=8080, opts=opts)

# Inspect requests
requests = client.get_requests(tunnel.subdomain)

# Replay a request
client.replay_request(tunnel.subdomain, requests[0]['id'], port=3000)

# Observability (v0.4.0)
metrics = client.get_metrics()     # Prometheus format
health = client.health_check()     # {"status": "ok"}

# Clean up
tunnel.close()

Node.js SDK

import { TunrClient } from '@tunr/cli'

const client = new TunrClient()

// Simple tunnel
const tunnel = await client.share(3000)
console.log(tunnel.publicUrl)

// TCP / UDP / TLS tunnels (v0.4.0)
const dbTunnel = await client.tcp(5432)
const dnsTunnel = await client.udp(53)
const tlsTunnel = await client.tls(8443)

// With options
const appTunnel = await client.share(8080, {
  subdomain: 'myapp',
  password: 'demo123',
  allowIps: ['10.0.0.0/8'],
  freeze: true,
  injectWidget: true,
  proxy: 'http://proxy:8080',
  ttl: '2h',
})

// Event-based lifecycle
tunnel.on('ready', () => console.log('Tunnel live'))
tunnel.on('error', (err) => console.error(err))
tunnel.on('exit', () => console.log('Tunnel closed'))

// Inspect & replay
const requests = await client.getRequests('myapp')
await client.replayRequest('myapp', requests[0].id, 3000)

// Observability (v0.4.0)
const metrics = await client.getMetrics()    // Prometheus text
const health = await client.healthCheck()    // {status: "ok"}

// Clean up
await tunnel.close()

Security & Debugging (Pinggy-Inspired)

tunr now includes all the enterprise-grade tunnel security and debugging features from Pinggy, built natively:

📱 QR Code Tunnel Sharing (--qr)

Instantly generate a scannable QR code for your tunnel URL. Perfect for mobile testing and sharing URLs with clients.

🔑 Bearer Token Access (--auth-token)

Protect your tunnel with a simple API key/token. Requests must include Authorization: Bearer <token> or pass ?token=<token> in the query string.

tunr share -p 3000 --auth-token "my-super-secret-key"

🛡️ IP Whitelisting (--allow-ip)

Restrict tunnel access to specific IP ranges using CIDR notation. Only whitelisted IPs can reach your local server.

# Only allow your office network
tunr share -p 3000 --allow-ip "203.0.113.0/24"

# Multiple networks
tunr share -p 3000 --allow-ip "10.0.0.0/8,172.16.0.0/12"

🔧 Live Header Modification

Add, replace, or remove HTTP headers on the fly before they reach your local server.

# Inject a debug header
tunr share -p 3000 --header-add "X-Debug: true"

# Replace the Host header for internal routing
tunr share -p 3000 --header-replace "Host: internal.local"

# Remove fingerprinting headers
tunr share -p 3000 --header-remove "X-Powered-By"

🌐 Forwarded Headers (--x-forwarded-for, --original-url)

Inject standard proxy headers so your application knows the original client IP and URL.

tunr share -p 3000 --x-forwarded-for --original-url
  • X-Forwarded-For — the real client IP address
  • X-Original-URL — the full public tunnel URL that was requested

🔓 CORS Preflight (--cors-origin)

Allow browser CORS preflight requests from specific origins without server-side changes.

tunr share -p 3000 --cors-origin "https://myapp.com"

HTTP Inspector

tunr ships with a built-in HTTP request inspector (like ngrok's web UI, but local).

tunr open  # opens http://localhost:19842

Features:

  • Live request/response stream
  • Headers, body, timing
  • One-click replay
  • Export as curl command

MCP Integration (Claude, Cursor, Windsurf)

tunr implements the Model Context Protocol — AI agents can manage tunnels directly.

Claude Desktop (~/.claude/claude_desktop_config.json):

{
  "mcpServers": {
    "tunr": {
      "command": "tunr",
      "args": ["mcp"]
    }
  }
}

Cursor (.cursor/mcp.json):

{
  "mcpServers": {
    "tunr": { "command": "tunr", "args": ["mcp"] }
  }
}

Configuration (.tunr.json)

Create a workspace config file:

{
  "$schema": "https://tunr.sh/schema/.tunr.schema.json",
  "port": 3000,
  "inspectorEnabled": true,
  "dashboardPort": 19842,
  "mcp": { "enabled": true }
}

Architecture

tunr is a single Go binary that:

  1. Starts a local HTTPS proxy with an embedded inspector
  2. Opens a WebSocket connection to the tunr relay (edge server)
  3. The relay issues a *.tunr.sh subdomain and forwards traffic
  4. HTTPS terminates at the relay; CLI ↔ dev-server traffic runs over the same WebSocket stream
Browser → relay.tunr.sh → [WebSocket] → tunr binary → localhost:PORT

Protocol support: tunr tunnels HTTP/HTTPS + WebSocket, TCP, UDP, and TLS (end-to-end encrypted) traffic. UDP datagrams are forwarded through the WebSocket control channel. TLS tunnels use SNI-based routing for zero-knowledge passthrough.

Multi-region: The relay supports region selection via the --region flag. Currently available regions: ams (Amsterdam, EU), sea (Seattle, US West), sin (Singapore, Asia). The balancer infrastructure (relay/internal/relay/balancer.go) manages cross-region routing metadata.

Wildcards: The relay is configured with *.tunr.sh wildcard routing through Fly.io / Caddy; wildcard domain support for custom domains is available.

Self-Hosting: The relay can be self-hosted using the included docker-compose.yml (Relay + Caddy + Postgres). See docs/SELF_HOSTING.md for the complete guide.

Docker: The CLI is available as a ~15MB Alpine Docker image. Build with docker build -t tunr . or pull from ghcr.io/ahmetvural79/tunr.

Observability: The CLI exposes Prometheus metrics at /metrics and K8s-ready health probes at /healthz and /readyz on the inspector port (19842).


Security

tunr takes security seriously for an open-source CLI tool:

  • Auth tokens stored in OS keychain (not plaintext files)
  • All relay traffic over TLS 1.3
  • No telemetry, no analytics, no phone-home by default
  • Supply chain integrity via go mod verify and govulncheck in CI

Found a vulnerability? Do not open a public issue. See SECURITY.md.


How tunr Compares

tunr vs ngrok

Both tools share localhost, but tunr focuses on developer experience and vibecoding workflows:

tunr ngrok (Personal)
Monthly Price 💸 Free / affordable 💸 $10/month
Bandwidth 📦 Unlimited 📦 5 GB/month cap
Vibecoder Demo Features ❄️🛡️💬✅ Exclusive
IP Whitelisting ❌ (Enterprise only)
Bearer Token Auth
Header Modification
QR Code Tunnel Sharing
MCP / AI Integration
Open Source CLI

Compare Pinggy vs ngrok

tunr vs Cloudflare Tunnel

tunr Cloudflare Tunnel
Setup complexity ⚡ 1 command (tunr share -p 3000) ⚠️ Requires Cloudflare account + DNS config
Persistent subdomains ✅ (tunr.sh managed) ❌ Must own a domain first
Vibecoder Demo Features ✅ Exclusive
Request Inspection ✅ Live inspector + replay
Bandwidth limits 📦 Unlimited ⚠️ 100 MB max upload
IP Whitelisting ✅ CLI-level (no dashboard)
Local dashboard ✅ Built-in

Compare Pinggy vs Cloudflare Tunnel

tunr vs LocalXpose

tunr LocalXpose (Pro)
Monthly Price 💸 Free / affordable 💸 $8/month
Bearer Token Auth
MCP Integration
Vibecoder Demo Features ✅ Exclusive
Header Modification
Open Source

Compare Pinggy vs LocalXpose

tunr vs LocalTunnel

LocalTunnel is free but minimal — tunr adds a full feature set on top of the same zero-cost model:

tunr LocalTunnel
HTTPS tunnel
WebSocket / HMR
Custom domains
Persistent subdomains
IP Whitelisting
Bearer Token Auth
Request Inspector
Password Protection
Demo / Freeze / Widget ✅ Exclusive

Compare Pinggy vs LocalTunnel


Roadmap

Feature Status Notes
TCP tunnel support ✅ Released Database, SSH, game server tunnels
UDP tunnel support ✅ Released (v0.4.0) DNS, game servers, real-time apps
TLS tunnel (E2E encryption) ✅ Released (v0.4.0) Zero-trust, relay can't read traffic
Python / Node.js SDKs ✅ Released Programmatic tunnel creation via pip install tunr / npm i @tunr/cli
Multi-region relay ✅ Released --region flag with ams, sea, sin regions
Docker / Self-Hosting ✅ Released (v0.4.0) docker-compose.yml for full stack; ~15MB CLI image
Prometheus Metrics ✅ Released (v0.4.0) /metrics, /healthz, /readyz
Service Install ✅ Released (v0.4.0) tunr service install (systemd / launchd)
Multi-Tunnel Config ✅ Released (v0.4.0) tunr up / tunr down from .tunr.json
Corporate Proxy ✅ Released (v0.4.0) --proxy flag + HTTP_PROXY / HTTPS_PROXY env
Wildcard custom domains ✅ Released (v0.4.0) *.yourdomain.com routing via self-hosted relay
GUI desktop app 📋 Backlog Windows, macOS, Linux
Webhook verification 📋 Backlog Signature validation for incoming webhooks
Team collaboration 📋 Backlog Shared tunnels, member management
Remote device management 📋 Backlog Manage tunnels on IoT / remote machines
Persistent TCP/UDP ports 📋 Backlog Fixed-port tunnel endpoints
Automatic Let's Encrypt certs 📋 Backlog Per-tunnel TLS certificate provisioning

Contributing

Contributions are welcome! Please read CONTRIBUTING.md first.

  1. Fork the repository
  2. Create a feature branch (git checkout -b feat/my-feature)
  3. Make your changes
  4. Ensure CI passes (go test ./... + golangci-lint run)
  5. Open a pull request

License

PolyForm Shield 1.0.0 — see LICENSE.

You are free to use, modify, and distribute this software. The only restriction is that you may not use it to build a competing product or service. See the license for full terms.