TAU-HOME.COM
LOADING

OpenTunnel: An End-to-End Encrypted Tunnel That Exposes Local Apps via Public URLs

dax (@thdxr) announced the end-to-end encrypted local tunnel OpenTunnel: the relay sees only the hostname and forwards the encrypted stream while TLS terminates

tau · October 8, 2026

#opentunnel #tunnel #dev-tools #localhost #opencode

OpenTunnel: An End-to-End Encrypted Tunnel That Exposes Local Apps via Public URLs

On October 8, 2026, dax (@thdxr) announced OpenTunnel (opentunnel.xyz), a tunneling tool that gives apps running on a local machine a public URL. The claimed differences from existing tunnel services are its end-to-end encrypted design and an SDK for embedding the functionality into apps. The author said integration into opencode was scheduled for the following day.

Developer laptop running a local server with an encrypted tunnel line extending to a public URL globe icon, relay node labeled hostname only

Image source: opentunnel.xyz

This article covers the opentunnel.xyz version of OpenTunnel only. It shares a name with opentunnel.sh, a remote-command tunnel for AI agents, but they are separate products — do not confuse them.

What OpenTunnel Does and How It Works

OpenTunnel is a CLI and SDK that creates publicly reachable URLs for apps running on your machine. Its official page describes a five-step flow:

  • create reserves a hostname and generates a private key on the user's machine. The key never leaves it.
  • The CLI sends a certificate request for that hostname, and a certificate bound to the tunnel name is issued. The relay only ever sees the public half.
  • connect opens an encrypted bridge from the user's machine to the relay.
  • When a visitor hits the public URL, the relay reads only the hostname from the TLS handshake and forwards the encrypted stream through the bridge.
  • The user's machine terminates TLS with its private key and proxies the traffic to the local app.

In the announcement thread, the author described OpenTunnel as a TCP proxy for traffic that sends SNI. That answer was given in response to a "what kinds of traffic" question, so traffic that does not send SNI falls outside this verified description.

CLI Usage and Prerequisites

The npm package opentunnel is a launcher that runs the native Rust CLI (crates/opentunnel-cli). The commands published on its official npm page include:

  • opentunnel route add api 3000 — maps api.<hostname> to 127.0.0.1:3000 and brings the tunnel up.
  • opentunnel route add @ 127.0.0.1:8080 — maps the hostname itself.
  • opentunnel route list — shows the route list.
  • opentunnel status — shows tunnel, routes, and connection status.
  • opentunnel up — connects the tunnel.

Who it is for: developers who need a public URL for a local app. The official page presents CLI/SDK-based public URL creation; specific use cases such as webhook reception or demo sharing are not stated in the cited evidence. The announced SDK is presented as a way to embed tunneling into apps.

Verified Limits: Trust Assumption, Pricing, and Integration Timing

The marketing claim ("the relay can't see anything") should not be taken literally. A third-party reviewer pointed out that the relay operator holds DNS edit rights and the certificate account, so it could obtain an additional certificate for any tunnel hostname under its own key. The author himself replied that he should add this to the privacy section, that trust is required, and that users can clone the relay and run it on their own domain. In other words, the current design assumes trust in the relay operator, and self-hosting the relay is the author-suggested alternative for those who want to avoid that assumption.

Pricing and traffic caps are unconfirmed. Asked about limits, the author replied that limits support would likely be needed; the pricing question went unanswered. Do not assume it is free or unlimited.

The opencode integration is at the announcement stage ("to be integrated tomorrow") and must not be reported as completed as of this article's date (2026-10-08). Feature suggestions such as auth-header support or social login have only discussion-level replies so far.

Sources