OpenTunnel: An End-to-End Encrypted Tunnel That Exposes Local Apps via Public URLs
dax (@thdxr) announced the end-to-end encrypted local tunnel OpenTunnel: the relay sees only the hostname and forwards the encrypted stream while TLS terminates
On October 8, 2026, dax (@thdxr) announced OpenTunnel (opentunnel.xyz), a tunneling tool that gives apps running on a local machine a public URL. The claimed differences from existing tunnel services are its end-to-end encrypted design and an SDK for embedding the functionality into apps. The author said integration into opencode was scheduled for the following day.

Image source: opentunnel.xyz
This article covers the opentunnel.xyz version of OpenTunnel only. It shares a name with opentunnel.sh, a remote-command tunnel for AI agents, but they are separate products — do not confuse them.
What OpenTunnel Does and How It Works
OpenTunnel is a CLI and SDK that creates publicly reachable URLs for apps running on your machine. Its official page describes a five-step flow:
createreserves a hostname and generates a private key on the user's machine. The key never leaves it.- The CLI sends a certificate request for that hostname, and a certificate bound to the tunnel name is issued. The relay only ever sees the public half.
connectopens an encrypted bridge from the user's machine to the relay.- When a visitor hits the public URL, the relay reads only the hostname from the TLS handshake and forwards the encrypted stream through the bridge.
- The user's machine terminates TLS with its private key and proxies the traffic to the local app.
In the announcement thread, the author described OpenTunnel as a TCP proxy for traffic that sends SNI. That answer was given in response to a "what kinds of traffic" question, so traffic that does not send SNI falls outside this verified description.
CLI Usage and Prerequisites
The npm package opentunnel is a launcher that runs the native Rust CLI (crates/opentunnel-cli). The commands published on its official npm page include:
opentunnel route add api 3000— mapsapi.<hostname>to127.0.0.1:3000and brings the tunnel up.opentunnel route add @ 127.0.0.1:8080— maps the hostname itself.opentunnel route list— shows the route list.opentunnel status— shows tunnel, routes, and connection status.opentunnel up— connects the tunnel.
Who it is for: developers who need a public URL for a local app. The official page presents CLI/SDK-based public URL creation; specific use cases such as webhook reception or demo sharing are not stated in the cited evidence. The announced SDK is presented as a way to embed tunneling into apps.
Verified Limits: Trust Assumption, Pricing, and Integration Timing
The marketing claim ("the relay can't see anything") should not be taken literally. A third-party reviewer pointed out that the relay operator holds DNS edit rights and the certificate account, so it could obtain an additional certificate for any tunnel hostname under its own key. The author himself replied that he should add this to the privacy section, that trust is required, and that users can clone the relay and run it on their own domain. In other words, the current design assumes trust in the relay operator, and self-hosting the relay is the author-suggested alternative for those who want to avoid that assumption.
Pricing and traffic caps are unconfirmed. Asked about limits, the author replied that limits support would likely be needed; the pricing question went unanswered. Do not assume it is free or unlimited.
The opencode integration is at the announcement stage ("to be integrated tomorrow") and must not be reported as completed as of this article's date (2026-10-08). Feature suggestions such as auth-header support or social login have only discussion-level replies so far.
Sources
- Official OpenTunnel page: opentunnel.xyz
- npm package page: opentunnel
- dax (@thdxr) announcement post: OpenTunnel launch, 2026-10-08
- Author reply on TCP proxy behavior and limits: SNI traffic scope, limits support needed
- Author reply on the trust assumption: trust required, self-hosting on own domain possible