HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH.
HTTP, WebSocket and TCP tunnels opened with a plain SSH client to a server you run, with no agent to install.
alternatives to
Hosted tunnels that expose services running on a private machine or network through the vendor's edge. A closed product from ngrok.
| Tool | Fit | Stars | Licence | Terms | Self-hosted | Language | Latest | Last push |
|---|---|---|---|---|---|---|---|---|
| sish | Full replacement | 4.8k | MIT | Open source | Yes | Go | v2.24.0 | 2026-10-02 |
| zrok | Full replacement | 4.8k | Apache-2.0 | Open source | Yes | Go | v2.0.7 | 2026-10-06 |
| frp | Partial | 110k | Apache-2.0 | Open source | Yes | Go | v0.71.0 | 2026-09-15 |
| Pangolin | Partial | 23k | Other | Open core | Yes | TypeScript | 1.24.0 | 2026-10-05 |
| rathole | Partial | 14k | Apache-2.0 | Open source | Yes | Rust | v0.5.0 | 2026-08-23 |
5 alternatives
HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH.
HTTP, WebSocket and TCP tunnels opened with a plain SSH client to a server you run, with no agent to install.
Secure internet sharing made simple.
Public and private shares of HTTP, TCP and UDP services started from a CLI, on the hosted service or an instance you run.
A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.
Exposes local TCP, UDP and HTTP services through a server you run, without the hosted edge or dashboard.
Modern networking and security platform providing secure access and connectivity to apps, infrastructure, and AI workloads. Connect and protect your users.
Publishes long-lived services through a server you run, without ad-hoc tunnels started from a CLI.
A lightweight and high-performance reverse proxy for NAT traversal, written in Rust. An alternative to frp and ngrok.
Exposes TCP and UDP services behind NAT through your own server, without request inspection or a dashboard.