pgrok: A Multi-Tenant HTTP/TCP Reverse Tunnel Solution via SSH

This repository profile is provided by osrepos.com, an open source repository discovery platform.

pgrok: A Multi-Tenant HTTP/TCP Reverse Tunnel Solution via SSH

Summary

pgrok is a "poor man's ngrok" designed for small teams, offering a multi-tenant HTTP/TCP reverse tunnel solution through SSH remote port forwarding. It provides stable subdomains for every user, gated by your SSO through the OIDC protocol, making it a cost-effective alternative for exposing local development environments to the public internet.

Repository Information

Analyzed by OSRepos on February 16, 2026

Topics

Click on any tag to explore related repositories

Use at your own risk

OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of code from these repositories is the user's own responsibility. Always review the repository, source code, dependencies, licenses, and security implications before running or installing anything. OSRepos is not responsible for issues, damages, or losses resulting from third-party repositories.

Introduction

pgrok is an open-source, multi-tenant HTTP/TCP reverse tunnel solution that leverages SSH remote port forwarding. Billed as a "poor man's ngrok," it's specifically designed for small teams that need to expose their local development environments to the public internet. It stands out by offering stable subdomains for individual users, secured by your own Single Sign-On (SSO) provider via the OIDC protocol.

This project aims to provide a simpler, more controlled alternative to commercial services for internal team use, allowing developers, community managers, sales, and PMs to easily share their local work without deep server operations knowledge. It requires you to bring your own domain name and SSO provider, offering a tailored and cost-efficient solution.

Installation

Setting up pgrok involves configuring both a server component (pgrokd) and a client (pgrok).

Prerequisites:

  • A domain name (e.g., example.com)
  • A server (VPS, dedicated) with a public IP address
  • An SSO provider that supports OIDC (e.g., Google, Okta, GitLab)
  • A PostgreSQL server

Server Setup (pgrokd):

  1. DNS Records: Add A records for your domain and a wildcard subdomain (e.g., example.com and *.example.com) pointing to your server's public IP.
  2. Server Deployment: Set up pgrokd using a single binary, Docker, or Docker Compose.
  3. Network Security: Allow inbound requests to port 2222 (and 10000-15000 for TCP tunnels) on your server.
  4. Reverse Proxy: Install and configure Caddy 2 to proxy requests to pgrokd.
  5. OIDC Client: Create an OIDC client in your SSO provider with the Redirect URI set to http://example.com/-/oidc/callback.

Client Setup (pgrok):

  1. Obtain Token: Visit your pgrokd instance (e.g., http://example.com), authenticate with SSO, and obtain your unique token and URL.
  2. Download Client:
    • For Homebrew: brew install pgrok
    • For others, download from the Releases page.
  3. Initialize Config: Run pgrok init --remote-addr example.com:2222 --forward-addr http://localhost:3000 --token {YOUR_TOKEN}.
  4. Launch Client: Execute pgrok or pgrok http to start the tunnel.

For detailed instructions and HTTPS setup, refer to the official pgrok documentation.

Examples

HTTP Tunneling:

pgrok http 8080

Raw TCP Tunnels:

pgrok tcp 5432

HTTP Dynamic Forwards:

Configure dynamic_forwards in your pgrok.yml to route specific paths to different local addresses:

dynamic_forwards: |
  /api http://localhost:8080
  /hook http://localhost:8080

This will forward requests to /api and /hook to http://localhost:8080, while other requests go to your forward_addr.

Vanilla SSH Client:

Since pgrok uses the standard SSH protocol, you can also use a vanilla SSH client:

  1. Obtain your token and URL from the pgrokd web interface.
  2. Run ssh -N -R 0::3000 example.com -p 2222 and enter your token as the password.

Why Use pgrok?

pgrok addresses the common pain points of high costs associated with stable subdomains and SSO integration in other tunneling solutions. It's built for teams who value simplicity and efficiency, especially when exposing local services for testing, demos, or collaboration.

  • Cost-Effective: Avoids the high enterprise tier costs of commercial alternatives by allowing you to use your existing infrastructure and SSO provider.
  • Simplified UX: Offers a "Copy, paste, and run" experience, making it accessible even for team members without extensive server operations knowledge.
  • Stable Subdomains & SSO: Provides consistent URLs for users, secured by your organization's SSO, which is crucial for internal team workflows.
  • Flexibility: Supports both HTTP and raw TCP tunneling, with advanced features like dynamic HTTP forwards.

Links

Related repositories

Similar repositories that may be relevant next.

e2a: Open-Source Email API for Applications and AI Agents

e2a: Open-Source Email API for Applications and AI Agents

September 29, 2026

e2a is an open-source email API designed for applications and AI agents, offering robust transactional email capabilities and real two-way inboxes. It supports both managed hosting and self-hosting with Docker, providing features like human-in-the-loop approval and advanced content screening. Built in Go, e2a aims to bridge email's universal addressability with the structured data world of AI agents.

ai-agentsemail-apigo
KSail: The All-in-One Kubernetes SDK for Cluster Management and GitOps

KSail: The All-in-One Kubernetes SDK for Cluster Management and GitOps

September 27, 2026

KSail is a comprehensive Kubernetes SDK designed to simplify cluster creation, management, and operation across multiple distributions like Kind, K3d, Talos, and VCluster. It integrates essential features such as GitOps, secrets management, an AI assistant, and an MCP server, making cloud-native development accessible with just Docker or a cloud provider.

kubernetescloud-nativedevops
ADL CLI: Scaffold Enterprise-Ready AI Agents with A2A Protocol

ADL CLI: Scaffold Enterprise-Ready AI Agents with A2A Protocol

September 15, 2026

The ADL CLI is a powerful command-line tool designed to rapidly scaffold and manage enterprise-ready AI Agents. It leverages the YAML-based Agent Definition Language (ADL) to generate complete project structures, eliminating boilerplate and ensuring consistent patterns. This tool significantly accelerates the development of AI agents powered by the A2A (Agent-to-Agent) protocol.

a2aai-agentscli-tool
Qovira: A Private, Self-Hostable AI Personal Assistant in Go

Qovira: A Private, Self-Hostable AI Personal Assistant in Go

September 15, 2026

Qovira is an ambitious project aiming to deliver a private, self-hostable AI personal assistant. Built with Go and SvelteKit, it will organize reminders, notes, and schedules using AI, all on infrastructure you control. Currently in early development, Qovira promises a secure and private alternative to cloud-based AI tools.

ai-assistantgogolang

Source repository

Open the original repository on GitHub.

19 counted GitHub visits

View on GitHub
OS
OSRepos

Analysis and discovery of open source repositories. Find interesting projects and follow their updates.

Monitor your website with YourWebsiteScore

OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of third-party repository code is at your own risk. Always review source code, dependencies, licenses, and security implications before running anything.

© 2025 OSRepos. Built with Nuxt 3 and lots of ❤️