Hosted in the European Union
Portlatch puts a service running at home on the internet, even when your provider won't let you open a port. Install a small agent, pick a port or a name, and visitors reach your machine through an encrypted tunnel.
No credit card· No time limit ·Paid plans from €3/month
If you can't open a port on your router, you're probably behind one of these.
CGNAT
Your provider shares one public address between many homes.
Starlink
Behind CGNAT by default.
4G/5G boxes
Mobile networks share their addresses, with no way to opt out.
Dual-Stack Lite (DS-Lite)
Your line has IPv6, but its IPv4 is shared.
A router that isn't yours
A rented flat, a student residence, an office: no access to its settings.
You don't need
How it works
No server to rent, nothing to configure on your router.
Create your account and pick what your visitors will type: a name for a website, a port for anything else.
New web route
Reserved
One Docker command on any machine of your network. It shows a code: type it in your dashboard, and the tunnel goes up.
$ docker run -d portlatch/portlatch-agent
Enrolment code: K7QM-4XZP
Tunnel up
Choose the machine and the port on your network. Your route is online within a minute.
Two ways to expose a service
The answer tells you which kind of route to create. And the target doesn't have to run the agent: any device it can reach on your network works.
https://nas.portlatch.com
Reached by its name alone, with no port number.
nas.portlatch.com:2222
A name and a port, for anything that speaks TCP.
Why Portlatch
Your services online, without a server to look after.
Any TCP port, not just websites
SSH, game servers, remote desktop, databases: if it speaks TCP, it goes through.
Nothing to install for your visitors
They get a real public address, and connect with the app they already use.
Survives a changing IP
Power cut, router restart, new address, switch to 4G: the tunnel comes back by itself.
Nothing to open on your router
The agent only makes outgoing connections, which every router allows.
WireGuard inside
A modern, fast tunnel protocol, already audited.
Your own domain
From the Pro plan, put a web route behind your own subdomain, like nas.example.com.
The visitor's real IP
Turn on PROXY protocol on paid plans, and nginx, Traefik or Caddy see who really connects.
Several networks, one account
An agent per network, at home or elsewhere, all in the same dashboard.
Privacy
Your traffic goes through our servers without being decrypted. And you can check it: the part that runs on your network is open source.
Run the agent on
Free plan
Need more?
FAQ
No. Visitors only reach the ports you publish: the rest of your network stays closed, to them and to us.
Read the full answerNo. HTTPS and SSH stay encrypted from the visitor to your machine.
Read the full answerWhat happens on your account, and how much traffic goes through. Never the content of your traffic.
Read the full answerYes, if your service reads PROXY protocol, as nginx, HAProxy, Traefik and Caddy do: turn it on for the route, on paid plans.
Read the full answerYes: 1 route, 10 GB of traffic every 30 days, no credit card and no time limit.
Read the full answerFrom 10 Mbit/s on Free up to 100 Mbit/s on Turbo and Dedicated.
Read the full answerYes, from the Pro plan: add a subdomain to a web route, then point a CNAME at the route's name. Up to 5 per web route.
No. Your machine shows its own certificate, from Let's Encrypt for instance, so we never hold a key to your traffic.
Read the full answer