Hosted in the European Union

Expose your homelab, one port at a time.

Portlatch puts a service running at home on the internet, even when your provider won't let you open a port. Install a small agent, pick a port or a name, and visitors reach your machine through an encrypted tunnel.

No credit card· No time limit ·Paid plans from €3/month

A visitor connects to nas.portlatch.com:2222; our node in Europe sends the connection down a WireGuard tunnel to the agent on your network, which hands it to your NAS at 192.168.1.42 port 22. THE INTERNET YOUR NETWORK · BEHIND CGNAT A visitor, anywhere nas.portlatch.com:2222 Portlatch node Public IPv4 · EU Portlatch agent Docker, on your network Your NAS 192.168.1.42:22 WireGuard tunnel started from your side Nothing open on your router Visitors see our address, never yours.

Works behind CGNAT, Starlink and 4G/5G

If you can't open a port on your router, you're probably behind one of these.

  • CGNAT

    Your provider shares one public address between many homes.

  • Starlink

    Behind CGNAT by default.

  • 4G/5G boxes

    Mobile networks share their addresses, with no way to opt out.

  • Dual-Stack Lite (DS-Lite)

    Your line has IPv6, but its IPv4 is shared.

  • A router that isn't yours

    A rented flat, a student residence, an office: no access to its settings.

You don't need

  • A fixed IP address
  • A full public IPv4
  • A dynamic DNS service
  • Port forwarding on your router
  • A server to rent

How it works

Up and running in three steps

No server to rent, nothing to configure on your router.

  1. 1

    Reserve a port or a name

    Create your account and pick what your visitors will type: a name for a website, a port for anything else.

    New web route

    https://nas.portlatch.com

    Reserved

  2. 2

    Run the agent

    One Docker command on any machine of your network. It shows a code: type it in your dashboard, and the tunnel goes up.

    $ docker run -d portlatch/portlatch-agent

    Enrolment code: K7QM-4XZP

    Tunnel up

  3. 3

    Point it at your service

    Choose the machine and the port on your network. Your route is online within a minute.

    → 192.168.1.42:443 Pending Online

Two ways to expose a service

Does it open in a browser?

The answer tells you which kind of route to create. And the target doesn't have to run the agent: any device it can reach on your network works.

Yes: a web route

HTTP and HTTPS

https://nas.portlatch.com

Reached by its name alone, with no port number.

  • Websites
  • Home automation
  • Your NAS
  • Your own films
  • Your photo library
  • Webhooks

No: a port forward

Any TCP protocol

nas.portlatch.com:2222

A name and a port, for anything that speaks TCP.

  • SSH
  • A game server
  • Remote desktop
  • Databases
  • A local LLM

Why Portlatch

Everything a public address gives you

Your services online, without a server to look after.

  • Any TCP port, not just websites

    SSH, game servers, remote desktop, databases: if it speaks TCP, it goes through.

  • Nothing to install for your visitors

    They get a real public address, and connect with the app they already use.

  • Survives a changing IP

    Power cut, router restart, new address, switch to 4G: the tunnel comes back by itself.

  • Nothing to open on your router

    The agent only makes outgoing connections, which every router allows.

  • WireGuard inside

    A modern, fast tunnel protocol, already audited.

  • Your own domain

    From the Pro plan, put a web route behind your own subdomain, like nas.example.com.

  • The visitor's real IP

    Turn on PROXY protocol on paid plans, and nginx, Traefik or Caddy see who really connects.

  • Several networks, one account

    An agent per network, at home or elsewhere, all in the same dashboard.

Privacy

Your traffic stays yours

Your traffic goes through our servers without being decrypted. And you can check it: the part that runs on your network is open source.

  • We never decrypt. No TLS termination, no key on our side: HTTPS and SSH stay encrypted from the visitor to your machine.
  • In Europe, outside the US. Our servers, your data and the company all stay in the European Union.
  • An open-source agent. Apache-2.0, small enough to audit in an afternoon.
  • Your keys stay home. The agent makes its WireGuard keys itself: the private key never leaves your machine.
  • Only what you publish. Visitors reach the services you chose, and nothing else on your network.
The source on GitHub

Run the agent on

Free plan

Your first port, for free.

  • 1 route, a web route or a port
  • 10 GB of traffic every 30 days
  • Up to 10 Mbit/s
  • No credit card, no time limit
Get your first port

Need more?

  • Pro Your services, your names. €3/month
  • Turbo Your media and backups, faster. €5/month
  • Dedicated Your own IP, every port. €9/month
Compare the plans

FAQ

Common questions

Is it a VPN?

No. Visitors only reach the ports you publish: the rest of your network stays closed, to them and to us.

Read the full answer
Can you read my traffic?

No. HTTPS and SSH stay encrypted from the visitor to your machine.

Read the full answer
What do you log?

What happens on your account, and how much traffic goes through. Never the content of your traffic.

Read the full answer
Will my service see the visitor's real IP? (PROXY protocol)

Yes, if your service reads PROXY protocol, as nginx, HAProxy, Traefik and Caddy do: turn it on for the route, on paid plans.

Read the full answer
Is there really a free plan?

Yes: 1 route, 10 GB of traffic every 30 days, no credit card and no time limit.

Read the full answer
How fast is it?

From 10 Mbit/s on Free up to 100 Mbit/s on Turbo and Dedicated.

Read the full answer
Can I use my own domain?

Yes, from the Pro plan: add a subdomain to a web route, then point a CNAME at the route's name. Up to 5 per web route.

Read the full answer
Do you handle HTTPS for me?

No. Your machine shows its own certificate, from Let's Encrypt for instance, so we never hold a key to your traffic.

Read the full answer

All the questions