NEW CONNECTION

Connect a device

Enable SSH on your device, then add the credentials Relay will use to connect back to it.

DEVICE CONNECTION

Open your tunnel

  1. Save the tunnel key on your device

    This key only opens this device’s dedicated tunnel.

  2. Run this in the same folder

    Keep the command running while you use Relay. If the connection drops, run it again.

  3. Verify the server fingerprint

    On first connection, compare the fingerprint shown by SSH with:

  4. Check the connection

Update device host key

Or copy the SSH server's public key directly from your device. This is different from your login public key in ~/.ssh/.

cat /etc/ssh/ssh_host_ed25519_key.pub

Accept device host key?

Accepting saves this key for future connections. Unexpected key changes will be blocked.

Add a Linux agent

Run this on your Linux machine. No root access or SSH server is required.

The code works once and expires in 10 minutes. Keep the agent running; it will appear under HTTP agents. Later starts use the saved identity and do not need a code.

Linux x86-64 · Linux ARM64 · SHA-256 checksum

HTTP traffic

TimeRequestStatusDurationResponse

Configure HTTP agent

Response replacements

Replace text in HTML, JSON, CSS, JavaScript, and other text response bodies. Rules run from top to bottom.

Regex captures: \g<1> or \g<name>. Flags: i (ignore case), m (multiline), s (dot matches newlines). Literal mode uses text exactly as entered. Text responses are buffered up to 8 MiB; larger bodies, binary files, and event streams pass through.

Capture request and response headers and bodies, including credentials or cookies they contain. Visible only when signed in. Each body is capped at 64 KiB, each header set at 16 KiB. Keep up to 500 requests per device, 2,000 total, for 24 hours.

Anyone with the device URL can access this target. Self-signed HTTPS certificates on the target are accepted.