Piperace vs ngrok vs Cloudflare Tunnel vs localhost.run

Four ways to give something on your machine a public address: a control panel for localhost, the best-known tunnel, a free tunnel that wants your domain, and one line of SSH. Where each one fits, and where each one stops.

All four solve the same first problem — a URL on the internet that reaches a port on your machine — and then stop solving the same problems. What actually separates them is what happens after the URL exists: whether the address survives a reconnect, whether you can see the requests, whether you can put a password on the link, and how much of your own infrastructure has to exist first.

Comparison table

Criteria Piperace ngrok Cloudflare Tunnel localhost.run
What you run Nothing. Install the app, sign in, and the relays are ours. Nothing. Install the agent. cloudflared, plus a domain you have moved onto Cloudflare. Nothing — an SSH client you already have.
Getting a public URL A switch in the dashboard, or piperace http 3000 -d myapp. ngrok http 3000. A quick tunnel is one command; a named one needs DNS setup first. ssh -R 80:localhost:8080 localhost.run.
Address that stays the same Yes, on every plan including the free one: myapp-1a2b3c.piperace.fun comes back when you reconnect under the same name. One static domain on the free plan; more on paid plans. Yes, once it is a named tunnel on your own domain. Free URLs rotate. A stable one needs the paid plan.
Trusted HTTPS on your own machine Yes — https://myapp.local, real certificate, works offline, no mkcert. No. It is a tunnel, not a local certificate authority. No. No.
Seeing the requests Every request through piperace, readable, with replay — plus a proxy for traffic that does not go through a tunnel at all. Traffic Inspector with replay, and export to log services on paid plans. Logs, no request inspector. No inspector.
Password on a shared link Yes, on Pro. Enforced on the relay, so a visitor without the password never reaches your machine. Yes, through Traffic Policy on paid plans (OAuth, SAML, basic auth). Yes, through Cloudflare Access. No.
AI agents An MCP server in the app, and the same over HTTP for an agent on another machine. No. No. No.
Protocols HTTP/HTTPS, TCP, TLS. HTTP/HTTPS, TCP, TLS. HTTP/HTTPS, plus arbitrary TCP for clients running cloudflared. HTTP/HTTPS, and TCP wrapped in TLS on 443.
Your own domain Not yet. Yes, on paid plans. Required, and the whole point. Yes, on the paid plan.
Network Our own relays, a handful of regions. A global edge network. Cloudflare's entire network. A single service.
Platforms macOS, Linux, Windows — installer, Homebrew, npm, or a binary. Menu-bar app on macOS. Agent everywhere, plus SDKs for several languages and a Kubernetes operator. cloudflared everywhere, Docker and Kubernetes included. Anything with SSH.
Free plan One public link at a time. Local .local sites and request inspection are unlimited. A free tier with limits on endpoints and requests. Free, if you already have a domain on Cloudflare. Free with a rotating URL.
Paid Pro — $9/month or $79/year — takes it to ten public links at once and unlocks password-protected links. Several tiers, usage-based above the free one. No charge for the tunnel itself. A single paid plan for a stable domain.
Best for Building on localhost every day: local HTTPS, a link you can hand someone, and the requests in front of you. Production-adjacent tunnels with policies, teams and observability. Putting something permanently on the internet through a domain you own. Sharing one thing, once, from a machine you cannot install on.

Piperace

Piperace is a hosted service: you install the app, sign in, and the relays that carry your traffic are ours to run. Nothing to deploy, no DNS to configure, no server to keep alive.

It is also not only a tunnel, which is the part a comparison table flattens. The public link is one switch in a dashboard of your local apps; next to it are trusted https://myapp.local addresses that work with no internet at all, and a readable list of every request your apps make. The tunnel is what you reach for when somebody else has to see the thing — the rest is for the ninety per cent of the day when nobody does.

The address stays yours across reconnects on every plan, including the free one — reconnect as myapp and the same URL comes back. A password on a link is a Pro feature, and it is checked on the relay: a visitor who does not have it never reaches your machine. Agents get an MCP server, locally or over HTTP from another machine, which none of the others offer.

Where it stops, plainly: no custom domains yet, a handful of relay regions rather than a global edge, no SAML or team policies, and no SDKs or Kubernetes operator. If what you need is a tunnel inside production infrastructure, the next two are better answers than this one.

ngrok

ngrok is the best-known of the four and the most complete as a tunnel. Install the agent, run ngrok http 3000, and the URL is served from a global edge network. Its Traffic Policy system covers IP rules, rate limits, OAuth, OIDC, SAML, JWT and mTLS; its Traffic Inspector shows and replays requests; there are SDKs and a Kubernetes operator for putting tunnels inside other software.

The trade-off is that the interesting half is a paid product with usage-based pricing, and that its scope ends at the tunnel: it has nothing to say about the certificate on your own machine, because that is not the job it took.

Cloudflare Tunnel

Cloudflare Tunnel is free and runs on Cloudflare's network, which is a hard combination to argue with. A quick tunnel gives you a throwaway trycloudflare.com URL in one command; the real thing — a named tunnel on your own hostname, with Access policies in front of it — needs a domain you have already moved onto Cloudflare and a few minutes of DNS work.

That prerequisite is also the dividing line. If the goal is to publish something permanently through a domain you own, this is the cheapest good answer available. If the goal is to show a colleague a branch you are working on right now, a domain migration is a strange first step, and there is no request inspector waiting for you at the end of it.

localhost.run

localhost.run is the smallest thing that works: SSH remote forwarding, so there is nothing to install and no account to make. ssh -R 80:localhost:8080 localhost.run and you have an HTTPS URL. HTTP, HTTPS and TLS-wrapped TCP all pass through it.

Free URLs rotate, bandwidth is limited, and there is no way to look at the requests; a stable address needs the paid plan. On a locked-down machine where you cannot install software, none of that matters and nothing else on this list will help you.

Which one should you choose?

Piperace if localhost is where you spend your day: you want trusted local HTTPS, a link you can hand to someone in one click, a password on that link, and the requests readable while you work.

ngrok if the tunnel itself has to carry policy — SSO, mTLS, rate limits — or has to live inside your production stack through an SDK or Kubernetes.

Cloudflare Tunnel if you already own a domain on Cloudflare and want something exposed permanently, for free, behind Access.

localhost.run if you need to share one thing once, from a machine you are not allowed to install anything on.

Bottom line: ngrok and Cloudflare are answers to "how does the internet reach this port". Piperace is an answer to "how do I work on localhost all day" — the public link is one of the switches, not the whole product. Pick by which of those two questions you actually have.

Try piperace

A public HTTPS link for anything running on your machine, trusted https://myapp.local names without mkcert, and every request your apps make — switches in one dashboard. macOS, Linux and Windows.

Free to start · what the plans include

Comments

Nothing here yet. If any of this matched your experience — or did not — say so.

← Back to blog