Get Started
A public URL for what runs on your computer. lnk tunnel open gives
a web app, a model or anything else that speaks HTTP an address anyone
can reach, with nothing to set up on your router.
Needs: macOS or Linux, the tunnel plugin (lnk up tunnels, which
adds the accounts plugin for your login) and a GitHub account on
Local Link's invite list. It's free.
Quickstart
lnk up tunnels # add the tunnel and accounts plugins
lnk auth login # log in with GitHub
lnk tunnel open 3000 --name my-app --auth friend:secret # https://my-app.<you>.local.link -> localhost:3000
lnk tunnel status # your open tunnels, from every machineOpen a tunnel
lnk tunnel open 3000 --name my-app --public # anyone with the URL
lnk tunnel open 3000 --github alice,bob # only these GitHub accounts
LINK_AUTH=friend:secret lnk tunnel open 3000 # anyone with the passwordThe tunnel stays open until you stop the command. Any local web server
works, including Next.js and Vite dev servers with hot reload. If the
connection drops, lnk reconnects and keeps the same URL.
--name <app>sets the<app>in the URL. It's random otherwise. A secondlnkopening the same name takes it over, and the first stops.- You must pick one of
--public,--githuband--auth, so nothing goes public by accident.
Let in only some people
lnk tunnel open 3000 --name my-app --github alice,bobEach visitor signs in with GitHub in their browser, and only the accounts
you list get in. A sign-in lasts a day. To let someone in or out, open
the tunnel again with a new list; whoever is off it is cut off at their
next request. Programs without a browser can't sign in: give them a
tunnel with --auth.
Protect it with a password
LINK_AUTH=friend:secret lnk tunnel open 3000 --name my-app
curl -u friend:secret https://my-app.<you>.local.linkVisitors log in with that user and password (HTTP Basic). Set
LINK_AUTH rather than --auth. Use a long random password: everyone
shares it.
Expose a model
lnk tunnel open qwen3 --name qwen --auth friend:secretNeeds the models plugin too. See Share a Model.
See your tunnels
lnk tunnel statusYour open tunnels, from all your computers, with who can reach each.
Use another relay
lnk tunnel open 3000 --public --relay http://localhost:7080 # a local dev relay needs no login- To log in to another relay: Accounts.
--relay <url>orLINK_RELAYpicks the relay onopenandstatus. The default is the one you logged in to, elsehttps://local.link.--token <t>orLINK_TOKENpasses a token onopenandstatus. Prefer the variable.RUST_LOG=link=debuglogs more.
Running your own relay: Run the Relay.
Where things live
- Your login is the accounts plugin's: Accounts.
- Open tunnels live only in the running
lnkand the relay's memory.
Troubleshooting
| Symptom | Fix |
|---|---|
| "choose who can reach it" | Add --public, --github or --auth. |
| "the relay can't sign visitors in with GitHub" | Use --auth, or ask the relay's operator. |
| A visitor sees "Not let in" | Add their account to --github and reopen. |
| "not on this relay's invite list" | Ask the operator for an invite. |
| Next.js hot reload fails | Add allowedDevOrigins: ['*.local.link'] to next.config. |
| The visitor gets 502 | Start your server, or check the port. |
| "lnk … is available (you have …)" | lnk upgrade. |
Every flag: lnk tunnel <command> --help. Logging in:
Accounts.
What's protected, the limits and the gaps: Security. Why
it works this way: Decisions.
