New — Iris AI drafts your firewall, routing & rate-limit rules. Explore AI features →
The AI-native edge cloud

One cloud for your
Applications, Tunnels & API Gateway.

Deploy apps to the edge, tunnel what you already run, and put a policy engine — WAF, routing, rate limits, auth — in front of every request. Drafted by Iris AI, approved by you.

Builds and runs your stack

React Vite Vue Svelte Angular Astro Next.js· static Nuxt Hugo Docker Kubernetes

API gateway & secure tunneling — managed ingress.

No firewall changes, no open ports. Route, secure, and monitor every API and device from a single control plane.

One cloud. Every layer.

Deploy to the edge, tunnel a local service, or front an existing API — then chain WAF, routing, rate limits, traffic policy and per-endpoint auth on top, all from one control plane. No extra vendor to wire up, no glue code between layers. Iris AI drafts the rules; you approve them.

Production Gateways

Secure egress-only connectivity into Kubernetes clusters. No inbound firewall changes, no open ports — just a single outbound tunnel.

  • Private cluster access with mTLS
  • Per-endpoint auth & policy
  • Works through NAT and firewalls
Public Internet
nNgris cloud
Ngris Agent
App Pod
DB Pod

Expose Localhost

One command to get a public HTTPS URL pointed at your dev server. Perfect for demos, webhook testing, and mobile device previews. Expose localhost to the internet →

  • Instant public URL on a custom domain
  • Webhook capture & replay inspector
  • Zero config TLS
Clients
Webhooks
nNgris cloud
localhost:3000

Ask Iris. Approve. Done.

Describe what you want in plain English — Iris drafts the firewall, routing, or rate-limit rule, previews its blast radius against real traffic, and never applies anything without your approval.

  • Plain English → policy rules
  • Blast-radius dry-run before apply
  • You approve every change

One policy engine, every rule type

WAF, rate limits, routing, geo & IP rules, JWT auth — 17+ rule types applied at the edge before your origin sees a byte. Iris drafts them; you manage them here.

  • 17+ rule types, one engine
  • Per-route or account-wide
  • Toggle or dry-run any rule

Deploy your app to the edge.

Push a repo or drop a folder — Ngris builds it, serves it over global HTTPS, and gives every deploy a shareable preview URL. No servers, no config, no agent. Built for the way AI writes code.

Push to deploy

Connect a GitHub or GitLab repo and every push auto-builds & ships. Or upload a build folder — either way you’re live in seconds.

Framework-aware builds

Vite, Next.js, Astro, SvelteKit, Nuxt, Gatsby, Angular, Hugo, Jekyll — auto-detected and built in an isolated sandbox, with live build logs you can tail.

A preview for every deploy

Each build gets its own unguessable preview URL to review before you promote — and rolling back to any version is an instant, atomic pointer flip.

Env vars & secrets

Per-app environment variables are injected into your build. Mark keys as secrets and they’re encrypted at rest — never shown again.

Edge policies included

Auth, firewall, rate limits, WAF, and a custom domain apply to your static app exactly like any other endpoint. One platform, one bill.

API-first deploys

One curl creates the app, uploads it, and returns a live URL — and Iris can drive the whole flow from chat. Read the guide →

Enterprise Edge Gateway & API Tunneling Platform

One dashboard for every layer — inspect traffic, tune policy, watch alerts, review security, and manage your team.

Observability

See & replay every request

Tail traffic live with full headers and body, search and redact secrets, then replay any call to any environment with header overrides — no local repro needed.

  • Live tail, search & redact
  • One-click replay with overrides
Live Inspectortailing · 1.2k/min
GET/api/users?page=220012msReplay
POST/login4038msReplay
POST/v1/inference200214msReplay
GET/checkout20021msReplay
DEL/sessions/8f2a2049msReplay
Monitoring

Alerts that reach you

Watch error rate, latency, cert expiry and rate-limit saturation. Cross a threshold and your team hears about it — in Slack, Teams, or a webhook.

  • Threshold & anomaly monitors
  • Slack, Teams & webhooks
Alerts4 monitors · 1 firing
5xx error rate > 1%firing · 2.3%
p95 latency > 500mswarn · 480ms
TLS cert expiry < 14 daysok · 68d
Rate-limit saturationok · 34%
New alertSlack · Teams · webhook
Posture

Security posture at a glance

A live score with the checks that matter — WAF coverage, TLS/HSTS, MFA, anonymous access, audit retention — so gaps never hide.

  • Continuous posture checks
  • 90-day audit log
Security overviewscore 92 / 100
WAF enabled on all endpoints
TLS 1.3 & HSTS enforced
MFA required for all admins
2 endpoints allow anonymous accessreview
Audit log · 90-day retention
Access

Your team, with real roles

Invite your team with granular RBAC — owner, admin, deploy, viewer — scoped per endpoint or account-wide, and every action lands in the audit log.

  • Per-resource RBAC
  • SSO enforcement & audit log
Members5 · RBAC
AKAda KesslerOwner
JSJon SilvaAdmin
MRMia ReyesDeploy
TOTheo OkaforViewer
Invite memberroles · SSO · audit log
Identity

SSO & OAuth, built in

Connect Okta, Google, Microsoft Entra ID or GitHub over OIDC or SAML 2.0, with SCIM provisioning — no add-on tier, no extra vendor to wire up.

  • OIDC & SAML 2.0
  • SCIM provisioning
Single Sign-On1 connected
Okta · SAML 2.0Connected
Google WorkspaceConnect
Microsoft Entra IDConnect
GitHubConnect
OIDC · SAML 2.0 · SCIM provisioning

Enterprise-grade security, built in.

Every plan includes these security foundations — not as add-ons, but as defaults.

TLS 1.3
Modern encryption on every tunnel, terminated at the edge with automatic certs.
Encrypted at Rest
AES-256 for volumes and envelope-encrypted secrets across the platform.
MFA / 2FA
Multi-factor authentication for accounts, with SSO enforcement options.
Audit Logs
Immutable trail of access and config changes across your org.
SSO / SAML
OAuth & SAML with Google, GitHub, Azure, and Okta on paid plans.
GDPR / CCPA
DPA available, secret redaction, and retention controls for captured data.

One API Gateway, Every Environment

From solo developers to infrastructure teams — secure tunneling and ingress for every workflow.

Webhook Development

Receive Stripe, GitHub, and Twilio events locally. Inspect payloads, debug signatures, and replay edge cases.

Kubernetes Ingress

Route external traffic into K8s clusters without exposing nodes. Egress-only agent model, zero inbound ports.

AI Gateway

Proxy LLM calls with PII redaction, caching, and automatic fallback across OpenAI, Anthropic, and local models.

Staging & Preview

Share secure links to in-progress work with SSO protection and short-lived URLs that expire automatically.

IoT & Edge

Connect remote devices and sensors through encrypted gateways with real-time traffic monitoring.

Static Egress IP

Route outbound traffic through a dedicated IP for third-party APIs that require allowlisting. Single-region or GeoDNS.

Debug in minutes, not days.

The Request Inspector captures inbound traffic with searchable payloads and lets you replay with overrides. Built-in redaction keeps secrets safe.

Full-text search

Search across headers and JSON bodies with regex support.

GDPR-friendly redaction

Automatic secret masking and retention controls (7–30 days).

Replay to dev/staging

Editable payloads and headers — replay to any environment.

Alerts to Slack/Teams

Get notified when requests fail or spike unexpectedly.

Request Inspector
POST/api/webhook200128ms
POST/api/data20164ms
GET/api/users?page=220031ms
PATCH/api/config42912ms
DELETE/sessions/8f2a2049ms
GET/healthz2003ms

No paywall. No sales call.

A typical production setup elsewhere runs $50–200+/mo after add-ons. On Ngris, the same setup starts at $10/mo — everything included.

$8/mo
Others — base
A handful of endpoints, limited bandwidth, no WAF, no SSO, no custom domains. Basic auth only.
$50+/mo
Others + add-ons
Same features as Ngris Team: base plan + WAF add-on + SSO per-user fee + custom domains + support tier.
WAF · SSO/SAML · Custom TLS · OAuth · RBAC · Inspector · Replay · Static egress — all included. No interstitial pages. Never.

Simple, Transparent Pricing

Start free. Scale without surprise bills. Everything others charge extra for is included.

Developer
Free plan for personal use
$0 / month
Billed yearly ($0/yr)
  • 5 concurrent endpoints
  • 10 tunnels
  • 10 GB bandwidth / month
  • 200K requests / month
  • Unlimited custom domains
  • RBAC included
  • All protocols
  • Community support
  • 3-day log + audit retention
Get Started
Team
Professional plan with higher limits
$10 / month
Billed yearly ($90/yr)
  • 25 concurrent endpoints
  • 100 tunnels
  • 50 GB bandwidth / month
  • 500K requests / month
  • 5 custom domains + subdomains
  • 5 dedicated TCP/UDP ports
  • Up to 5 team members
  • SSO & RBAC included
  • Priority email support
  • 15-day log retention
Choose Team
No credit cardFree forever plan14-day trial on paid plansCancel anytime
Add-ons & Extras
$10/mo per IP
Dedicated IP
A stable IP for your endpoint — single region, or per-region GeoDNS. One-time setup fee.
from $5/mo
Extra Data & Requests
Scale beyond plan limits without changing tiers.
$20/mo
Extended Retention
Keep inspector data 30 days instead of plan-default retention.
Custom
Dedicated Region
Isolated edge capacity in the region of your choice. Enterprise.

Runs everywhere you deploy.

One egress-only agent for every OS and runtime, plus a REST API and OpenAPI spec to drive it from code.

macOS
brew install ngris
Native binary for Apple Silicon & Intel.
Linux
curl -fsSL https://ngris.com/install.sh | sh
Static binary; systemd unit for long-running tunnels.
Windows
winget install Ngris
Signed installer, or a portable single executable.
Docker
docker pull ghcr.io/ngris-edge/ngris
Sidecar image — drop the agent into any compose stack.
Kubernetes
helm install ngris-operator oci://ghcr.io/ngris-edge/charts/ngris-operator
Operator & CRDs — egress-only tunnel from your cluster, zero inbound ports.
REST API
https://api.ngris.com
OpenAPI 3 — manage endpoints, domains & firewall as code. Terraform-ready.

Install & run in seconds.

Install the agent, authenticate once, and point it at a local port — you're live on the edge with TLS already terminated.

1

Install the agent

One egress-only binary for your OS — no daemon, no inbound ports.

macOSbrew install ngris
2

Authenticate

Link the agent to your account, once.

ngris auth --browser
3

Run a tunnel

Get a public HTTPS URL, then attach WAF, OAuth, and rate limits.

ngris http 3000
Terminal
$ brew install ngris
$ ngris auth --browser
  ✓ Authentication successful

$ ngris http 3000 --url myapp.ngris.io

  Status     online
  Routing    https://myapp.ngris.io  localhost:3000
  Inspector  https://dashboard.ngris.com/endpoints/myapp

  # other install targets
  curl -fsSL https://ngris.com/install.sh | sh
  winget install Ngris
  docker pull ghcr.io/ngris-edge/ngris

Everything else, answered.

Still stuck? The docs go deeper, or reach the team at sales@ngris.com.

Platform & features

Secure tunneling creates an encrypted connection between a local server and the Ngris edge, exposing your application via a public URL without opening firewall ports or configuring DNS. The Ngris agent establishes an outbound TLS connection to the edge, which routes inbound traffic to your local service. All traffic is encrypted end-to-end with automatic TLS termination.

Yes. Ngris hosts static sites and web apps on the edge with no server and no agent: upload a folder or connect a GitHub/GitLab repo, and Ngris auto-detects your framework (Vite, Next.js, Astro, SvelteKit, Hugo and more), builds it in an isolated sandbox, and serves it over global HTTPS. Every deploy gets a shareable preview URL, per-app environment variables and secrets, live build logs, and instant atomic rollback.

An API gateway is a reverse proxy between clients and backend services that handles routing, authentication, rate limiting, and observability. Ngris goes beyond traditional API gateways by adding live traffic inspection and replay, per-endpoint identity-aware access, a built-in WAF, static egress IPs, and AI-powered rule generation — all without managing infrastructure.

All agent-to-edge traffic is encrypted. Paid plans add SSO/OIDC, IP allowlists, per-endpoint policies, and audit logs. Redaction and retention controls keep captured data safe.

A real-time dashboard that captures every inbound request with full headers and body. You can search, filter, redact secrets, and replay requests to any environment.

Networking, plans & production

Yes. Paid plans include custom subdomains and domains via automated DNS and ACME. Enterprise supports dedicated certificates and wildcard TLS.

A dedicated outbound IP address that all your outbound traffic routes through. This is useful when third-party APIs or services require IP allowlisting.

Yes. Ngris is designed for production workloads with multi-region redundancy, continuous monitoring, automatic TLS, and edge security. Run it as your primary ingress for APIs, webhooks, and microservices — or alongside your existing CDN and load balancer for layered observability. Enterprise plans include dedicated regions and priority support.

The Starter plan includes 5 concurrent endpoints, 100k requests per month, random subdomains, and a basic request inspector. No credit card required.

Ship faster with managed ingress.

Create an account and launch your first endpoint in under a minute. No config files, no credit card, no friction.

Sign Up Free View Docs
Ask an AI to summarise this page
Iris