One cloud for your
Applications, Tunnels & API Gateway.
Deploy apps to the edge, tunnel what you already run, and put a policy engine — WAF, routing, rate limits, auth — in front of every request. Drafted by Iris AI, approved by you.
Builds and runs your stack
API gateway & secure tunneling — managed ingress.
No firewall changes, no open ports. Route, secure, and monitor every API and device from a single control plane.
One cloud. Every layer.
Deploy to the edge, tunnel a local service, or front an existing API — then chain WAF, routing, rate limits, traffic policy and per-endpoint auth on top, all from one control plane. No extra vendor to wire up, no glue code between layers. Iris AI drafts the rules; you approve them.
Production Gateways
Secure egress-only connectivity into Kubernetes clusters. No inbound firewall changes, no open ports — just a single outbound tunnel.
- Private cluster access with mTLS
- Per-endpoint auth & policy
- Works through NAT and firewalls
Expose Localhost
One command to get a public HTTPS URL pointed at your dev server. Perfect for demos, webhook testing, and mobile device previews. Expose localhost to the internet →
- Instant public URL on a custom domain
- Webhook capture & replay inspector
- Zero config TLS
Ask Iris. Approve. Done.
Describe what you want in plain English — Iris drafts the firewall, routing, or rate-limit rule, previews its blast radius against real traffic, and never applies anything without your approval.
- Plain English → policy rules
- Blast-radius dry-run before apply
- You approve every change
/api to 100/minManage your entire edge from your AI assistant
Ngris runs a hosted MCP server at mcp.ngris.com. Connect Claude Code, Claude Desktop, or any MCP client and drive the whole edge in plain language — expose ports, deploy sites, inspect & replay traffic, and configure policies. About 150 user-facing tools, and it can never do more than you can. Read the MCP docs →
- Claude Code, Claude Desktop & any MCP client
- OAuth 2.1 browser login or an API key
- User-facing scope only — no admin
One policy engine, every rule type
WAF, rate limits, routing, geo & IP rules, JWT auth — 17+ rule types applied at the edge before your origin sees a byte. Iris drafts them; you manage them here.
- 17+ rule types, one engine
- Per-route or account-wide
- Toggle or dry-run any rule
Deploy your app to the edge.
Push a repo or drop a folder — Ngris builds it, serves it over global HTTPS, and gives every deploy a shareable preview URL. No servers, no config, no agent. Built for the way AI writes code.
Push to deploy
Connect a GitHub or GitLab repo and every push auto-builds & ships. Or upload a build folder — either way you’re live in seconds.
Framework-aware builds
Vite, Next.js, Astro, SvelteKit, Nuxt, Gatsby, Angular, Hugo, Jekyll — auto-detected and built in an isolated sandbox, with live build logs you can tail.
A preview for every deploy
Each build gets its own unguessable preview URL to review before you promote — and rolling back to any version is an instant, atomic pointer flip.
Env vars & secrets
Per-app environment variables are injected into your build. Mark keys as secrets and they’re encrypted at rest — never shown again.
Edge policies included
Auth, firewall, rate limits, WAF, and a custom domain apply to your static app exactly like any other endpoint. One platform, one bill.
API-first deploys
One curl creates the app, uploads it, and returns a live URL — and Iris can drive the whole flow from chat. Read the guide →
Enterprise Edge Gateway & API Tunneling Platform
One dashboard for every layer — inspect traffic, tune policy, watch alerts, review security, and manage your team.
See & replay every request
Tail traffic live with full headers and body, search and redact secrets, then replay any call to any environment with header overrides — no local repro needed.
- Live tail, search & redact
- One-click replay with overrides
Alerts that reach you
Watch error rate, latency, cert expiry and rate-limit saturation. Cross a threshold and your team hears about it — in Slack, Teams, or a webhook.
- Threshold & anomaly monitors
- Slack, Teams & webhooks
Security posture at a glance
A live score with the checks that matter — WAF coverage, TLS/HSTS, MFA, anonymous access, audit retention — so gaps never hide.
- Continuous posture checks
- 90-day audit log
Your team, with real roles
Invite your team with granular RBAC — owner, admin, deploy, viewer — scoped per endpoint or account-wide, and every action lands in the audit log.
- Per-resource RBAC
- SSO enforcement & audit log
SSO & OAuth, built in
Connect Okta, Google, Microsoft Entra ID or GitHub over OIDC or SAML 2.0, with SCIM provisioning — no add-on tier, no extra vendor to wire up.
- OIDC & SAML 2.0
- SCIM provisioning
Enterprise-grade security, built in.
Every plan includes these security foundations — not as add-ons, but as defaults.
One API Gateway, Every Environment
From solo developers to infrastructure teams — secure tunneling and ingress for every workflow.
Webhook Development
Receive Stripe, GitHub, and Twilio events locally. Inspect payloads, debug signatures, and replay edge cases.
Kubernetes Ingress
Route external traffic into K8s clusters without exposing nodes. Egress-only agent model, zero inbound ports.
AI Gateway
Proxy LLM calls with PII redaction, caching, and automatic fallback across OpenAI, Anthropic, and local models.
Staging & Preview
Share secure links to in-progress work with SSO protection and short-lived URLs that expire automatically.
IoT & Edge
Connect remote devices and sensors through encrypted gateways with real-time traffic monitoring.
Static Egress IP
Route outbound traffic through a dedicated IP for third-party APIs that require allowlisting. Single-region or GeoDNS.
Debug in minutes, not days.
The Request Inspector captures inbound traffic with searchable payloads and lets you replay with overrides. Built-in redaction keeps secrets safe.
Full-text search
Search across headers and JSON bodies with regex support.
GDPR-friendly redaction
Automatic secret masking and retention controls (7–30 days).
Replay to dev/staging
Editable payloads and headers — replay to any environment.
Alerts to Slack/Teams
Get notified when requests fail or spike unexpectedly.
No paywall. No sales call.
A typical production setup elsewhere runs $50–200+/mo after add-ons. On Ngris, the same setup starts at $10/mo — everything included.
Popular guides & comparisons
Start with the task you came for — expose a local server, or see how Ngris stacks up against the tool you already use.
Expose localhost to the internet
Turn localhost:3000 into a public HTTPS URL in one command — open it on your phone or share it with a teammate, no port forwarding.
Put a custom domain on localhost
Point your own domain at a local or tunneled service with automatic HTTPS — a stable URL that survives restarts.
GuideTest webhooks with a public URL
Give Stripe, GitHub, or Shopify a public endpoint on your laptop, live-tail every delivery, and replay the ones that failed.
CompareNgris vs ngrok
The policy-first ngrok alternative: the same one-command workflow, plus a per-endpoint policy engine, dedicated ports/IPs, and Iris AI.
CompareNgris vs Cloudflare Tunnel
A cloudflared alternative without DNS + CDN lock-in — per-endpoint policy, dedicated ports/IPs, and a Kubernetes operator.
CompareNgris vs Vercel
Deploy a React or Vite front end — and run the backend on the same edge — behind a WAF, edge auth, and rate limits.
Simple, Transparent Pricing
Start free. Scale without surprise bills. Everything others charge extra for is included.
- 5 concurrent endpoints
- 10 tunnels
- 10 GB bandwidth / month
- 200K requests / month
- Unlimited custom domains
- RBAC included
- All protocols
- Community support
- 3-day log + audit retention
- 25 concurrent endpoints
- 100 tunnels
- 50 GB bandwidth / month
- 500K requests / month
- 5 custom domains + subdomains
- 5 dedicated TCP/UDP ports
- Up to 5 team members
- SSO & RBAC included
- Priority email support
- 15-day log retention
- Unlimited concurrent endpoints
- Unlimited tunnels
- Unlimited bandwidth
- Unlimited requests
- Unlimited custom domains
- 10 dedicated TCP/UDP ports
- Unlimited team members
- SSO & RBAC included
- All protocols
- Priority support (4h)
- 30-day log retention
Runs everywhere you deploy.
One egress-only agent for every OS and runtime, plus a REST API and OpenAPI spec to drive it from code.
brew install ngriscurl -fsSL https://ngris.com/install.sh | shwinget install Ngrisdocker pull ghcr.io/ngris-edge/ngrishelm install ngris-operator oci://ghcr.io/ngris-edge/charts/ngris-operatorhttps://api.ngris.comInstall & run in seconds.
Install the agent, authenticate once, and point it at a local port — you're live on the edge with TLS already terminated.
Install the agent
One egress-only binary for your OS — no daemon, no inbound ports.
brew install ngrisAuthenticate
Link the agent to your account, once.
ngris auth --browserRun a tunnel
Get a public HTTPS URL, then attach WAF, OAuth, and rate limits.
ngris http 3000$ brew install ngris $ ngris auth --browser ✓ Authentication successful $ ngris http 3000 --url myapp.ngris.io Status online Routing https://myapp.ngris.io → localhost:3000 Inspector https://dashboard.ngris.com/endpoints/myapp # other install targets curl -fsSL https://ngris.com/install.sh | sh winget install Ngris docker pull ghcr.io/ngris-edge/ngris
Everything else, answered.
Still stuck? The docs go deeper, or reach the team at sales@ngris.com.
Secure tunneling creates an encrypted connection between a local server and the Ngris edge, exposing your application via a public URL without opening firewall ports or configuring DNS. The Ngris agent establishes an outbound TLS connection to the edge, which routes inbound traffic to your local service. All traffic is encrypted end-to-end with automatic TLS termination.
Yes. Ngris hosts static sites and web apps on the edge with no server and no agent: upload a folder or connect a GitHub/GitLab repo, and Ngris auto-detects your framework (Vite, Next.js, Astro, SvelteKit, Hugo and more), builds it in an isolated sandbox, and serves it over global HTTPS. Every deploy gets a shareable preview URL, per-app environment variables and secrets, live build logs, and instant atomic rollback.
An API gateway is a reverse proxy between clients and backend services that handles routing, authentication, rate limiting, and observability. Ngris goes beyond traditional API gateways by adding live traffic inspection and replay, per-endpoint identity-aware access, a built-in WAF, static egress IPs, and AI-powered rule generation — all without managing infrastructure.
All agent-to-edge traffic is encrypted. Paid plans add SSO/OIDC, IP allowlists, per-endpoint policies, and audit logs. Redaction and retention controls keep captured data safe.
A real-time dashboard that captures every inbound request with full headers and body. You can search, filter, redact secrets, and replay requests to any environment.
Yes. Paid plans include custom subdomains and domains via automated DNS and ACME. Enterprise supports dedicated certificates and wildcard TLS.
A dedicated outbound IP address that all your outbound traffic routes through. This is useful when third-party APIs or services require IP allowlisting.
Yes. Ngris is designed for production workloads with multi-region redundancy, continuous monitoring, automatic TLS, and edge security. Run it as your primary ingress for APIs, webhooks, and microservices — or alongside your existing CDN and load balancer for layered observability. Enterprise plans include dedicated regions and priority support.
The Starter plan includes 5 concurrent endpoints, 100k requests per month, random subdomains, and a basic request inspector. No credit card required.
Ship faster with managed ingress.
Create an account and launch your first endpoint in under a minute. No config files, no credit card, no friction.