> ## Documentation Index
> Fetch the complete documentation index at: https://ngrok.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Expose a Service with the ngrok Agent

> Commands for putting an HTTP, TCP, or TLS service online with the ngrok agent, from a random URL to a reserved domain with authentication in front of it.

Each example below starts an endpoint and forwards its traffic to a service you're already running.
They are all the same shape: `ngrok <protocol> <what to forward to>`, with flags for anything you want to change about the endpoint.
Before you begin, [install the Agent CLI](/docs/gateway/agent/install) and [add your authtoken](/docs/gateway/agent/authtokens).

## HTTP endpoint

The common case: a web app on a local port, reachable at a URL ngrok picks for you.
Serve your web app listening at port 8080 on a random public URL

```bash theme={null}
ngrok http 8080
```

## Pre-defined domain

Use a [reserved domain](/docs/gateway/domains/) so the URL survives restarts instead of changing each time.
Serve a web app on example.ngrok.app

```bash theme={null}
ngrok http 8080 --url https://example.ngrok.app
```

## Basic Auth

Put a username and password in front of the service without changing the service itself.
Secure your web app with a username + password

```bash theme={null}
ngrok http 80 --traffic-policy-file traffic-policy.yml
```

##### `traffic-policy.yml`

```yaml theme={null}
on_http_request:
  - actions:
      - type: basic-auth
        config:
          credentials:
            - username1:password1
            - username2:password2
```

## Forward to non-local

Point the agent at another host on the network, not just `localhost`.
Forward to a service not listening on localhost

```bash theme={null}
ngrok http 192.168.1.2:80
```

## Local HTTPS server

Forward to an upstream that already speaks HTTPS, rather than plain HTTP.
Forward to an upstream service listening for `https`

```bash theme={null}
ngrok http https://localhost:8443
```

## Forwarding to an IPv6 address

Forward to an upstream reachable only over IPv6.
The ngrok agent can also forward to IPv6 addresses

```bash theme={null}
ngrok http '[::1]:80' --url https://ipv6.example.com
```

```bash theme={null}
ngrok http 'https://[2001:db8::123.123.123.123]:8443' --url https://ipv6.example.com
```

## TCP endpoint

Expose anything that isn't HTTP, such as a database, SSH, or RDP.
Accept traffic to a non-HTTP service.

```bash theme={null}
ngrok tcp 22
```

## TLS endpoint

Accept TLS traffic and pass it through, for protocols wrapped in TLS that aren't HTTPS.
Listen on `your-name.ngrok.app` for TLS traffic.
It could be HTTPS, but any
protocol wrapped in TLS is accepted.

```bash theme={null}
ngrok tls 80 \
  --url tls://your-name.ngrok.app \
  --traffic-policy-file traffic-policy.yml
```

##### `traffic-policy.yml`

```yaml theme={null}
on_tcp_connect:
  - actions:
      - type: terminate-tls
```

## Multiple endpoints

Run several services from one agent by naming them in a configuration file.
Start multiple endpoints defined in the [configuration file](/docs/gateway/agent/config/).

```bash theme={null}
ngrok start foo bar baz
```
