Private connectivity that works across any cloud.
PrivateLink locks you into one cloud. VPC peering breaks when CIDRs overlap. ngrok gives you private, encrypted connectivity to customer networks across AWS, Azure, GCP, on-prem, and hybrid deployments.
Skip PrivateLink, VPC peering, and CIDR headaches.
Your customer runs a lightweight agent that creates an outbound tunnel to ngrok. You connect through private endpoints the same way whether they run in AWS, Azure, GCP, a data center, or all four.
Customers run a lightweight agent that creates secure tunnels: outbound TLS connections from agents to the ngrok cloud on port 443.
Authorize connections with your choice of mTLS, IP restrictions, or JWTs. ngrok relays traffic from your cloud directly to the target service.
Connections from your cloud to ngrok are wrapped in mTLS by the ngrok Kubernetes Operator. Only your cluster can ping the URL, so there's no need for auth.
Not running in Kubernetes? We also support private URLs with our agent CLI and Go SDK. Talk to an engineer
Access more services on other protocols with one setup—DBs, web apps, IoT devices, and much more.
Expand from one to many customers with the same agent configuration and new private endpoints.
Why ngrok?
One model across every environment. PrivateLink requires both sides in the same cloud; ngrok works across any cloud, on-prem, or hybrid.
No overlapping CIDR pain. ngrok uses its own addressing layer so overlapping customer networks are never a blocker.
Skip per-customer infrastructure sprawl. Avoid provisioning PrivateLink endpoints, peering, and account-specific networking for every customer.
Sail through the most rigorous security assessments.
The ngrok agent already runs in banks, healthcare systems, and Fortune 100 networks to deliver private connectivity.
Access a service, not your customer's whole network
Tightly scope your access to the APIs and databases you need and not a single port or process more.
Encrypt end-to-end with your own keys
Terminate TLS in your customer's network at the upstream service or the ngrok agent. The ngrok cloud service only sees ciphertext.
Restrict traffic regions for data residency
Comply with data residency requirements by selecting the exact ngrok data centers used to relay your connections.
Safe multi-tenancy with least-privilege agent ACLs
Agents operate with only the permissions you explicitly define. ACLs control which endpoints they can create and ensure strict separation across customer environments.
All the boxes you need to check
Your customers have questions.
We have answers.
Send your customers a complete Q&A on how ngrok works and why it's secure.
Check it outHit all the 9s in your SLA.
Network failures are inevitable. Identify and recover from them automatically.
Reconnect automatically
You can't control your customer's network. That's why the ngrok agent runs in the background and heartbeats its connection to recover quickly after it sees connection reset by peer.
Alert on issues before customers notice
Publish tunnel status and connection events to your telemetry platform. When a connection drops, you'll know before your customer does.
High availability with agent redundancy
Run multiple agents in your customer's network and ngrok will balance connections among them. You'll stay connected even when a machine running one agent fails.
Stay online during region outages
Agents create secure tunnels to multiple regions of the ngrok cloud service. You won't go down when entire datacenters fail (cough, us-east-1, cough).
Everything you need to productize and scale.
Prepackaged for every OS, Docker & Kubernetes
The ngrok agent is a cross-platform, lightweight, dependency-free executable. We've pre-packaged it to make distribution easy for you.
import ngrok
Embed the ngrok agent in your own code with an SDK if a sidecar isn't right for you. Great for when your software is already running in your customer's environment (like bring-your-own-cloud).
Automate everything with APIs
There's an API for every feature so it's easy to scale across all your customers. We've also integrated ngrok into the declarative IaC tools you use to manage the rest of your production infra.
White-label everything your customers see
Brand your URLs and the address the agent connects to with your own domains. You can assign them dedicated IPs, too.
Need to self-host ngrok?
Inquire about private editionReplace the PrivateLink sprawl with one connection model.
No upfront costs. No contact sales. Pay only for what you use.