Skip to main content
Private connectivity

Private connectivity that works across any cloud.

PrivateLink locks you into one cloud. VPC peering breaks when CIDRs overlap. ngrok gives you private, encrypted connectivity to customer networks across AWS, Azure, GCP, on-prem, and hybrid deployments.

  • Calendly
  • Cyera
  • Databricks
  • GitHub
  • Grafana
  • Harvey
  • Hugging Face
  • Mercor
  • Microsoft
  • Okta
  • Open AI
  • Perplexity
  • Ramp
  • Schneider Electric
  • Twilio
  • Vercel
  • Windsurf
  • Zoom
How it works

Skip PrivateLink, VPC peering, and CIDR headaches.

Your customer runs a lightweight agent that creates an outbound tunnel to ngrok. You connect through private endpoints the same way whether they run in AWS, Azure, GCP, a data center, or all four.

Diagram showing how traffic flows from your cloud through ngrok to customer networks

Customers run a lightweight agent that creates secure tunnels: outbound TLS connections from agents to the ngrok cloud on port 443.

Authorize connections with your choice of mTLS, IP restrictions, or JWTs. ngrok relays traffic from your cloud directly to the target service.

Diagram showing private addressability with the ngrok Kubernetes Operator wrapping connections in mTLS

Connections from your cloud to ngrok are wrapped in mTLS by the ngrok Kubernetes Operator. Only your cluster can ping the URL, so there's no need for auth.

Not running in Kubernetes? We also support private URLs with our agent CLI and Go SDK. Talk to an engineer

Diagram showing multiple services and endpoints connected through ngrok

Access more services on other protocols with one setup—DBs, web apps, IoT devices, and much more.

Expand from one to many customers with the same agent configuration and new private endpoints.

Why ngrok?

One model across every environment. PrivateLink requires both sides in the same cloud; ngrok works across any cloud, on-prem, or hybrid.

No overlapping CIDR pain. ngrok uses its own addressing layer so overlapping customer networks are never a blocker.

Skip per-customer infrastructure sprawl. Avoid provisioning PrivateLink endpoints, peering, and account-specific networking for every customer.

Replace the PrivateLink sprawl with one connection model.

No upfront costs. No contact sales. Pay only for what you use.

Frequently asked questions