Deliver webhooks to services behind your firewall. No open inbound ports.
Stripe, GitHub, Twilio, and 70+ providers need to reach a service on your private network. ngrok verifies every signature at the edge and routes the event to your on-prem app over an outbound-only tunnel, so you stop polling and never expose a port.
One gateway. Every provider. Straight to your private network.
Run a lightweight agent next to the service that should receive the webhook. It dials out to ngrok on port 443. Providers deliver to your ngrok endpoint, a Traffic Policy verifies the signature, and the event lands on your on-prem app—with nothing exposed to the internet.
Signatures are verified at the edge for 70+ providers. Spoofed or tampered requests are rejected before they reach any of your compute.
Store provider secrets in an encrypted vault and reference them from a single Traffic Policy—no secrets scattered across services.
The agent dials out over port 443, so your on-prem Jenkins, CI server, or internal API receives events with no inbound firewall rule and no public IP.
Routing, verification, and secrets live in one place. Talk to an engineer
Add a new provider with a policy rule, not a new public endpoint—Stripe, GitHub, Bitbucket, Twilio, Slack, and dozens more through one gateway.
Route each provider to a different upstream on any protocol, all from the same agent configuration.
Why ngrok?
Stop polling and stop hitting API rate limits. Receive events the moment they happen instead of hammering a SaaS API on a timer.
No public endpoint to stand up or defend. Cloud webhook services still need your receiver on the internet. ngrok delivers into the private network directly.
One gateway for every provider. Verification, routing, and secrets sit in a single Traffic Policy instead of duplicated in each app.
Pass the audit before the webhook ever reaches you.
Regulated teams run ngrok in banks, healthcare systems, and Fortune 100 networks. Zero-trust controls apply to inbound webhooks the same way they apply to everything else.
Reject spoofed webhooks with cryptographic verification
Signatures from 70+ providers are validated at the edge. Tampered or replayed requests are dropped before they touch your compute—no verification code to maintain in every service.
No open inbound ports, ever
The agent makes outbound-only connections on port 443. Your receiver stays off the public internet, so there is no attack surface to scan and no DDoS target to defend.
Layer on IP restrictions, mTLS, and JWTs
Beyond signatures, add IP allowlists for provider ranges, mutual TLS, and JWT checks in the same Traffic Policy. Defense in depth on every inbound event.
Keep regulated payloads in-region
Pin traffic to specific ngrok regions to satisfy data residency requirements for PHI, PII, and other regulated webhook payloads.
All the boxes your security review needs
Don't drop the events you can't replay.
Providers won't always retry. Keep the gateway connected so a missed webhook doesn't become a missed deploy.
Reconnect automatically
The agent heartbeats its connection and recovers quickly after it sees connection reset by peer. so your gateway is back online before the next event fires.
See every event and its outcome
Inspect inbound webhooks, replay them during development, and export connection events to your telemetry platform so a delivery problem never goes unnoticed.
High availability with redundant agents
Run multiple agents next to your receiver and ngrok balances events among them. You keep receiving webhooks even when a machine running one agent fails.
Stay online during region outages
Agents connect to multiple regions of the ngrok cloud, so an entire datacenter can fail without taking your webhook gateway down with it.
From one webhook to your whole event pipeline.
Deploy the agent anywhere
The ngrok agent is a cross-platform, dependency-free binary pre-packaged for Docker, Kubernetes, Windows, Linux, and macOS—drop it next to any receiver.
Config, not code
Verification, routing, and secret handling are declared in a Traffic Policy. Add a provider or change a route without shipping a release to your receiver.
Automate the rollout
APIs for every feature and a Terraform provider let you stand up gateways and policies as code, across every environment and team.
Debug with full traffic inspection
Inspect the exact headers and payload of every inbound webhook, so you can see why a provider's delivery failed instead of guessing.
Need to self-host ngrok?
Inquire about private editionRoute your first provider to on-prem in 10 minutes.
No open ports. No upfront costs. Pay only for what you use.
