Your customers' APIs, databases, and internal tools live behind firewalls you don't control. ngrok gives your SaaS secure, scoped access without VPN setup, open ports, or VPC peering projects.
Your customer runs a lightweight agent behind their firewall. It dials out to ngrok on port 443 and gives you private endpoints to the APIs, databases, and services you're authorized to reach.
Customers run a lightweight agent that creates secure tunnels : outbound TLS connections from agents to the ngrok cloud on port 443.
Authorize connections with your choice of mTLS, IP restrictions, or JWTs . ngrok relays traffic from your cloud directly to the target service.
Connections from your cloud to ngrok are wrapped in mTLS by the ngrok Kubernetes Operator. Only your cluster can ping the URL, so there's no need for auth.
Not running in Kubernetes? We also support private URLs with our agent CLI and Go SDK. Talk to an engineer
Access more services on other protocols with one setup—DBs, web apps, IoT devices, and much more.
Expand from one to many customers with the same agent configuration and new private endpoints.
Customers can run an agent without networking projects. That shortens onboarding time and gets integrations live faster.
Keep customer networking out of your support queue. Your team focuses on product value instead of firewall tickets and peering issues.
One integration works for every enterprise topology. AWS, Azure, on-prem, and hybrid environments all use the same connection model.
Databricks evaluated 17 alternatives before choosing ngrok for secure ingress into customer environments across cloud and hybrid deployments.
The ngrok agent already runs in banks, healthcare systems, and Fortune 100 networks. Your customers' security teams have seen it before.
Tightly scope your access to the APIs and databases you need and not a single port or process more.
Terminate TLS in your customer's network at the upstream service or the ngrok agent. The ngrok cloud service only sees ciphertext.
Comply with data residency requirements by selecting the exact ngrok data centers used to relay your connections.
Agents operate with only the permissions you explicitly define. ACLs control which endpoints they can create and ensure strict separation across customer environments.
Send your customers a complete Q&A on how ngrok works and why it's secure.
Network failures are inevitable. Identify and recover from them automatically.
You can't control your customer's network. That's why the ngrok agent runs in the background and heartbeats its connection to recover quickly after it sees connection reset by peer.
Publish tunnel status and connection events to your telemetry platform. When a connection drops, you'll know before your customer does.
Run multiple agents in your customer's network and ngrok will balance connections among them. You'll stay connected even when a machine running one agent fails.
Agents create secure tunnels to multiple regions of the ngrok cloud service. You won't go down when entire datacenters fail ( cough, us-east-1, cough ).
The ngrok agent is a cross-platform, dependency-free binary pre-packaged for Docker, Kubernetes, Windows, Linux, and macOS.
Embed the agent directly in your application with an SDK for BYOC deployments where your software already runs in the customer environment.
APIs for every feature, a Terraform provider for IaC, and bot users plus wildcard domains to automate per-customer onboarding.
Brand your URLs, agent connect address, and dedicated IPs with your own domains so customers associate the connection with your product.
How teams give their product a secure path into customer environments without shipping a VPN.
No upfront costs. No contact sales. Pay only for what you use.
The spec-sheet view for connecting your SaaS into a customer's network. Where an alternative says "no," it's usually a consequence of its architecture, not a missing feature.
For a use-case-by-use-case breakdown, see our ngrok vs. Tailscale and ngrok vs. Cloudflare Tunnel comparisons.