Compare
Portlatch vs Cloudflare Tunnel, ngrok, playit.gg and Tailscale Funnel
All five put a service running at home online without a public IP. What sets them apart: the traffic they let through, and whether they decrypt it on the way.
- Never decrypted
- Any TCP port
- Based in the EU
At a glance
As of October 2026, from each service's own pages: the sources are at the bottom.
| Portlatch | Cloudflare Tunnel | ngrok | playit.gg | Tailscale Funnel | |
|---|---|---|---|---|---|
| What gets through | |||||
| Any TCP port, nothing for visitors to install | Yes | No 1 | Yes 2 | Premium | No 3 |
| UDP | No | No | No | Yes | No |
| Privacy | |||||
| HTTPS by name, never decrypted | Yes | No 4 | On request 5 | Premium | Yes |
| Visitor's real IP reaches your service | PROXY protocol, paid plans 6 | HTTP header | HTTP header, PROXY protocol on TCP | PROXY protocol | PROXY protocol |
| Based in the EU | Yes | No, US | No, US | No, US | No, Canada |
| Your names | |||||
| Choose your subdomain | From €3/month | No | From $10/month | From $3/month | No |
| Your own domain | From €3/month | Free, DNS on Cloudflare 7 | From $20/month | From $3/month | No |
| Dedicated IPv4, every port | €9/month | Not listed | Through sales | Not listed | No |
| Openness | |||||
| Free tier | Yes | Yes | Yes | Yes | Yes |
| Open-source agent | Yes, Apache-2.0 | Yes | No | Yes | Yes |
- 1Services other than HTTP need
cloudflaredon each visitor's machine. - 2TCP on ngrok's free plan requires a card on file.
- 3Funnel listens on ports 443, 8443 and 10000 only, for TLS traffic.
- 4Cloudflare terminates TLS at its edge for web hostnames. Other TCP services, reached with
cloudflared, pass through. - 5ngrok terminates TLS on HTTP endpoints, to inspect requests. End-to-end TLS isn't on Free or Hobbyist, and on request on Pay-as-you-go. Its TCP endpoints pass bytes through.
- 6Why not an HTTP header? Adding one means decrypting your traffic. PROXY protocol carries the visitor's IP in front of the encrypted stream instead; Caddy, Traefik, nginx and HAProxy read it.
- 7Keeping your DNS elsewhere takes a CNAME setup, on the Business plan and up.
Why prefer Portlatch
Any TCP port, nothing to install
SSH, a database, your NAS: people connect as they would to any server, with no client of ours.
Never decrypted, and still the visitor's IP
HTTPS and SSH stay encrypted from the visitor to your machine. On paid plans, the visitor's IP reaches your service through PROXY protocol.
Your names, from €3/month
Your own name on our domain, or your own domain. A dedicated IPv4 with every port, €9/month.
Made to stay online
Your address doesn't change and doesn't expire. The free tier carries 10 GB every 30 days.
A European service
Based in the EU, with servers in the EU: your data stays under EU law.
An agent you can audit
Open source, Apache-2.0, running in two minutes with Docker, Linux or Windows.
When to choose another one
Cloudflare Tunnel
Choose Cloudflare Tunnel if
You publish a website and want Cloudflare's CDN and firewall in front of it, your domain already uses Cloudflare's DNS, and you're fine with Cloudflare decrypting your traffic.
Choose Portlatch
For SSH, or anything you'd rather keep encrypted end to end.
ngrok
Choose ngrok if
You test webhooks or give a demo from your laptop: request inspection and replay are built for that. Its free tier is sized for development: 1 GB a month, and a warning page in front of browser visitors.
Choose Portlatch
For a service that stays online at home: 10 GB free every 30 days, your own domain from €3/month.
playit.gg
Choose playit.gg if
You need UDP: Portlatch carries TCP only.
Choose Portlatch
For anything you open in a browser: HTTPS routed by name from the free tier, where playit.gg asks for Premium.
Tailscale Funnel
Choose Tailscale Funnel if
You already run Tailscale and share one HTTPS service under your ts.net name: it's free and built in.
Choose Portlatch
For your own domain, a port other than 443, 8443 or 10000, or a name people remember.
Or run it yourself
A VPS with frp, rathole or WireGuard does the same job, and it's a fine setup if you enjoy running it. It takes a server at a few euros a month, its configuration, its security updates, and a public machine to keep an eye on.
Portlatch is that setup, run for you, with an agent you can audit.
Questions
Is Portlatch a Cloudflare Tunnel alternative?
Yes, for services you'd rather keep encrypted end to end, and for anything that isn't a website. Cloudflare Tunnel decrypts web traffic at its edge, and its visitors need cloudflared for anything but HTTP. Portlatch never decrypts, and any TCP port works with nothing installed on the visitor's side.
Is Portlatch an ngrok alternative for self-hosting?
Yes. ngrok is built for development: inspecting and replaying requests from your laptop. Portlatch is built for services that stay online at home: 10 GB every 30 days on the free tier, your own names from €3/month.
How can I check that you don't decrypt?
Look at the certificate your visitors get: open your address in a browser and compare its fingerprint with the certificate on your server. They're the same, because the TLS connection ends on your machine. If we decrypted, we would have to show a certificate of ours, with another fingerprint. SSH works the same way, with your server's host key. Our relay isn't open source, and this check doesn't need it.
Why doesn't Portlatch add an X-Forwarded-For header?
Because it would have to decrypt your traffic to do it: the header lives inside the encrypted HTTPS stream. Portlatch only reads the name the browser announces in clear, to route the connection. On paid plans, PROXY protocol carries the visitor's IP in front of the encrypted stream; Caddy, Traefik, nginx and HAProxy read it.
Sources (22), checked on 8 October 2026
- Cloudflare Tunnel: protocols
- Cloudflare: HTTP request headers
- Cloudflare: CNAME setup
- cloudflared on GitHub
- ngrok: pricing
- ngrok: free plan limits
- ngrok: dedicated IPs
- ngrok: TCP endpoints
- ngrok: TLS endpoints
- ngrok: FAQ
- ngrok: terms of service
- playit.gg: pricing
- playit.gg: Premium
- playit.gg: HTTPS tunnels
- playit.gg: PROXY protocol
- playit.gg: terms
- playit agent on GitHub
- Tailscale Funnel
- tailscale funnel command
- Tailscale on GitHub
- Cloudflare on Wikipedia
- Tailscale on Wikipedia
Cloudflare, ngrok, playit.gg and Tailscale are trademarks of their respective owners. Portlatch is not affiliated with them. Write to support@portlatch.eu if something here is out of date.