Download
Download the agent
v1.0.1 Open source, Apache-2.0 Source on GitHub
-
1
Start the container
Docker picks the image for your machine. The volume keeps the agent's identity across updates.
docker run -d \ --name portlatch-agent \ --restart unless-stopped \ -v portlatch:/.data \ portlatch/portlatch-agent:latest
-
2
Read the code
The agent prints an eight-character code, then waits for your approval.
docker logs -f portlatch-agent
-
3
Approve it in your dashboard
Type the code and name the machine. The tunnel comes up a few seconds later: add your first route.
Create a free account first, or log in.
-
1
Download the archive
Without Docker: in a Proxmox LXC container, on a minimal Raspberry Pi.
curl -LO https://github.com/portlatch/portlatch-agent/releases/latest/download/portlatch-agent_linux_amd64.tar.gz
On a Raspberry Pi, replace
amd64witharm64for a 64-bit system, orarmv7for a 32-bit one. -
2
Install the program and its service
The service runs as an unprivileged user created for it alone, and keeps its data in
/var/lib/portlatch-agent. The code shows in its logs.tar -xzf portlatch-agent_linux_*.tar.gz sudo install -m 0755 portlatch-agent /usr/local/bin/ sudo install -m 0644 portlatch-agent.service /etc/systemd/system/ sudo systemctl enable --now portlatch-agent journalctl -u portlatch-agent -f
-
3
Approve it in your dashboard
Type the code and name the machine. The tunnel comes up a few seconds later: add your first route.
Create a free account first, or log in.
-
1
Download and unzip
Put
Download for Windowsportlatch-agent.exein a folder where it will stay: the service runs it from there. -
2
Enrol it from an administrator PowerShell
The code shows in the window. Once you approve it, the agent installs itself as a service that starts with Windows.
cd "C:\Program Files\Portlatch" .\portlatch-agent.exe enrol
The program isn't signed yet: if SmartScreen stops it, choose More info, then Run anyway.
-
3
Approve it in your dashboard
Type the code and name the machine. The tunnel comes up a few seconds later: add your first route.
Create a free account first, or log in.
Also runs on Raspberry Pi Proxmox Anything Go builds for, from source
Through Docker on Synology QNAP Unraid TrueNAS OpenMediaVault
Updating
Nothing updates the agent behind your back. Your dashboard shows “Update available” once a newer version is out, and older versions keep working meanwhile.
How to updateWhat it needs
Outgoing UDP for the tunnel, outgoing HTTPS for the dashboard. Nothing incoming, nothing to open on your router.
When it doesn't connectWhat it tells us
A heartbeat every 30 seconds with its version and platform. Nothing about your machine, your network or your traffic.
Read the source