Frequently asked questions

Getting started

What is Portlatch?

Portlatch makes a service running at home reachable from the internet, even when your provider won't let you open a port.

You install a small agent on your network, pick a port or a name in your dashboard, and visitors reach your machine through an encrypted tunnel.

Do I need it?

If you can't open a port on your router, yes. That's the case behind CGNAT, which is common with Starlink, 4G/5G boxes, DS-Lite lines, many regional providers and shared building connections. It's also the case when the router simply isn't yours.

If you have a public IPv4 and can forward ports, you may not need us. You'd still keep your home IP address out of sight: visitors only see ours.

How does it work?

The agent opens a WireGuard tunnel from your network to one of our servers, which has a public IPv4 address. When a visitor connects to your address, our server sends the connection down the tunnel, and the agent hands it to the machine you chose.

nas.portlatch.com:2222 → our server → tunnel → 192.168.1.42:22

The tunnel is started from your side, so it goes through CGNAT, and it comes back by itself if your connection drops or your IP address changes.

Do I need to open anything on my router?

No. The agent only makes outgoing connections, which every home router allows. Nothing to open, nothing to configure.

What can I expose?

Anything that speaks TCP: a website, SSH, Home Assistant, a NAS (Synology, QNAP, Unraid, TrueNAS…), your own film library on Jellyfin or Plex, your photos on Immich or Nextcloud, a game server that runs over TCP (Minecraft Java, for instance), remote desktop, the app you're working on.

The target doesn't have to be the machine running the agent. Any device the agent can reach on your network works: your NAS, a camera, another computer.

Is it for permanent use, or just for a quick test?

Portlatch is made to run all the time. The agent runs as a service, the tunnel comes back by itself after a reboot or a dropped connection, and your address stays the same for as long as you keep the route. There's no session to keep open and no random URL that changes each time.

It works just as well for a short need: create a route for a demo or a webhook test, then pause it or delete it.

Is it a VPN?

No. Traffic only flows one way: from the internet to the services you chose. Only the ports you publish are reachable. The rest of your network stays closed, to visitors and to us.

Can you read my traffic?

Not what's encrypted, and that's almost everything: HTTPS and SSH stay encrypted end to end, between the visitor and your machine. We pass bytes along without decrypting them.

And you don't have to take our word for it: the agent, the part that runs on your network, is open source. You can read exactly what it does with your traffic.

Plain protocols (HTTP without TLS, FTP) travel as they are, like anywhere on the internet. Use their encrypted version.

Is there really a free plan?

Yes. 1 route, 10 GB of traffic every 30 days, no credit card and no time limit. It's enough to reach your NAS, your Home Assistant or your SSH from anywhere.

Watching your own films from Jellyfin or Plex, or syncing your photo library to Immich or Nextcloud, takes more: that's what Turbo is for, with 1 TB and up to 100 Mbit/s.

Routes

Port forward or web route: which one should I pick?

It depends on one thing: does it open in a browser?

  • Yes → a web route. You get https://nas.portlatch.com, with no port number. It carries HTTP and HTTPS.
  • No → a port forward. You get nas.portlatch.com:2222, and it carries any TCP protocol: SSH, games, remote desktop, databases…

Both count toward the same route limit of your plan.

What address will my visitors use?

Every route has a name under portlatch.com. On the Free plan it's generated, like a1b2c3.node-x-1.portlatch.com. On paid plans you pick it, like nas.portlatch.com.

A web route is reached by its name alone. A port forward by its name and its port.

Can I choose my public port?
  • Free: no, it's assigned for you, between 10000 and 65535.
  • Pro and Turbo: yes, any port that is still free on at least one of our shared addresses.
  • Dedicated: yes, any port, guaranteed, on an IP address that is yours alone.

The port on your side is always yours to choose: a visitor on port 2222 can land on port 22 of your machine.

Why is port 22 already taken?

On a shared address, a port can only belong to one customer, and 22 is the one everybody wants. SSH doesn't announce a name before it talks, so we can't share the port the way web routes do.

Pick another port (SSH works on any), or take the Dedicated plan: every port of your own IP address is yours.

Why can't I reserve port 80 or 443?

On our shared addresses, 80 and 443 belong to web routes. Everyone shares them, and we tell visitors apart by the name their browser asks for. That's how every plan, Free included, gets https:// with no port number.

On a dedicated IP address, 80 and 443 are yours like any other port.

Which ports are blocked?

25, 465, 587, on every plan. They carry email, and an open mail relay would get our addresses blacklisted for everyone.

Can I choose my hostname?

On paid plans, yes: yourname.portlatch.com, 3 to 32 characters, lowercase letters, digits and hyphens. A few names are reserved (www, mail, admin, anything starting with node-…).

On the Free plan, the name is generated for you.

Can one name carry several routes?

Yes: as many port forwards as you like, and one web route. nas.portlatch.com can serve your website, nas.portlatch.com:2222 your SSH and nas.portlatch.com:8123 your Home Assistant.

Can I use my own domain?

Yes, from the Pro plan, on web routes. Click Domains on the route in your dashboard, add nas.example.com, then create a CNAME record at your DNS provider, from that name to the route's name on portlatch.com. We look for it every minute: as soon as we see it, your domain answers. Up to 5 domains per web route.

  • Still pending? The record must be a CNAME to the route's exact name. An address (A record) doesn't count, and neither does a proxy that hides the CNAME: on Cloudflare, turn the proxy off (grey cloud). A domain still pending after a day is removed; add it again once the record is set.
  • Subdomains only, like nas.example.com: a root domain like example.com can't carry a CNAME.
  • A domain routes to one web route only. If it's on someone else's route and you point it to yours, it moves to yours.

Your machine then gets a certificate for your domain, the same way as for your Portlatch name.

Can I pause a route?

Yes. Suspend it from your dashboard: it stops answering, and keeps its name and port. Reactivate it whenever you want, as long as your plan still has room for it.

What happens when I delete a route?

It stops at once. Its port is released right away and can go to someone else.

Its name stays yours for 90 days, unless another of your routes still uses it: nobody else can take it, and you get it back by typing it again for a new route. After that, anyone can. If one of your own domains pointed at it, remove that CNAME now.

Will my service see the visitor's real IP? (PROXY protocol)

The agent always knows the visitor's real IP address. Your service, though, sees the agent's address, because the agent opens the connection to it.

To pass the real IP along, turn on PROXY protocol on the route (paid plans). The agent then adds a small header at the start of each connection. Only turn it on if your service reads it: nginx, HAProxy, Traefik and Caddy can. SSH, most NASes and game servers can't, and will refuse the connection.

Why does my route say "pending" or "offline"?
  • Pending: the route is being set up on our server and on your agent. It takes a few seconds, up to a minute. A new chosen name can take a few minutes more, the time for DNS to follow.
  • Offline: your agent hasn't checked in for two minutes. Check that it's running and that your machine is online.

HTTPS & certificates

Do you handle HTTPS for me?

No: we never see your data. We don't decrypt anything. The encryption runs from the visitor's browser all the way to your machine, and we don't hold any key. Our server reads the name the browser announces, picks your tunnel, and passes the bytes along without being able to read them.

So it's your machine that shows the certificate, for your Portlatch name. Getting one is free and works like on any server: see below.

How do I get a certificate for my Portlatch name?

With Let's Encrypt, like any web server, using the HTTP or TLS-ALPN challenge. The order matters:

  • Create the web route first, and point it at your machine.
  • Then ask for the certificate (certbot, Caddy, Traefik, Nginx Proxy Manager…).

Without the route, Let's Encrypt can't reach your machine to check the name. Port 80 of a web route always stays open for that reason: renewals go through it.

Why does my browser say "not secure"?

Your machine isn't showing a valid certificate for the name the browser asked for: none at all, a self-signed one, or one for another name like nas.local. The connection still works, the browser just warns. Get a certificate for the exact name of the route, or of your domain, and the warning goes away.

Your dashboard tells you which certificate each name presents: see below.

What does the certificate check in my dashboard mean?

Every hour, we connect to each name of your web routes from the internet, like a visitor would, and read the certificate your machine presents. We only read it: nothing changes on your side. Check now runs it at once. It never changes how your route or your domains work: it only tells you what visitors will see.

  • Valid: all good.
  • Expiring soon: it expires in less than 14 days. Check that renewal works; it goes through port 80 of the route.
  • Wrong name: the certificate is for another name, like nas.local. Ask for one for the exact name.
  • Domain only, in gray, on the Portlatch name: your certificate covers your own domain, not this name. Fine if you only use your domain; otherwise, one certificate can carry both names.
  • Self-signed or Untrusted: browsers don't trust who signed it. Use Let's Encrypt.
  • Expired: renew it.
  • No HTTPS: your service answers in plain HTTP, or the route only has its HTTP port.
  • Unreachable: nothing answered on HTTPS. Check that your service runs and listens on the target port.
Why can't I use a DNS challenge?

It would mean writing into our DNS zone, which stays closed to customers. The HTTP and TLS-ALPN challenges work instead, through your web route.

The agent

Where can I run it?

Anywhere Docker runs, on amd64, arm64 and armv7: a NAS, a server, a Raspberry Pi. Without Docker, as a single Linux program with its systemd service, or on Windows 10 and 11 as a service. It needs no system dependency, and builds from source with Go for anything else.

Everything is on the download page.

How do I install it?

Start the agent, with no settings at all. It prints a code. Type that code in your dashboard, name the machine, and the tunnel comes up a few seconds later. The download page has the commands for Docker, Linux and Windows.

Keep its data folder: it holds the agent's identity. Without it, every restart asks for a new code. With Docker, that's the volume of the command; the Linux service and Windows keep it for you.

Where do I find the code to type?

In the agent's logs: docker logs with Docker, journalctl -u portlatch-agent for the Linux service, the PowerShell window on Windows. On a NAS, where logs are hard to reach, it's also written to enrolment.txt in the agent's data folder. The file disappears once the agent is approved. A code is valid for 15 minutes.

Does it need root or a privileged container?

No. The tunnel runs inside the agent itself: no root, no kernel module, no network interface added to your machine. It works in a plain, unprivileged container. On Windows, installing the service asks for administrator rights.

Does my private key ever leave my machine?

Never. The agent creates its WireGuard key on your machine and only sends us the public half. You can check it in the source code.

The agent keeps two secrets in its data folder: that private key, for the tunnel, and an API token, for talking to us. On Linux and in Docker, they're readable by their owner only; on Windows, they take the permissions of C:\ProgramData\Portlatch. Treat that folder like a password. Anyone who copies it can take the agent's place and receive the traffic of its routes. If it leaks, or the machine is lost or sold, delete the agent from your dashboard: both secrets stop working at once.

Is the agent open source?

Yes, under the Apache 2.0 license, on GitHub. It's the part that runs on your network, so you should be able to read it. It's kept small, so it's easy to audit.

Can I run several agents?

Yes, as many as you like: one per network, one per machine, as you prefer. Your plan's speed and traffic are shared between them.

My agent doesn't connect. What should I check?

The agent needs to send outgoing UDP to our server, and outgoing HTTPS to the dashboard. Home connections allow both. Some office networks and a few mobile plans block outgoing UDP, and then the tunnel can't come up.

Also check the agent's logs: an agent deleted from the dashboard stops with a clear message.

What happens if my connection drops or my IP changes?

Nothing to do. The tunnel comes back by itself, after a power cut, a router restart, a new IP address or a switch to 4G.

How do I remove an agent?

Delete its routes first, then the agent, from your dashboard. The tunnel is cut and the agent's access is revoked at once: even a copy of it can't reconnect.

How do updates work?

We never update your agent for you: it runs on your machine, you decide. Older versions keep working, and your dashboard shows Update available next to an agent once a newer version is out.

Docker: bridge or host network?

Bridge, Docker's default, is enough to reach the other machines of your network: the agent goes through the host.

To reach a service on the agent's own machine through 127.0.0.1, start the container with --network host: in bridge, 127.0.0.1 is the container itself. Host networking is native on Linux; on Docker Desktop, turn it on in the settings first.

Traffic & speed

How much traffic do I get?

10 GB on Free, 200 GB on Pro, 1 TB on Turbo and Dedicated. It counts both directions, for your whole account, over the last 30 days: there's no reset on the 1st of the month, old traffic simply rolls out.

What happens when I reach my quota?

Nothing is cut. A banner and an email warn you at 80%. At 100%, your account slows down to 2 KB/s: your agent stays connected and your routes stay up, just very slowly. Full speed comes back once your usage falls under 90%, and the dashboard shows the expected date. Upgrading lifts the limit at once.

How fast is it?

Up to 10 Mbit/s on Free, 50 Mbit/s on Pro, 100 Mbit/s on Turbo and Dedicated, for your whole account.

Where can I see my usage?

In your dashboard: live graphs for each agent and each route, and your 30-day total on the Billing page.

Where are your servers?

In the European Union. Everything runs in Europe: our servers, your data, the company. More regions may come later.

Plans & billing

Can I change plans at any time?

Yes, both ways, from the Billing page, whenever you like. Going up is paid at once, minus what is left of your current period, and takes effect at once. Going down takes effect at once too: what is left of your period is credited on your next invoices, and your routes are suspended, so you reactivate the ones your new plan has room for.

Dedicated comes with its own IP address, taken the moment you pay. When none is left, the plan shows as sold out and you stay where you are: you never pay for an address we don't have.

How do I upgrade?

From the Billing page, by card. The new limits apply at once.

Monthly or yearly?

Both. Paying yearly gets you 2 months free on Pro, 2 on Turbo and 1 on Dedicated. You can switch from one to the other on the Billing page.

Is VAT included?

There is no VAT to add: the price you see is the price you pay.

What happens if I downgrade?

Your routes are suspended, not deleted, and you reactivate the ones your new plan has room for. Your chosen names stay yours. Going down to Free, your own domains are removed.

Leaving Dedicated, your IP address is released at once, and the routes on it are deleted. Only a payment that fails keeps it for you 7 days: pay again within that time and you get the same one.

How do I cancel? Can I get an invoice?

Cancel from the Billing page at any time: your plan runs until the end of the period you paid for, then your account goes back to Free. Nothing is paid back, and you can resume your plan until then. Your invoices are on the same page.

Account & privacy

How do I change my password?

From My account: we email you a link to set a new one. Logged out? Use Forgot password on the login page.

Can I turn on two-factor authentication?

Yes, and we recommend it: your account opens your network to the internet, so a stolen password could expose your router's admin page, your NAS or your cameras. Two-factor authentication means the password alone is not enough.

Turn it on from My account with any authenticator app (Aegis, 2FAS, Bitwarden, 1Password…). You also get recovery codes, in case you lose your phone.

How do I close my account?

From My account, by typing your email address again. Your agents, routes and names are removed at once, and your email address is freed.

The law requires us to keep who owned which address for 12 months, in case of an abuse complaint. After that, your identity is erased for good.

What do you log?

Who did what on the account (sign-ups, logins, routes created or deleted), and how much traffic went through. Never the content of your traffic: we can't read it anyway.

We don't keep your visitors' IP addresses: they stay in your agent's logs, on your machine.

The privacy policy lists everything we keep, and for how long.

Where is my data stored?

In the European Union, on European hosting providers. We don't sell or share it.

Can I share my account with my team?

Not for now: one account is one person.

Rules & limits

What is not allowed?

Anything illegal, phishing, malware, spam, and attacking other people from your routes. A route that breaks the rules is suspended, and the account can be closed.

The full list is in the terms of service.

How do I report abuse?

Write to abuse@portlatch.eu with the address, the port and the time you saw. We act quickly.

Is there an uptime guarantee?

No. Portlatch is built for homelabs and side projects, and we do our best to keep it running. Don't rely on it for anything critical.

Do you support UDP, IPv6 or other regions?

Not for now: TCP over IPv4, from one region in Europe. IPv4 is precisely what we provide: it's what CGNAT takes away from you.

Is there a public API?

Not yet. Everything is done from the dashboard.

How do I contact support?

By email, at support@portlatch.eu. Portlatch is a small team: we answer every message, not always the same day.

Still stuck?

Write to support@portlatch.eu : we answer every message, not always the same day.