Reach every machine you manage. Without VPNs, port forwarding, or vendor binaries.
A zero-configuration reverse-tunnel service for ops teams, MSPs, integrators, and IoT operators. Your fleet stays behind its firewall — you reach it through a tunnel your own server opens on demand, encrypted with your own keys.
installed on your fleet
across 3 continents
forwarding server
shared team plans
Every operations team eventually hits the same wall.
Branch offices on consumer ISPs
You maintain dozens of small-office Linux servers behind ADSL or cable lines with no static IP and no router access.
Locked-down customer networks
The Windows PCs you support via VNC sit behind a firewall the customer's IT department refuses to touch.
IoT and Raspberry Pi at the edge
You have embedded devices deployed across customer sites. Every truck-roll for a console session costs you margin.
Demos, webhooks, dev tunnels
Your developers need to expose a local service to Stripe, Slack, or a customer — without standing up infrastructure each time.
Your server opens the tunnel. You steer it from the web.
Upload your key
Use your existing SSH keypair or generate one in the dashboard. We never see your private key.
Drop the script
A short, auditable Python script ships to each device. Plain text — read it, fork it, replace it.
Open from the web
Click a button in the console (or hit the API). The device opens its outbound tunnel on demand.
Connect & work
SSH, SCP, VNC over forwarded ports, anything the device supports. Idle tunnels close automatically.
The honest comparison.
| sshreach.me | VPN mesh services | Dynamic DNS + port forwarding | DIY SSH bastion | |
|---|---|---|---|---|
| Installs proprietary agent on every machine | No — uses standard ssh client | Yes — kernel module or daemon | Often (DDNS client) | No |
| Requires router / firewall changes at customer site | Never | Usually no | Yes — port forwarding | No |
| Tunnel encrypted with your SSH keys | Yes | Provider keys | Depends on protocol | Yes |
| Works on Dropbear / minimal IoT | Yes | Rarely | Sometimes | Yes |
| Effort to scale to 500+ devices | Add clients in dashboard | Mesh management overhead | Per-site router work | You build & maintain it |
| Replaceable / forkable client | Yes — it's a Python script | No | Vendor-dependent | Yes — you wrote it |
| Monthly cost for 50 endpoints | €25 | €100–300+ typical | Hidden in IT labor | Server + your time |
Three kinds of teams that save real money with us.
Manage a fleet of small-business Linux & Windows hosts
Stop rolling trucks to remote sites for routine maintenance. Reach every client device the same way, regardless of their ISP or router.
- One dashboard for every customer site
- Per-tunnel audit through the API
- Team accounts on shared plans
Service deployed devices in the field at scale
Built for Raspberry Pi, embedded Linux, and Dropbear-class hardware. Dedicated forwarding servers handle up to 5,000 endpoints with IP whitelisting.
- Works on memory-constrained devices
- Forward any port (VNC, web UI, Modbus-gw)
- Regional edges keep latency low
Expose local services without standing up infra
Test Stripe, Slack, or PayPal webhooks against a real public endpoint. Share a staging app with a customer in one click. No corporate VPN politics.
- Public URL for any local port
- Tunnels auto-close when idle
- Unlimited API calls on paid plans
Trust is a thing you should be able to verify.
Your keys, never ours
The tunnel is encrypted with your own public/private keypair. Even if our forwarding server is compromised, there's nothing useful to read.
Auditable client
A plain-text Python script — no compiled binary, no obfuscation. Read it, fork it, replace it with your own implementation if you'd rather.
Closed by default
Tunnels only exist when you ask for them. Idle connections close automatically. Dedicated plans add IP-based whitelisting on top.
Pay for clients. Not seats.
Team 10
- 10 clients / endpoints
- 10 GB transfer per month
- Unlimited API calls
- Forward any port
- Team accounts included
- Regional shared edges
Team 50
- 50 clients / endpoints
- 50 GB transfer per month
- Unlimited API calls
- Forward any port
- Team accounts included
- Edges in California, Germany, Singapore
- Scales up to 250 on shared plans
Dedicated forwarder
- 5,000 clients per server
- 3 TB transfer / month / server
- IP-based whitelisting
- Unlimited API calls & team support
- Deploy in CA, TX, ON, NJ, UK, DE, IN, SG, JP
- Run multiple servers for HA
// Shared plans available at 20, 40, 100, 150, 200, 250 clients