🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

easytyga

Package Overview
Dependencies
Maintainers
1
Versions
14
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

easytyga

Tunnel your local AI to the internet. Secure. One command. Works with Ollama, OpenClaw, vLLM, and any HTTP service.

latest
Source
npmnpm
Version
3.1.0
Version published
Maintainers
1
Created
Source

easytyga

Your homelab AI, accessible from anywhere. One command.

Expose your local Ollama, OpenClaw, vLLM, or any HTTP service to the internet with API key authentication. No port forwarding, no static IP, no nginx configs.

npx easytyga
  easytyga v3.0.0
  Tunnel your local AI to the web

  GPU:     NVIDIA GeForce RTX 4090
  Target:  http://localhost:11434

  Tunnel active

  Public URL:  https://relay.easytyga.com/t/abc123
  API Key:     et_a1b2c3d4e5f6...

  Credits:     50,000 requests remaining

  Manage your account: https://easytyga.com/account
  Press Ctrl+C to disconnect.

That's it. Your local AI is now accessible from anywhere, secured with an API key.

The whole box, not just HTTP

easytyga turns a tunnel into full remote access to your GPU pod. Beyond HTTP, you can reach raw TCP ports - SSH into the machine, drive its Docker daemon, open Jupyter or TensorBoard, sync files, or hit a database - all over the same secured, API-key-authenticated tunnel, with no public IP.

Everything is default-deny: a port is only reachable if the pod explicitly allowed it, and the relay enforces the same allowlist independently.

# On the pod: allow SSH, Docker, and Jupyter
npx easytyga --stream-ports 22,2375 --jupyter

# On your machine: SSH in, or open Jupyter locally
npx easytyga connect mypod --port 22 --local 2222
npx easytyga connect mypod --jupyter --local 8888

Multi-tunnel

Run multiple tunnels in a single process. Expose Ollama, vLLM, OpenClaw, or any mix of services at the same time, each with its own public URL and API key.

npx easytyga --tunnel ollama=http://localhost:11434 --tunnel vllm=http://localhost:8000
  easytyga v3.0.0 (2 tunnels)
  Tunnel your local AI to the web

  GPU:     NVIDIA GeForce RTX 4090

  Tunnels:
    ollama -> http://localhost:11434
    vllm -> http://localhost:8000

  [ollama] Tunnel active
  [ollama] Public URL:  https://relay.easytyga.com/t/abc123
  [ollama] API Key:     et_a1b2c3d4...

  [vllm] Tunnel active
  [vllm] Public URL:  https://relay.easytyga.com/t/def456
  [vllm] API Key:     et_e5f6g7h8...

Or use a config file for more control:

npx easytyga --config easytyga.config.json
{
  "tunnels": [
    { "name": "ollama", "target": "http://localhost:11434" },
    { "name": "vllm", "target": "http://localhost:8000", "list": true },
    { "name": "openclaw", "target": "http://localhost:18789", "openclaw": true }
  ]
}

Each tunnel gets independent heartbeat, reconnection, and health checks. If one tunnel fails, the others keep running.

Tunnel any HTTP service

easytyga isn't just for AI. Point it at any local HTTP service - a dev server, webhook receiver, dashboard, home automation UI - and get a public, API-key-protected URL in seconds.

# Auto-detect: if the target isn't Ollama, it's tunnelled as a plain HTTP service
npx easytyga --target http://localhost:3000

# Force generic mode explicitly
npx easytyga --raw --target http://localhost:3000

# Service still starting up? Retry the target check for up to 120s
npx easytyga --raw --target http://localhost:3000 --wait-target 120

Request headers and content types are passed through untouched, so JSON APIs, HTML pages, form posts, and binary responses all work.

SSH, Docker, and databases over your tunnel

Beyond HTTP, easytyga tunnels raw TCP - so you can SSH into a remote box or reach its Docker socket over the same secured tunnel. This is ideal for GPU pods: expose port 22 and manage the machine from anywhere, no public IP required.

There are two sides.

On the remote machine (the pod), list the local ports you want to allow. This is an explicit allowlist - nothing is reachable unless you name it here:

# Allow SSH (22) and the Docker daemon (2375)
npx easytyga --stream-ports 22,2375

On your machine (the renter), open a local port that forwards to the pod:

# Forward local 2222 -> pod's port 22, then SSH in
npx easytyga connect mypod --port 22 --local 2222
ssh user@localhost -p 2222
# Reach the pod's Docker daemon on a local port
npx easytyga connect mypod --docker --local 2375
DOCKER_HOST=tcp://localhost:2375 docker ps

mypod is the tunnel name (the same key the pod connected with). Ports are default-deny end to end: the connection is refused unless the port is in the pod's --stream-ports allowlist, and the relay enforces the same allowlist independently.

Service presets

Common workflows get a single flag instead of a port number to remember. Presets are shorthand for --stream-ports on the pod and connect --port on your machine - the same default-deny allowlist, just less typing.

On the pod, expose services by name:

# Jupyter (8888), TensorBoard (6006), and Postgres (5432) in one line
npx easytyga --jupyter --tensorboard --db 5432

From your machine, reach one by name and get the exact command printed back for you:

npx easytyga connect mypod --jupyter --local 8888
#   Connect with:  open http://localhost:8888

npx easytyga connect mypod --db 5432 --local 5432

npx easytyga connect mypod --rsync --local 2222
#   Connect with:  rsync -e 'ssh -p 2222' <user>@localhost:/remote/path ./
PresetPortRides on
--jupyter [port]8888its own stream
--tensorboard [port]6006its own stream
--docker2375its own stream
--db <port>your choiceits own stream
--rsync / --scp22the SSH stream

A preset never widens access. It just adds its port to the same allowlist and entitlement checks as --stream-ports, so nothing is reachable unless the pod named it. An explicit --port always overrides the preset.

Why?

Most local AI services have no built-in authentication and no remote access. If you want to use your GPU from your phone, office, or a cloud app, you need to cobble together nginx + Cloudflare tunnels + basic auth.

easytyga solves this in one command:

  • Secure tunnel - no port forwarding, works behind any NAT/firewall
  • API key auth - auto-generated, every request authenticated
  • Auto-detects your GPU - knows what hardware you're running
  • Works with anything - Ollama, OpenClaw, vLLM, LocalAI, ComfyUI, or any HTTP service

easytyga vs ngrok

ngrok is a great general-purpose tunnel. easytyga is built specifically for self-hosted AI and GPU boxes. The tunnel is full, authenticated access to the whole machine (SSH, Docker, Jupyter, databases), so a lot works differently out of the box.

easytygangrok (Free)
API key auth on every endpointYes, auto-generated, always onHTTP/HTTPS only (not TCP); auth is opt-in
Raw TCP (SSH / Docker)Yes, included, default-deny allowlistRequires credit-card verification
Service presets (Jupyter, TensorBoard, DB)One-flag shortcuts built inManual port config
The whole box, not just HTTPSSH + Docker + notebooks in one tunnelPer-endpoint agents, paid TCP
Session lengthUnlimited2 hour cap
Interstitial warning pageNoneShown to all visitors
GPU + model detectionBuilt in (NVIDIA, AMD, Apple Silicon)No
Multi-tunnel in one processYes, one WebSocket per tunnelOne agent per endpoint
AI-native modes--openclaw, Ollama/vLLM auto-detectGeneric HTTP only
Pricing modelCredits, one-time, never expireMonthly subscription
Entry cost$1 one-time activation (1,000 requests)Free tier, then monthly plans

Numbers reflect ngrok's published Free plan as of 2026. See ngrok.com/pricing for their current terms.

If you need a mature API gateway with global edge, load balancing, and Kubernetes ingress, use ngrok. If you want your whole GPU box online in one command - HTTP, SSH, Docker, and notebooks, all authenticated, with no time limits - use easytyga.

Usage

# Tunnel local Ollama (default port 11434)
npx easytyga

# Multiple tunnels at once
npx easytyga --tunnel ollama=http://localhost:11434 --tunnel vllm=http://localhost:8000

# From a config file
npx easytyga --config easytyga.config.json

# Tunnel your OpenClaw AI assistant gateway
npx easytyga --openclaw

# OpenClaw on a custom port
npx easytyga --openclaw 19000

# Tunnel a different service
npx easytyga --target http://localhost:8080

# Tunnel any non-AI HTTP service (generic mode)
npx easytyga --raw --target http://localhost:3000

# Wait for a slow-starting service before tunnelling
npx easytyga --wait-target 60

# Use a specific key
npx easytyga --key et_abc123...

# Expose raw TCP ports (SSH, Docker) on the remote machine
npx easytyga --stream-ports 22,2375

# Reach a remote pod's port from your machine
npx easytyga connect mypod --port 22 --local 2222

Options

FlagDescription
--target <url>Local endpoint (default: http://localhost:11434)
--tunnel name=urlAdd a named tunnel (repeatable for multi-tunnel)
--config <path>Load tunnel config from JSON file
--openclaw [port]OpenClaw gateway mode (default port: 18789)
--rawGeneric HTTP mode - tunnel any local service
--wait-target <sec>Retry the target check for up to <sec> seconds at startup
--eagerRegister the tunnel immediately, probe the target lazily
--stream-ports <list>Allow raw-TCP streams to these local ports (e.g. 22,2375)
--jupyter [port]Preset: expose Jupyter (default port 8888)
--tensorboard [port]Preset: expose TensorBoard (default port 6006)
--db <port>Preset: expose a database port (e.g. 5432)
--server <url>Relay server URL
--key <key>Connection key
--listAdvertise this tunnel to gpusmarket.com
--memoryEnable persistent conversation memory
--helpShow help

connect subcommand

Reach a remote pod's raw-TCP port from your machine: npx easytyga connect <tunnel> [options]

FlagDescription
--port <n>Remote port on the pod to reach (e.g. 22)
--local <n>Local port to listen on (e.g. 2222)
--dockerPreset for the Docker daemon port (2375)
--jupyter [port]Preset for Jupyter (default 8888)
--tensorboard [port]Preset for TensorBoard (default 6006)
--db <port>Preset for a database port (e.g. 5432)
--rsync / --scpPreset for file transfer over the SSH stream (22)
--bind <host>Local interface to bind (default: 127.0.0.1)
--key <key>Tunnel key

How it works

  • easytyga connects to the relay server via WebSocket (one connection per tunnel)
  • The relay assigns each tunnel a public URL with API key auth
  • Incoming requests are forwarded through the tunnel to your local service
  • Responses stream back to the caller

Your IP stays private. No ports to open. Works from any network.

Features

  • Multi-tunnel - run multiple services in one process, each with its own URL
  • Config file support - define tunnels in easytyga.config.json
  • One command - npx easytyga, no install needed
  • API key auth - every tunnel gets a unique key, no anonymous access
  • GPU detection - auto-detects NVIDIA, AMD, and Apple Silicon
  • Model detection - discovers installed Ollama models automatically
  • OpenClaw support - native --openclaw flag for AI assistant gateways
  • Auto-reconnect - exponential backoff, set and forget
  • Client-side heartbeat - detects dead connections within 30s, auto-reconnects when relay restarts
  • Streaming - full support for streaming responses (chat, generate)
  • Any HTTP service - not locked to Ollama; --raw tunnels anything with full header passthrough
  • Raw TCP (SSH / Docker) - --stream-ports exposes local ports over the tunnel; connect forwards them to your machine, default-deny by allowlist
  • Service presets - --jupyter, --tensorboard, --db, --rsync/--scp are one-flag shortcuts over raw TCP, still default-deny
  • Wait for target - --wait-target retries at startup instead of failing while your service boots

Credits

A one-time $1 activates your tunnel key and includes 1,000 requests (about 1,000 Ollama prompts). It is a spam-buster to keep the shared relay clean, not a profit centre. Beyond that, credit packs remove the rate limit and never expire.

  • Starter - 10,000 requests for $4.99
  • Popular - 50,000 requests for $14.99
  • Pro - 200,000 requests for $29.99

Buy credits at easytyga.com/credits. Manage your account at easytyga.com/account.

Integrations

  • OpenClaw - Tunnel your personal AI assistant gateway to the internet for WhatsApp, Telegram, Slack, Discord, Signal, and 20+ channels (--openclaw)
  • gpusmarket.com - A peer-to-peer GPU rental marketplace built on easytyga. Advertise a tunnel to it with --list
  • agenticmemory.ai - Add persistent conversation memory to your AI (--memory)

See easytyga.com for documentation.

License

MIT

Trademarks

"easytyga" and the easytyga logo are trademarks of Tyga.Cloud Ltd. easytyga is a division of Tyga.Cloud Ltd. The name and branding may not be used in derivative works without written permission.

This software is provided under the MIT license - you are free to use, modify, and distribute the code, but the easytyga name, branding, and relay infrastructure remain the property of Tyga.Cloud Ltd.

Ollama is a trademark of Ollama, Inc. OpenClaw is a trademark of OpenClaw contributors. vLLM is a trademark of vLLM contributors. NVIDIA, GeForce, and RTX are trademarks of NVIDIA Corporation. AMD and Radeon are trademarks of AMD. Apple and Apple Silicon are trademarks of Apple Inc. All other trademarks are the property of their respective owners. This project is not affiliated with or endorsed by any of these companies.

A Tyga.Cloud Ltd product. Built by jyswee.

Keywords

tunnel

FAQs

Package last updated on 10 Jul 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts