Share a Local Web App
Give someone a link to a web app that runs on your laptop: no deploy, no port forwarding, no firewall change. The link works while nfltr http runs and stops the moment you stop it.
Goal
A reviewer opens a public https://….nfltr.xyz/ link and sees the app on your localhost:8080. Then you protect the link with a generated password, and finally revoke it.
Prerequisites
- The
nfltrCLI on your laptop (Getting Started, step 2). - Your account's API key saved once:
nfltr config add-api-key(orNFLTR_API_KEYin the environment). - The reviewer needs only a browser (or
curl). They do not need an account or the CLI.
1. Start the app
Use your own app on any port. This tutorial uses a one-file page served by Python on port 8080:
$ echo '<h1>Hello from my laptop</h1>' > index.html
$ python3 -u -m http.server 8080
Serving HTTP on :: port 8080 (http://[::]:8080/) ...
Leave it running and open a second terminal.
2. Share it
$ nfltr http 8080
Agent ID you.apple-local-5bef
Share URL https://fast-beam-0d80c450ede795600648c0d0aec3e87e.nfltr.xyz/
Access Public
Policy public link
Expires 2026-09-30T07:59:31Z
Tunnel Mode Verified, Private Share
Connected — waiting for requests... (press Ctrl+C to stop)
Send the Share URL to the reviewer. Anyone with the link can open it until it expires (24 hours unless you pass --share-ttl 2h) or you stop the command. The tunnel is end-to-end encrypted by default (Verified): TLS ends on your laptop, not on the relay.
Check it yourself ($URL stands for the Share URL printed above):
$ curl -s "$URL"
<h1>Hello from my laptop</h1>
3. Revoke it: stop the command
Press Ctrl+C in the terminal running nfltr http. The link stops working at once:
$ curl -s -o /dev/null -w '%{http_code}\n' "$URL"
503
The link is tied to this machine's agent name. If you share again from the same machine under the same name within its lifetime, the same link comes back. To hand out a link the earlier reviewer cannot reuse, start the new share with a different name: nfltr http 8080 --name review-2.
4. Protect the link with a password
--share-preset review puts HTTP Basic Auth in front of the link and generates the credentials for you:
$ nfltr http 8080 --share-preset review
Share URL https://fast-beam-0d80c450ede795600648c0d0aec3e87e.nfltr.xyz/
Access Review Share
Policy browser-friendly Basic Auth
Expires 2026-09-30T08:11:06Z
Basic Auth curl -u "review:5e24e5cd2bb6" <url>
Send the reviewer the link and the review:… user and password (a browser prompts for them). Without them the link answers 401; with them it serves the app ($CRED stands for the review:… pair):
$ curl -s -o /dev/null -w '%{http_code}\n' "$URL"
401
$ curl -s -u "$CRED" "$URL"
<h1>Hello from my laptop</h1>
Other ways to restrict a link: --share-auth user:password (your own credentials), --share-bearer TOKEN (for API clients), --share-ip-allowlist 203.0.113.0/24, --share-header X-Api-Key=value. --no-share creates no public link at all.
5. Clean up
Press Ctrl+C in the nfltr http terminal. Even with the password, the link now answers 503:
$ curl -s -u "$CRED" -o /dev/null -w '%{http_code}\n' "$URL"
503
Then stop the web server with Ctrl+C too.
If it goes wrong
| You see | Meaning and fix |
|---|---|
Error: recv error: rpc error: code = AlreadyExists desc = API key is already in use by agent <agent id> | One API key runs one live tunnel at a time, and another nfltr command already uses it. Stop that command, or create a second key in the dashboard and pass it with --key-name (see nfltr config list-api-keys). |
The link answers 502 with tunnel error: Get "http://localhost:8080": dial tcp [::1]:8080: connect: connection refused | The tunnel is up but nothing listens on that port. Start the app, or pass the port it really uses (nfltr http 3000, or a full URL such as nfltr http https://myapp.local:3000). |
The link answers 503 with agent "…" registered but no pod currently holds its connection | nfltr http is not running (stopped, or reconnecting after a network drop). Start it again; the same link comes back. |
An upload answers 413 with request body too large: the relay accepts at most 1 GiB (http.server.max_request_body_size) | Request bodies are limited to 1 GiB. Split the upload, or move the file between your own machines with nfltr p2p send (Send files and messages). If the message says the agent reads request bodies whole, the agent is an old nfltr: update it. |
The link answers 401 Unauthorized | The share has a password (--share-preset review or --share-auth). Use the credentials nfltr printed. |
health server error: listen tcp :29501: bind: address already in use | Harmless when two tunnels run on one machine: only the local health endpoint of the second one is off. Pass --health-addr :29502 to move it. |
Next
- Share a log file or command output
- HTTP tunnels: routes, recording, the traffic inspector
- Diagnose connection problems