Share a Local Web App

Give someone a link to a web app that runs on your laptop: no deploy, no port forwarding, no firewall change. The link works while nfltr http runs and stops the moment you stop it.


Goal

A reviewer opens a public https://….nfltr.xyz/ link and sees the app on your localhost:8080. Then you protect the link with a generated password, and finally revoke it.

Prerequisites

1. Start the app

Use your own app on any port. This tutorial uses a one-file page served by Python on port 8080:

$ echo '<h1>Hello from my laptop</h1>' > index.html
$ python3 -u -m http.server 8080
Serving HTTP on :: port 8080 (http://[::]:8080/) ...

Leave it running and open a second terminal.

2. Share it

$ nfltr http 8080
Agent ID               you.apple-local-5bef
Share URL              https://fast-beam-0d80c450ede795600648c0d0aec3e87e.nfltr.xyz/
  Access               Public
  Policy               public link
  Expires              2026-09-30T07:59:31Z
Tunnel Mode        Verified, Private Share
Connected — waiting for requests... (press Ctrl+C to stop)

Send the Share URL to the reviewer. Anyone with the link can open it until it expires (24 hours unless you pass --share-ttl 2h) or you stop the command. The tunnel is end-to-end encrypted by default (Verified): TLS ends on your laptop, not on the relay.

Check it yourself ($URL stands for the Share URL printed above):

$ curl -s "$URL"
<h1>Hello from my laptop</h1>

3. Revoke it: stop the command

Press Ctrl+C in the terminal running nfltr http. The link stops working at once:

$ curl -s -o /dev/null -w '%{http_code}\n' "$URL"
503

The link is tied to this machine's agent name. If you share again from the same machine under the same name within its lifetime, the same link comes back. To hand out a link the earlier reviewer cannot reuse, start the new share with a different name: nfltr http 8080 --name review-2.

4. Protect the link with a password

--share-preset review puts HTTP Basic Auth in front of the link and generates the credentials for you:

$ nfltr http 8080 --share-preset review
Share URL              https://fast-beam-0d80c450ede795600648c0d0aec3e87e.nfltr.xyz/
  Access               Review Share
  Policy               browser-friendly Basic Auth
  Expires              2026-09-30T08:11:06Z
  Basic Auth           curl -u "review:5e24e5cd2bb6" <url>

Send the reviewer the link and the review:… user and password (a browser prompts for them). Without them the link answers 401; with them it serves the app ($CRED stands for the review:… pair):

$ curl -s -o /dev/null -w '%{http_code}\n' "$URL"
401
$ curl -s -u "$CRED" "$URL"
<h1>Hello from my laptop</h1>

Other ways to restrict a link: --share-auth user:password (your own credentials), --share-bearer TOKEN (for API clients), --share-ip-allowlist 203.0.113.0/24, --share-header X-Api-Key=value. --no-share creates no public link at all.

5. Clean up

Press Ctrl+C in the nfltr http terminal. Even with the password, the link now answers 503:

$ curl -s -u "$CRED" -o /dev/null -w '%{http_code}\n' "$URL"
503

Then stop the web server with Ctrl+C too.

If it goes wrong

You seeMeaning and fix
Error: recv error: rpc error: code = AlreadyExists desc = API key is already in use by agent <agent id>One API key runs one live tunnel at a time, and another nfltr command already uses it. Stop that command, or create a second key in the dashboard and pass it with --key-name (see nfltr config list-api-keys).
The link answers 502 with tunnel error: Get "http://localhost:8080": dial tcp [::1]:8080: connect: connection refusedThe tunnel is up but nothing listens on that port. Start the app, or pass the port it really uses (nfltr http 3000, or a full URL such as nfltr http https://myapp.local:3000).
The link answers 503 with agent "…" registered but no pod currently holds its connectionnfltr http is not running (stopped, or reconnecting after a network drop). Start it again; the same link comes back.
An upload answers 413 with request body too large: the relay accepts at most 1 GiB (http.server.max_request_body_size)Request bodies are limited to 1 GiB. Split the upload, or move the file between your own machines with nfltr p2p send (Send files and messages). If the message says the agent reads request bodies whole, the agent is an old nfltr: update it.
The link answers 401 UnauthorizedThe share has a password (--share-preset review or --share-auth). Use the credentials nfltr printed.
health server error: listen tcp :29501: bind: address already in useHarmless when two tunnels run on one machine: only the local health endpoint of the second one is off. Pass --health-addr :29502 to move it.

Next