OpenTunnel is an end-to-end encrypted (“blind”) TLS tunnel hosted on Cloudflare by Anomaly. Each client receives a unique
Downloads and runs the install script, which fetches the prebuilt opentunnel binary from GitHub releases. The CLI is also available via npm (npm install -g opentunnel), Homebrew (brew install anomalyco/tap/opentunnel), AUR (opentunnel-bin) and Cargo (cargo install opentunnel-cli).
curl -fsSL https://opentunnel.xyz/install | sh
Creates the tunnel on first use, routes <SUBDOMAIN>.<id>.opentunnel.xyz to 127.0.0.1:<PORT> and starts the background service.
opentunnel route add <SUBDOMAIN> <PORT>
Routes the tunnel's root hostname (<id>.opentunnel.xyz) to an arbitrary host and port reachable from the machine, such as another internal system.
opentunnel route add @ <HOST>:<PORT>
Runs the tunnel in the foreground instead of as a registered service, for containers or environments without systemd/launchd.
opentunnel serve
Creates the tunnel if needed and starts the background service. Where available it registers as a systemd user service (opentunnel-<profile>.service) or launchd agent (xyz.opentunnel.<profile>) that starts at login.
opentunnel up