Mint a master key once — your AI assistant runs autonomously with scoped, short-lived child keys and instant cascade revoke. Built for Claude Code, Cursor, Aider, Devin. Also a complete open-source ngrok alternative in Rust: HTTP, TCP, SSH and gRPC tunnels, sticky subdomains, custom domains on the free tier, edge auth, live request inspector, team RBAC and audit logs. Self-host the whole stack free forever under MIT and Apache-2.0. No tier-locked security features.
Hey Product Hunt. I work with the team building 21tunnel, and the product started with a security problem: every AI coding agent setup ends with "paste your full-access API token into the agent's environment." No expiry, no scope, one prompt injection away from a leak. 21tunnel inverts it — the master key cannot open tunnels at all, it only mints scoped child keys with TTL and project isolation, and one click cascade-revokes everything the agent ever made. Underneath, it is a full open-source ngrok alternative in Rust: custom domains on the free tier, sticky subdomains, request inspector, RBAC, audit logs, self-hostable forever. Happy to answer anything, especially on the security model. What would you never let an AI agent hold?
Report
No reviews yetBe the first to leave a review for 21tunnel