Share Localhost Through Firewalls Without Touching Your Router
You've built something on localhost:8080. Now you need to show it to someone—a client, a teammate, a friend—and suddenly you're staring down port forwarding, firewall rules, or yet another tunneling service that wants your credit card. zrok is a tool that sidesteps all of that. It lets you share web services, files, and network resources across the internet or your private network without changing a single thing about your network configuration.
What It Does
zrok is a sharing tool built on OpenZiti, a programmable zero-trust network overlay. In practice, that means you can expose a local web service, a folder of files, or a TCP/UDP service to the internet (or just to specific people) without requiring inbound connectivity. It works from behind firewalls and NAT because the connection is established outbound—no port forwarding, no router configuration, no static IP.
You run a command like zrok share public localhost:8080, and zrok handles the rest. It supports HTTP/HTTPS, TCP, UDP, and file sharing, and it runs on Windows, macOS, Linux, and Raspberry Pi. There's also a Go SDK if you want to embed sharing directly into your own applications, and the whole thing is self-hostable—the single binary contains everything you need to run your own instance, scaling from a personal setup to something enterprise-sized.
Why It's Cool
The zero-config part is real, not marketing. Most tunneling tools still ask you to think about ports and protocols. zrok just works from wherever you are—corporate network, coffee shop Wi-Fi, a Raspberry Pi behind two routers. That's because it's built on OpenZiti's overlay, which only needs outbound connectivity.
End-to-end encryption means the zrok servers can't see your traffic. This is a meaningful distinction from tools where the relay service sits in the middle with full visibility. With zrok, even if you're using the public zrok.io service, your data is encrypted in a way that the infrastructure can't inspect. Peer-to-peer connections are established when possible, which cuts latency and reduces reliance on relays.
Identity-based access, not IP-based. When you share privately, you're sharing with specific zrok users, not with an IP range or a shared secret. That's a cleaner security model, especially for teams or for sharing internal services without exposing them to the public internet.
The file-sharing mode is a nice touch. Running zrok share public --backend-mode drive ~/Documents turns a folder into a network drive. It's the kind of feature that seems small until you need to send someone a large file and don't want to deal with cloud storage uploads or expiring links.
Self-hosting is a first-class option. A lot of hosted sharing tools treat self-hosting as an afterthought. zrok ships as a single binary and uses the same codebase as the public service, so you're not getting a stripped-down version if you decide to run your own.
How to Try It
Getting started takes about two minutes, assuming you already have an account on the free zrok.io service.
- Install zrok for your platform following the install guide.
- Get an account with
zrok invite. - Enable sharing with
zrok enable.
Once that's done, you can share whatever you need:
# Share a web service publicly
zrok share public localhost:8080
# Share files as a network drive
zrok share public --backend-mode drive ~/Documents
# Share privately with other zrok users
zrok share private localhost:3000
If you want to embed sharing in your own Go application, the SDK makes it fairly direct:
shr, err := sdk.CreateShare(root, &sdk.ShareRequest{
BackendMode: sdk.TcpTunnelBackendMode,
ShareMode: sdk.PrivateShareMode,
})
listener, err := sdk.NewListener(shr.Token, root)
The SDK guide has complete examples. And if you'd rather run your own instance, the self-hosting guide covers that path.
You can find the project at github.com/openziti/zrok.
Final Thoughts
zrok is best suited for developers who need to share something quickly and don't want to think about networking—whether that's demoing a local app, giving a teammate access to an internal service, or moving files between machines. The zero-trust foundation means you're not trading security for convenience, and the self-hosting option means you're not locked into the public service. If you've ever spent an afternoon debugging a tunnel or a firewall rule just to show someone a work-in-progress, zrok is worth a look.