> ## Documentation Index
> Fetch the complete documentation index at: https://ngrok.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# How Sharing Localhost Works

> Learn what happens when you put a service running on your machine on the internet, and what that means for access and security.

Your app runs on `localhost`, where only you can reach it.
Sharing localhost gives it a public URL that anyone you choose can open, without deploying your code, changing your network, or opening a port on your machine.

## What happens when you share

Start the ngrok agent and point it at the port your app already listens on:

```bash theme={null}
ngrok http 8080
```

The agent opens an outbound connection to ngrok's cloud service, which hands back a public URL.
Requests to that URL travel over that connection and arrive at your app on `localhost:8080`.

Your code keeps running where it always did.
Edit a file, restart your server, and the next request at the same URL hits the new version.

Two things follow from the agent dialing out rather than listening:

* **Your machine stays closed.** Nothing accepts inbound connections on it, so there are no ports to forward and no firewall rules to change. The connection works from home networks, coffee shop Wi-Fi, and corporate networks that block inbound traffic.
* **The traffic is encrypted.** The connection between your machine and ngrok runs over TLS, and your public URL is served over HTTPS with a certificate ngrok provisions and renews for you.

## What you can share

| What you're sharing | Command |
| - | - |
| A web app, API, or webhook receiver | `ngrok http 8080` |
| A database, SSH server, RDP host, or game server | `ngrok tcp 3389` |
| A service that presents its own TLS certificate | `ngrok tls 8443` |

See the [protocols documentation](/docs/gateway/endpoints/protocols) for the details of each.

## Who can reach it

Your URL is public as soon as it exists.
Anyone who has it can open it, so treat it like a link to a live service rather than a private address—and remember that whatever you share is running on your own machine.

You control access without changing your app:

* [Add authentication](/docs/share-localhost/auth) so visitors sign in before they reach you.
* [Review the security model](/docs/share-localhost/security) to understand what you expose and how to limit it.
* [Apply a Traffic Policy](/docs/gateway/traffic-policy/) to require credentials, restrict IP addresses, rate limit requests, or rewrite traffic in flight.

When you stop the agent, the URL stops working and your machine is unreachable again.
What you created while it ran is an [Agent Endpoint](/docs/gateway/endpoints/agent-endpoints), an endpoint that exists only for the life of the agent process.

## Next steps

* [Quickstart](/docs/share-localhost/quickstart): share your first local service.
* [Inspect traffic and replay requests](/docs/share-localhost/inspection): see every request that reaches your app and send it again.
* [Agent CLI reference](/docs/gateway/agent/cli): the full set of commands and flags.
