Your AI agent is ready for the enterprise. Its data is stuck behind a firewall.
Ship one lightweight ngrok agent per customer and your AI agents reach the internal APIs, databases, and MCP servers they need. Each customer stays isolated, and traffic is encrypted end to end—so you never become a subprocessor of their data.
One ngrok agent per customer. Every system your AI agents need.
Your customer runs a lightweight ngrok agent behind their firewall. It dials out to ngrok and gives your AI agents private, scoped URLs to only the APIs, databases, and MCP servers you're authorized to reach.
Customers run a lightweight ngrok agent that creates secure tunnels: outbound TLS connections from ngrok agents to the ngrok cloud on port 443.
Authorize your AI agents' access with mTLS, IP restrictions, or JWTs. ngrok relays traffic from your product directly to the target service.
Reach every service your AI agents need over one ngrok agent: REST APIs, databases, internal web apps, and private MCP servers, each on its own scoped URL.
Expand from one to many customers with the same ngrok agent configuration and new endpoints with the layers of authentication they demand.
Why ngrok?
Unblock the deal that was stuck on access. Your customer runs one ngrok agent, not a networking project. Live in days, not quarters.
Keep customer networking out of your support queue. Your team focuses on your product's value instead of firewall tickets and peering issues.
One integration reaches every customer environment. AWS, Azure, on-prem, and hybrid environments all use the same connection model.
Pass your customers' security reviews on the first try.
The ngrok agent already runs in banks, healthcare systems, and Fortune 100 networks. End-to-end TLS means the ngrok cloud only ever sees ciphertext, so you never become a subprocessor of their data.
Give your AI agents one service, not the whole network
Your customer exposes exactly one service by name—nothing else in their network is even addressable. Scope access to the APIs, databases, and MCP servers your AI agents need and not a single port more.
Never become a subprocessor
Terminate TLS in your customer's network at the upstream service or the ngrok agent. The ngrok cloud service only sees ciphertext, so your AI agents' traffic stays private end to end.
Restrict traffic regions for data residency
Comply with data residency requirements by selecting the exact ngrok data centers used to relay your AI agents' connections.
Isolate every customer, credential by credential
Each customer gets its own scoped, endpoint-bound token and its own policy. A credential stolen at one customer can never touch another's endpoints, and offboarding is a single token revocation.
All the boxes you need to check
Your customers have questions.
We have answers.
Send your customers a complete Q&A on how ngrok works and why it's secure.
Check it outHit all the 9s in your SLA.
Network failures are inevitable. Identify and recover from them automatically.
Reconnect automatically
You can't control your customer's network. That's why the ngrok agent runs in the background and heartbeats its connection to recover quickly after it sees connection reset by peer.
Alert on issues before customers notice
Publish tunnel status and connection events to your telemetry platform. When a connection drops, you'll know before your customer does.
High availability with ngrok agent redundancy
Run multiple ngrok agents in your customer's network and ngrok will balance connections among them. You'll stay connected even when a machine running one ngrok agent fails.
Stay online during region outages
Agents create secure tunnels to multiple regions of the ngrok cloud service. You won't go down when entire datacenters fail (cough, us-east-1, cough).
Built to run a fleet of ngrok agents, not a tunnel.
Ship the ngrok agent to every customer
The ngrok agent is a cross-platform, dependency-free binary pre-packaged for Docker, Kubernetes, Windows, Linux, and macOS.
`import ngrok`
Embed the ngrok agent directly in your product with an SDK in five languages—ideal when your own software already runs inside the customer environment.
Provision every customer with an API call
APIs for every feature, a Terraform provider for IaC, and bot users plus wildcard domains to automate per-customer onboarding as your ngrok agent footprint grows.
White-label everything
Brand your URLs, ngrok agent connect address, and dedicated IPs with your own domains so the customer's security team allowlists your product—not a generic ngrok endpoint.
Need to self-host ngrok?
Inquire about private editionConnect your AI agents to your first customer network in 10 minutes.
No upfront costs. No contact sales. Pay only for what you use.
