Skip to main content
SaaS connectivity

Your SaaS needs data from your customer's network. Get it without the VPN circus.

Your customers' APIs, databases, and internal tools live behind firewalls you don't control. ngrok gives your SaaS secure, scoped access without VPN setup, open ports, or VPC peering projects.

  • Calendly
  • Cyera
  • Databricks
  • GitHub
  • Grafana
  • Harvey
  • Hugging Face
  • Mercor
  • Microsoft
  • Okta
  • Open AI
  • Perplexity
  • Ramp
  • Schneider Electric
  • Twilio
  • Vercel
  • Windsurf
  • Zoom
How it works

One agent per customer. Every service on their network.

Your customer runs a lightweight agent behind their firewall. It dials out to ngrok on port 443 and gives you private endpoints to the APIs, databases, and services you're authorized to reach.

Diagram showing how traffic flows from your cloud through ngrok to customer networks

Customers run a lightweight agent that creates secure tunnels: outbound TLS connections from agents to the ngrok cloud on port 443.

Authorize connections with your choice of mTLS, IP restrictions, or JWTs. ngrok relays traffic from your cloud directly to the target service.

Diagram showing private addressability with the ngrok Kubernetes Operator wrapping connections in mTLS

Connections from your cloud to ngrok are wrapped in mTLS by the ngrok Kubernetes Operator. Only your cluster can ping the URL, so there's no need for auth.

Not running in Kubernetes? We also support private URLs with our agent CLI and Go SDK. Talk to an engineer

Diagram showing multiple services and endpoints connected through ngrok

Access more services on other protocols with one setup—DBs, web apps, IoT devices, and much more.

Expand from one to many customers with the same agent configuration and new private endpoints.

Why ngrok?

Customers can run an agent without networking projects. That shortens onboarding time and gets integrations live faster.

Keep customer networking out of your support queue. Your team focuses on product value instead of firewall tickets and peering issues.

One integration works for every enterprise topology. AWS, Azure, on-prem, and hybrid environments all use the same connection model.

Watch

Ingress into customer networks, explained

How teams give their product a secure path into customer environments without shipping a VPN.

Connect your SaaS to your first customer network in 10 minutes.

No upfront costs. No contact sales. Pay only for what you use.

ngrok vs. VPNs, Cloudflare Tunnel, Tailscale, and PrivateLink

The spec-sheet view for connecting your SaaS into a customer's network. Where an alternative says "no," it's usually a consequence of its architecture, not a missing feature.

CapabilityngrokSite-to-site VPNCloudflare TunnelTailscaleAWS PrivateLink
Built to reach many customers' networksYes — per-customer agent ACLsNoNo — for your own originsNo — one shared tailnetNo — one AWS account
Inbound firewall ports the customer opensNone — outbound TLS on 443Inbound ports and appliancesNoneNoneNone
Scope of access grantedA single service, API, or DBThe whole networkService or networkThe whole tailnetA single service
White-label and embed in your productYesNoNoNoNo
Any cloud, hybrid, or on-premYes — cloud-agnosticVaries by applianceYesYesSame cloud and region only
Customer-side setupRun one lightweight agentVPN appliance plus configRun a connectorJoin the tailnetVPC and endpoint config
End-to-end encryption with your own keysYes — mTLS, ngrok sees ciphertextYesTLSWireGuardTLS
API and Terraform automationYesLimitedPartialPartialAWS APIs only

For a use-case-by-use-case breakdown, see our ngrok vs. Tailscale and ngrok vs. Cloudflare Tunnel comparisons.

Frequently asked questions