CIDR allowlist
Allow precise IPs or ranges when the provider sends from known addresses.
HTTP AUTHENTICATION
An HTTP tunnel can remain open for an expected webhook or require proof of access depending on the published service. The choice is stored in the tunnel profile.
Choose a mode proportional to the service: no filter for reception controlled by application signature, or an access rule for a human interface.
auth_http_mode = google_oidcControlled HTTP accessAllow precise IPs or ranges when the provider sends from known addresses.
Add straightforward protection for a short-lived preview that should not be open to everyone.
Use Google or Microsoft OIDC when visitor identity must participate in the access rule.
OPENPORT.FR
Publish a local service or open private access in seconds, without opening an inbound port.