Skip to content

Cloudflare Tunnel alternative: no account, no domain

Cloudflare Tunnel (cloudflared) is an excellent way to publish a service, especially one you run in production on your own domain. For a long-lived named tunnel you need a Cloudflare account and a domain whose DNS is on Cloudflare. Its quick tunnels on trycloudflare.com skip the account, but Cloudflare positions them for testing.

Consensus sits in between: one command, no account, no domain, with HTTP and TCP tunnels from the same CLI.

Terminal window
npm install -g @canister-software/consensus-cli
consensus tunnel http localhost:3000
ConsensusCloudflare Tunnel
Account requiredNoYes for named tunnels (quick tunnels: no)
Your own domain requiredNoYes for named tunnels
Public HTTPS URLYes, *.tunnel.canister.softwareYes, on your domain or trycloudflare.com
Raw TCP servicesYes, any client that can send the tunnel name firstYes, clients typically run cloudflared access
Access policies (SSO, device rules)NoYes (Cloudflare Access)
NetworkDecentralized nodesCloudflare’s global network
PriceFree during the public betaFree tier; paid Zero Trust plans
  • you want a public URL now and don’t want to set up an account, DNS, or a config file;
  • you don’t own a domain, or don’t want to move its DNS;
  • you need a quick TCP tunnel for an MQTT broker, database, or game server;
  • you’re already using Consensus for proxying, static IPs, or WebSockets.
  • the service is in production on your own domain;
  • you need SSO, device posture, or other access policies in front of it;
  • you want Cloudflare’s CDN, WAF, and DDoS protection on the same hostname.
CloudflareConsensus
cloudflared tunnel --url http://localhost:3000consensus tunnel http localhost:3000
Named tunnel + DNS route + config.ymlNot needed
cloudflared access tcp … on the clientClient sends the tunnel name, then talks normally (details)

Can I expose localhost without a Cloudflare account? Yes. Consensus tunnels need no account and no domain. Run consensus tunnel http localhost:3000 and share the URL it prints.

Does it work behind NAT or a firewall? Yes. The tunnel is an outbound connection from your machine, so no inbound ports need opening.

Is it free? Tunnels are free during the public beta.