A localtunnel alternative without the IP password
localtunnel's public server makes visitors type your IP address before they see your site. Why, how code skips it, and a link a client opens in one step.
By Mads Sauer, who makes ouicu, one of the tools here, so read it as a maker's comparison: each fact about another product links to that product's own page, read on . Published .
localtunnel is free, open source and needs no account. But its public server puts a reminder page in front of every browser visit, and since May 2023 that page wants a password: the public IP address of the computer sharing the site. For a client, that is a confusing first step, and it hands them your address. ouicu gives a link they open with one click on Free, and with nothing in the way on Hobby and Pro.
At a glance
As of , from each product's own pages (listed under Sources). Prices in US dollars.
| Paid from | Free plan | Warning page on free | Passwords and sign-in | Same link each time | Protocols | Open source | |
|---|---|---|---|---|---|---|---|
| localtunnel | Sponsor, $5 a month: custom subdomains and higher rate limits | Random subdomains, with basic rate limits | Visitors must type a tunnel password: your public IP address, from loca.lt/mytunnelpassword | None of its own: the reminder page is the only gate | A name you ask for with --subdomain isn't promised | Not stated | Yes, MIT; you can run your own server |
| ouicu | Hobby, $4 a month | 1 share at a time, 2 hours each, 1 GB a month | Yes, a notice on page loads, once a week per browser and share; none on Hobby and Pro | Password on Hobby and Pro; invited emails on Pro | Reserved names on Hobby and Pro | HTTP and WebSockets, web pages only | No; the MCP server and SDK are MIT |
The reminder page and its IP password
Open a loca.lt link in a browser and the first page is headed “Tunnel Website Ahead!”, not your site. Its operator added it because the free subdomains were hosting phishing pages. When a page with a button wasn't enough, a password followed:
“all tunnels now require a real user to enter the endpoint IP address (which acts like your tunnel link's password) on the consent page.”
In practice: visitors must type a tunnel password: your public IP address, from loca.lt/mytunnelpassword. When we opened a tunnel on , the page printed the sharer's address itself, above the box, so a visitor only has to copy it. Either way, everyone you send the link to learns your public IP address, and with it roughly where you are.
- How often: once per subdomain and visitor IP address, every 7 days. A client who opens the link on their phone, then at home, types it again.
- Who sees it: “The page will only show up for requests coming from browsers.” Scripts and most webhooks go straight through; a person clicking your link never does.
Its new site still offers it for client work: “Share your work in progress with clients and stakeholders.” That is the case where the reminder page hurts most, because the client is the one who meets it.
When it says the endpoint IP is not correct
A visitor who types the wrong address gets this:
Error: endpoint IP is not correct. Please try again or contact whoever gave you this link for the correct public IP.
- The password is the address of the machine running
lt. On a cloud notebook, a container host or a server, that is the machine's address, not yours. - A VPN gives your computer a public address other than your connection's, and home connections get a new one now and then, so last week's password can stop working.
- It has failed on the server side too: in January 2025 the check turned correct addresses away for days, until the operator fixed it.
To read the right address, ask from the machine running lt:
curl https://loca.lt/mytunnelpasswordSkipping the page in code
For requests your own code makes, there are two ways past it:
- A
bypass-tunnel-reminderheader is meant to skip it; people report it still showing. It worked when we tried it on . - A non-standard User-Agent, like
localtunnel, skips it.
curl -H "bypass-tunnel-reminder: true" https://your-name.loca.lt/api/healthA service that fetches pages like a browser, such as a screenshot or PDF tool, is stuck: a service calling your tunnel can't add that header, and its IP won't match the password. Neither way helps a client clicking a link in an email either, since their browser sends a normal User-Agent and no extra header. The guide to ngrok's warning page compares these headers across tunnels.
Is localtunnel still maintained?
The open source parts are quiet, and the public server runs code that isn't published:
- The client's last release is 2.0.2, from September 2021.
- The server's code last changed in March 2019.
- An open issue reports high-severity npm audit advisories in the client's axios dependency.
- Users reported tunnels answering 503 from December 2025 into January 2026.
“The version running on the public localtunnel server is slightly more modified with the consent page middleware and not publically available”
The public server now has a paid tier: Sponsor, $5 a month: custom subdomains and higher rate limits. The pricing page doesn't say whether sponsors skip the reminder page.
Run your own localtunnel server
The operator recommends it:
“It's easy to run your own fork on any domain you control and I highly recommend running a private one yourself.”
Your own server runs the open code, which has no consent page, so visitors go straight to your site. You need:
- A server of your own needs DNS for a domain and its wildcard,
*.domain.tld, and open TCP ports above 1000. - A reverse proxy in front of it for https, on a machine that stays up.
lt --hostpoints the client at your server instead of localtunnel.me.
lt --host https://tunnel.example.com --port 5173The open code has no password or sign-in, so anyone who finds a name on your server reaches your dev server. Put basic auth in the proxy if that matters.
Vite, Next.js and the Host header
By default the client hands your dev server the loca.lt name as Host: we saw it on . Vite then answers Blocked request. This host ("your-name.loca.lt") is not allowed. --local-host sends requests to another host, and sets the Host header to it, which gets you past it:
lt --port 5173 --local-host localhostouicu does the same on every share without a flag: Host is localhost:5173, the public address is in X-Forwarded-Host, and hot reload WebSockets get a local Origin, so Next.js accepts them too.
Where localtunnel is better
- Client and server are MIT-licensed, and you can run the server yourself.
- No sign-up:
npx localtunnel --port 8000is the whole setup. - A link lasts for as long as
ltruns. --local-httpsreaches a dev server that only speaks https.
ouicu has no option for a dev server that only speaks https: it expects plain http on localhost. Its code isn't open either, apart from the MCP server and SDK, and you can't run your own server.
Where ouicu fits better
- No password page and no IP address on show. Free shows a notice with one button, once a week per browser and share, on page loads only; Hobby and Pro show nothing.
- A password you choose, with Hobby and Pro. A browser that typed it stays in for 7 days.
- Names that stay yours, with Hobby and Pro, instead of a subdomain you may not get back.
- An email when someone opens the link, with Hobby and Pro, and the last version kept up while your laptop sleeps, with Hobby and Pro.
On Free, a share runs 2 hours; for longer, Hobby is $4 a month.
Questions people ask
What is the localtunnel password?
The public IP address of the machine running lt. Open loca.lt/mytunnelpassword from that machine to see it, and send it to your visitors.
How do I get rid of the localtunnel reminder page?
In code, send the bypass-tunnel-reminder header. For people, run your own server, or use a tool without one for browsers.
Is localtunnel down?
Its public server has had outages that users reported on GitHub, like the one above. If tunnels hang or fail, try again later, or run your own server.
Is there a localtunnel alternative with no password page?
Cloudflare's Quick Tunnels: as for a warning page, none in the Quick Tunnel docs' list of limits, though they give a new name each run; see Cloudflare Tunnel vs ouicu. ouicu shows a one-click notice on Free and none on Hobby and Pro.
Try ouicu
Install it (Getting started), then share the port your dev server listens on:
ouicu share 5173For a client, keep the name and add a password (Hobby and Pro):
ouicu share 5173 --name acme --passwordSources
Prices, defaults and quotes about other products, and the day each was last checked at its source.
- Issue 598: Tunnel Consent page now requires a password, localtunnel on GitHub. Checked .
- Pricing, LocalTunnel. Checked .
- Issue 648: IP password is not being accepted, localtunnel on GitHub. Checked .
- localtunnel/localtunnel, localtunnel on GitHub. Checked .
- localtunnel/server, localtunnel on GitHub. Checked .
- Issue 663: bypass-tunnel-reminder Http Header not working, localtunnel on GitHub. Checked .
- Issue 366: How to avoid Friendly Reminder page, localtunnel on GitHub. Checked .
- LocalTunnel - Expose your localhost to the world, LocalTunnel. Checked .
- Issue 693: Error: endpoint IP is not correct. Please try again or contact whoever gave you this link for the correct public IP., localtunnel on GitHub. Checked .
- Issue 727: URL parameter to bypass interstitial page for programmatic access, localtunnel on GitHub. Checked .
- localtunnel, npm. Checked .
- Issue 724: Is localtunnel even maintained? Still has CRITICAL SECURITY VULNERABILITY (axios) from 2 years ago, localtunnel on GitHub. Checked .
- Issue 726: Consistent 503 errors, localtunnel on GitHub. Checked .
- Quick Tunnels, Cloudflare docs. Checked .