Skip to the page

Skip or avoid ngrok's browser warning page

Why ngrok's free plan shows visitors a warning page, how ngrok-skip-browser-warning works for API calls, and what to use when a client opens the link.

Updated

On ngrok's free plan, anyone who opens your link in a browser gets a warning page before your site. Code can skip it with one header. A person clicking your link can't, so when a client opens it, the fix is a paid plan or a tool that doesn't show one.

What the warning page is

“To deter phishing attacks, ngrok shows an interstitial page in front of all HTML browser traffic on the free tier.” The page tells visitors the site is served through ngrok and asks them to click Visit. Shown to free users since June 2022:

“This week we enabled an interstitial page for all new, free users of the ngrok platform”

ngrok blog, Fighting Abuse on the ngrok Platform

After the click, a cookie hides it on that domain for 7 days. A new browser, a private window or a colleague on another laptop sees it again. Any paid plan removes it, Hobbyist included.

Skip it for API calls: ngrok-skip-browser-warning

If your own code calls the tunnel, from a frontend on another address or from a script, send the header with any value:

“add a header value of ngrok-skip-browser-warning and set it to any value”

ngrok docs, Free plan limits
curl -H "ngrok-skip-browser-warning: 1" https://your-name.ngrok-free.app/api
fetch(url, {  headers: { "ngrok-skip-browser-warning": "1" },});

A non-standard User-Agent skips it too. A request from a browser page to another address with a custom header like this one is preflighted, so the server behind the tunnel must allow the header in its CORS answer. And ngrok says the page doesn't stop APIs or programmatic clients in the first place: webhooks from other services reach you as they are.

Why a header can't help a client

A link in an email or a chat can't carry a header. Your client clicks it, the browser asks for the page, and ngrok answers with the warning. Browser extensions that change the User-Agent work for you, not for someone you sent a link to. That leaves two ways out: pay for ngrok, where Hobbyist, $10 a month is the cheapest plan, or share with a tool that doesn't put a page in front of yours.

Other tunnels' warning pages

Most free tunnels have one, for the same reason: free links are used for phishing. Each has its own way past it.

As of , from each product's own pages (listed under Sources). Prices in US dollars.

Warning pages on free tunnels, how code skips them, and what removes them
How code skips itWhat removes it
ngrokRequests with an ngrok-skip-browser-warning header, any value, skip itHobbyist, $10 a month
PinggyAn X-Pinggy-No-Screen header, any value, skips it. So does a custom User-AgentPro, $3 a seat a month, or $2.50 billed yearly
serveoA serveo-skip-browser-warning: true header skips itPro, $6 a month or $60 a year
zrokA skip_zrok_interstitial header, any value, skips it. Its cookie lasts a weekYes, on free accounts; adding a card removes it
Microsoft dev tunnelsAn X-Tunnel-Skip-AntiPhishing-Page header skips it. It isn't shown to requests other than GET, or without text/html in AcceptNot stated
localtunnelA bypass-tunnel-reminder header is meant to skip it; people report it still showingNot stated
ouicuNone needed: only page loads see itHobby, $4 a month

localtunnel's page is the hardest on a client: visitors must type a tunnel password: your public IP address, from loca.lt/mytunnelpassword. A service calling your tunnel can't add that header, and its IP won't match the password.

ouicu's notice, honestly

ouicu's Free plan has a notice too. It shows the address, says the site runs on someone's computer and reaches the visitor through ouicu, and offers an Open the preview button. It differs in where it stands:

  • Only in front of a page load in a browser. A fetch, an XHR, a WebSocket, an image or a script goes straight through, and so does a webhook from another server. No header is needed, and none skips it.
  • Each browser sees it once a week for each share, then goes straight to your page.
  • A small Report button sits in a corner of every preview, on every plan, so anyone can tell ouicu about one that looks wrong. Reports go to ouicu.

On Hobby and Pro, there is no notice: the link opens on your page.

Where ngrok is better

The warning is the price of a free plan that gives a lot:

Questions people ask

How do I bypass the ngrok browser warning?

From code, send ngrok-skip-browser-warning with any value, or a User-Agent of your own. For people opening the link, only a paid ngrok plan removes it.

Is ngrok safe to use?

The warning exists because free tunnel links get used for phishing, so it protects visitors, not you. What you share is your own risk: a tunnel reaches whatever runs on the port, debug pages included.

Does ouicu show a warning page?

On Free, a notice once a week per browser and share, on page loads only. On Hobby and Pro, none.

Share without a warning page

With ouicu installed and logged in (see Getting started), share the port your dev server listens on:

ouicu share 3000

Keep the name, add a password (Hobby and Pro)

For a client, keep one name and put a password on it. Visitors type the password on a page of ouicu's, then see your site:

ouicu share 3000 --name studiolund --password

The pricing lists what each plan includes. For the same comparison across ngrok's limits and prices, see ngrok vs ouicu, and for other tools, ngrok alternatives.

Sources

Prices, defaults and quotes about other products, and the day each was last checked at its source.

  1. Free plan limits, ngrok docs. Checked .
  2. Fighting Abuse on the ngrok Platform, ngrok blog. Checked .
  3. Pricing, ngrok. Checked .
  4. Browser Screening Page, Pinggy docs. Checked .
  5. Simple Localhost Tunnels, Pinggy. Checked .
  6. Documentation, Serveo. Checked .
  7. Expose local servers to the internet, Serveo. Checked .
  8. interstitial-page.md, zrok on GitHub. Checked .
  9. zrok Pricing, zrok. Checked .
  10. Dev tunnels security, Microsoft Learn. Checked .
  11. Issue 663: bypass-tunnel-reminder Http Header not working, localtunnel on GitHub. Checked .
  12. Issue 648: IP password is not being accepted, localtunnel on GitHub. Checked .
  13. Issue 727: URL parameter to bypass interstitial page for programmatic access, localtunnel on GitHub. Checked .
  14. Domains, ngrok docs. Checked .
  15. Inspect Traffic and Replay Requests, ngrok docs. Checked .
  16. Authentication, ngrok docs. Checked .