Skip to the page

Share a Next.js dev server, with or without allowedDevOrigins

Next.js 16.2 blocks dev resources from other origins by default. Share next dev with a public link and working hot reload, no config change.

Updated

Since 16.2.0, next dev refuses requests for its dev resources from any origin it doesn't know, hot reload's socket included. Through a tunnel that passes the public origin on, the page loads but never updates. Add the host to allowedDevOrigins, or share with ouicu, which needs no change.

Next.js at a glance
Next.js
Dev server port3000
On your Wi-FiAlready, on 0.0.0.0
Host checkallowedDevOrigins
Build folder to uploadout, from next build

When the check came, version by version

The check guards /_next/ and /__nextjs, where the dev server keeps its scripts, its hot reload socket and its error overlay. It came with a security fix and has changed three times since; each version links to where it is written down:

Next.js and requests from other origins, by version
VersionReleasedAnother origin gets
15.2.211 March 2025Refused, hot reload's socket included, with nothing in the terminal
15.2.318 March 2025Still refused, and the terminal says so
15.2.424 March 2025Only a warning, unless allowedDevOrigins is set
16.2.018 March 2026Refused by default: other origins need allowedDevOrigins

We ran each of those against a hot reload socket from https://calm-otter-4821.ouicu.app, and the warning through to 16.1.7. From 15.2.4, setting allowedDevOrigins at all turns the warning into a refusal for the origins it leaves out.

What it lets in, in its docs' words: “The dev server already allows localhost, its subdomains, and the hostname it was started with.” An address on your Wi-Fi, like 192.168.1.20, isn't one of them.

The error messages, by version

From 16.2.0, the terminal running next dev prints:

In the terminal, from that version on
Blocked cross-origin request to Next.js dev resource /_next/hmr from "calm-otter-4821.ouicu.app".

It goes on: “Cross-origin access to Next.js dev resources is blocked by default for safety.” The browser's request gets Unauthorized back, so hot reload never connects and edits never show. Before that, from 15.2.4, the same request only earned a warning:

In the terminal, in the versions that only warned
Cross origin request detected from calm-otter-4821.ouicu.app to /_next/* resource. In a future major version of Next.js, you will need to explicitly configure "allowedDevOrigins" in next.config to allow this.

15.2.3 refused it, and said:

In the terminal, in the version before them
Blocked cross-origin request from calm-otter-4821.ouicu.app. To allow this, configure "allowedDevOrigins" in next.config

15.2.2 refused it without a word.

Allow an origin

List host names in next.config.ts, without https:// or a port, then restart next dev. A * stands for one label of the name, ** for several:

import type { NextConfig } from "next"; const nextConfig: NextConfig = {  allowedDevOrigins: ["*.ouicu.app", "192.168.1.20"],}; export default nextConfig;

Share next dev with ouicu

Start the dev server as usual, then share its port in a second terminal. Getting started has the install.

npm run dev# in a second terminalouicu share 3000

Nothing goes in next.config.ts. ouicu hands next dev each request for /_next/ and /__nextjs, and each WebSocket, with the origin http://localhost:3000: one it allows. Every other request keeps its real origin, so the check still keeps other sites out.

In 16.4.0, hot reload's socket is /_next/hmr. Through the link it connects to wss://calm-otter-4821.ouicu.app/_next/hmr, and an edit to app/page.tsx shows without a reload.

On your phone over Wi-Fi

next dev already listens on 0.0.0.0, every address, and its Network line shows yours. But from 16.2.0, a phone at http://192.168.1.20:3000 has its hot reload socket refused until that address is in allowedDevOrigins. A ouicu link skips both: scan the QR code it prints (QR codes). Both ways are in how to open localhost on your phone.

Server Actions errors

Server Actions have a check of their own. The docs:

“To prevent CSRF attacks, Next.js compares the host in a request's Origin header against the app's own host, taken from x-forwarded-host or host, and rejects the action when the two differ.”

Next.js docs, serverActions

ouicu sends X-Forwarded-Host with the public name, so a form with an action works through the link. Behind a proxy that sets Host to localhost and passes nothing on, the action fails with 500, and the terminal says:

In the terminal
`x-forwarded-host` header with value `localhost:3000` does not match `origin` header with value `calm-otter-4821.ouicu.app` from a forwarded Server Actions request. Aborting the action.

Then add the public name to the actions' own list, which takes the same * and **:

experimental: {  serverActions: { allowedOrigins: ["*.ouicu.app"] },},

Upload a static export

For a link that stays up with your laptop closed, export the site and upload it. Add output: "export" to next.config.ts, and next build writes it to out:

npm run buildouicu deploy out

The 16.4.0 starter can't export as it comes. It turns on cacheComponents and partialPrefetching, and the build stops with Error: Invariant: PPR cannot be enabled in export mode. Take both lines out and it builds.

Server Actions don't export either: “Features that require a Node.js server, or dynamic logic that cannot be computed during the build process, are not supported”. Share next dev for those. No --spa is needed: an upload answers /about with about.html, as the export writes it (Uploading a built site). For showing it to a client, see show a client a website before it goes live.

Tested with Next.js 16.4.0 on , with Node 24.21.0: npx create-next-app@latest with its defaults and a Server Action added, shared with ouicu share through ouicu's edge and opened in Chromium at its https link, and through a tunnel that keeps the public origin; its static export; and next dev from 15.2.2 to 16.2.0, for the table above.

Sources

Prices, defaults and quotes about other products, and the day each was last checked at its source.

  1. next: versions, npm. Checked .
  2. next CLI, Next.js docs. Checked .
  3. Static Exports, Next.js docs. Checked .
  4. GHSA-3h52-269p-cp9r (CVE-2025-48068), Next.js, GitHub advisory database. Checked .
  5. block-cross-site.ts at v15.2.3, Next.js on GitHub. Checked .
  6. block-cross-site.ts at v15.2.4, Next.js on GitHub. Checked .
  7. allowedDevOrigins, Next.js docs. Checked .
  8. block-cross-site-dev.ts, Next.js on GitHub. Checked .
  9. serverActions, Next.js docs. Checked .
  10. action-handler.ts, Next.js on GitHub. Checked .