Skip to the page

Share a Vite dev server without touching allowedHosts

Fix 'Blocked request. This host is not allowed' and get a link to your Vite dev server that works on any phone or laptop, with hot reload.

Updated

Vite answers only the hosts it knows, so a tunnel that passes your public address on gets a page that starts with Blocked request. Add the name to server.allowedHosts, or share the dev server with ouicu, which hands Vite localhost and needs no change at all. Hot reload keeps working either way.

Vite at a glance
Vite
Dev server port5173
On your Wi-Finpm run dev -- --host
Host checkserver.allowedHosts
Build folder to uploaddist, from npm run build

Blocked request. This host is not allowed

Open your dev server through a tunnel and Vite answers this:

What the browser shows
Blocked request. This host ("calm-otter-4821.ouicu.app") is not allowed.To allow this host, add "calm-otter-4821.ouicu.app" to `server.allowedHosts` in vite.config.js.

Vite added the check on 20 January 2025, in versions 6.0.9, 5.4.12 and 4.5.6, for CVE-2025-24010. The advisory's summary: without it, “an attacker can send arbitrary requests to the development server bypassing the same-origin policy.” Now Vite's docs say: “localhost and domains under .localhost and all IP addresses are allowed by default.”

Add the host to server.allowedHosts

With a tunnel that keeps the public name, list it in vite.config.js and restart the dev server. A leading dot allows the name and every name under it:

import { defineConfig } from 'vite' export default defineConfig({  server: {    allowedHosts: ['.ouicu.app'],  },})

vite preview checks too, against a setting of its own, and says so:

From vite preview
To allow this host, add "calm-otter-4821.ouicu.app" to `preview.allowedHosts` in vite.config.js.

Setting either to true lets every host in. Vite warns:

“Setting server.allowedHosts to true allows any website to send requests to your dev server through DNS rebinding attacks, allowing them to download your source code and content.”

Vite docs, Server Options

Or rewrite the Host header

The check reads the Host header. A tunnel that rewrites it to localhost passes with no setting: with ngrok, --host-header=rewrite sends your local address as the Host header, and ouicu does it for every share. The public name travels on in X-Forwarded-Host, with X-Forwarded-Proto: https.

Share it with ouicu

Start Vite as usual. Then, in a second terminal, share its port. If you haven't installed ouicu yet, Getting started has the one-line install.

npm run dev# in a second terminalouicu share 5173

There's no --host to add and no allowedHosts to set: ouicu connects to Vite on localhost, whichever address it listens on, and Vite sees each request as coming to localhost:5173. The line Vite prints as it starts, Network: use --host to expose, is about your Wi-Fi, not the link. And mind the port: “Note if the port is already being used, Vite will automatically try the next available port so this may not be the actual port the server ends up listening on.”

On Free, a share runs for up to 2 hours, and visitors see a short notice from ouicu before your page.

Hot reload through a link

Vite's page opens its hot reload socket to the address in the browser's bar, so through the link it dials wss://calm-otter-4821.ouicu.app/ on the link's own port. ouicu hands that socket to Vite as coming from localhost. Save a file and the page updates on every screen that has the link open.

It breaks when the config pins the client to another port, as some Docker set-ups do with clientPort: 5173. The browser's console then says:

In the browser console
[vite] failed to connect to websocket (Error: WebSocket closed without opened.).

Remove the pin, or point it at the link's port, 443. Since Vite 8.1.0, released on 23 June 2026, the setting lives under server.ws; the changelog says “rename server.hmr options to server.ws options”. The old server.hmr.clientPort still works.

server: {  ws: { clientPort: 443 },},

On your phone

ouicu draws the link as a QR code in your terminal. Scan it and the site opens on the phone, on Wi-Fi or mobile data, over https, with hot reload as on your laptop (QR codes). To use the same Wi-Fi without a link, Vite needs npm run dev -- --host; how to open localhost on your phone has both ways.

Vue, React, Svelte and Preact

Every starter npm create vite@latest makes shares the same way, with nothing changed. In each, we changed the heading while the page was open through the link:

Vite starters through a ouicu link
StarterTemplateAn edit through the link
React 19.3.0react-tsShows in place
Vue 3.5.43vue-tsShows in place
Svelte 5.57.2svelte-tsShows in place
Preact 10.29.8preact-tsShows in place
No frameworkvanilla-tsThe page reloads: the starter has no hot module boundary

For React apps still on Create React App, see share a React app from localhost.

Upload the build instead

For a client who looks later, with your laptop closed, upload the build. vite build writes it to dist:

npm run buildouicu deploy dist --spa

--spa answers paths with no file with index.html, for apps with routing in the browser. On Free, an upload stays up for 7 days. More in Uploading a built site and show a client a website before it goes live.

Troubleshooting

  • Blocked request from vite preview: it checks preview.allowedHosts, not the server setting. Through ouicu it passes, as the dev server does.
  • [vite] failed to connect to websocket: a pinned port, as under hot reload.
  • “The site isn't running yet”: nothing listens on the port you shared. Start Vite, or share the port it printed.

Tested with Vite 8.3.3 on , with Node 24.21.0: the react-ts, vue-ts, svelte-ts, preact-ts and vanilla-ts starters from npm create vite@latest, each shared with ouicu share through ouicu's edge and opened in Chromium at its https link; and Vite 6.0.8 next to 6.0.9, for when the check came.

Sources

Prices, defaults and quotes about other products, and the day each was last checked at its source.

  1. Server Options, Vite docs. Checked .
  2. Building for Production, Vite docs. Checked .
  3. hostCheck.ts, Vite on GitHub. Checked .
  4. GHSA-vg6x-rcgg-rjx6 (CVE-2025-24010), Vite, GitHub advisory database. Checked .
  5. Preview Options, Vite docs. Checked .
  6. Virtual hosts, ngrok docs. Checked .
  7. client.ts, Vite on GitHub. Checked .
  8. packages/vite/CHANGELOG.md, Vite on GitHub. Checked .