Share a Vite dev server without touching allowedHosts
Fix 'Blocked request. This host is not allowed' and get a link to your Vite dev server that works on any phone or laptop, with hot reload.
Updated
Vite answers only the hosts it knows, so a tunnel that passes your public address on gets a page that starts with Blocked request. Add the name to server.allowedHosts, or share the dev server with ouicu, which hands Vite localhost and needs no change at all. Hot reload keeps working either way.
| Vite | |
|---|---|
| Dev server port | 5173 |
| On your Wi-Fi | npm run dev -- --host |
| Host check | server.allowedHosts |
| Build folder to upload | dist, from npm run build |
Blocked request. This host is not allowed
Open your dev server through a tunnel and Vite answers this:
Blocked request. This host ("calm-otter-4821.ouicu.app") is not allowed.To allow this host, add "calm-otter-4821.ouicu.app" to `server.allowedHosts` in vite.config.js.Vite added the check on 20 January 2025, in versions 6.0.9, 5.4.12 and 4.5.6, for CVE-2025-24010. The advisory's summary: without it, “an attacker can send arbitrary requests to the development server bypassing the same-origin policy.” Now Vite's docs say: “localhost and domains under .localhost and all IP addresses are allowed by default.”
Add the host to server.allowedHosts
With a tunnel that keeps the public name, list it in vite.config.js and restart the dev server. A leading dot allows the name and every name under it:
import { defineConfig } from 'vite' export default defineConfig({ server: { allowedHosts: ['.ouicu.app'], },})vite preview checks too, against a setting of its own, and says so:
To allow this host, add "calm-otter-4821.ouicu.app" to `preview.allowedHosts` in vite.config.js.Setting either to true lets every host in. Vite warns:
“Setting server.allowedHosts to true allows any website to send requests to your dev server through DNS rebinding attacks, allowing them to download your source code and content.”
Or rewrite the Host header
The check reads the Host header. A tunnel that rewrites it to localhost passes with no setting: with ngrok, --host-header=rewrite sends your local address as the Host header, and ouicu does it for every share. The public name travels on in X-Forwarded-Host, with X-Forwarded-Proto: https.
Share it with ouicu
Start Vite as usual. Then, in a second terminal, share its port. If you haven't installed ouicu yet, Getting started has the one-line install.
npm run dev# in a second terminalouicu share 5173There's no --host to add and no allowedHosts to set: ouicu connects to Vite on localhost, whichever address it listens on, and Vite sees each request as coming to localhost:5173. The line Vite prints as it starts, Network: use --host to expose, is about your Wi-Fi, not the link. And mind the port: “Note if the port is already being used, Vite will automatically try the next available port so this may not be the actual port the server ends up listening on.”
On Free, a share runs for up to 2 hours, and visitors see a short notice from ouicu before your page.
Hot reload through a link
Vite's page opens its hot reload socket to the address in the browser's bar, so through the link it dials wss://calm-otter-4821.ouicu.app/ on the link's own port. ouicu hands that socket to Vite as coming from localhost. Save a file and the page updates on every screen that has the link open.
It breaks when the config pins the client to another port, as some Docker set-ups do with clientPort: 5173. The browser's console then says:
[vite] failed to connect to websocket (Error: WebSocket closed without opened.).Remove the pin, or point it at the link's port, 443. Since Vite 8.1.0, released on 23 June 2026, the setting lives under server.ws; the changelog says “rename server.hmr options to server.ws options”. The old server.hmr.clientPort still works.
server: { ws: { clientPort: 443 },},On your phone
ouicu draws the link as a QR code in your terminal. Scan it and the site opens on the phone, on Wi-Fi or mobile data, over https, with hot reload as on your laptop (QR codes). To use the same Wi-Fi without a link, Vite needs npm run dev -- --host; how to open localhost on your phone has both ways.
Vue, React, Svelte and Preact
Every starter npm create vite@latest makes shares the same way, with nothing changed. In each, we changed the heading while the page was open through the link:
| Starter | Template | An edit through the link |
|---|---|---|
| React 19.3.0 | react-ts | Shows in place |
| Vue 3.5.43 | vue-ts | Shows in place |
| Svelte 5.57.2 | svelte-ts | Shows in place |
| Preact 10.29.8 | preact-ts | Shows in place |
| No framework | vanilla-ts | The page reloads: the starter has no hot module boundary |
For React apps still on Create React App, see share a React app from localhost.
Upload the build instead
For a client who looks later, with your laptop closed, upload the build. vite build writes it to dist:
npm run buildouicu deploy dist --spa--spa answers paths with no file with index.html, for apps with routing in the browser. On Free, an upload stays up for 7 days. More in Uploading a built site and show a client a website before it goes live.
Troubleshooting
- Blocked request from
vite preview: it checkspreview.allowedHosts, not the server setting. Through ouicu it passes, as the dev server does. [vite] failed to connect to websocket: a pinned port, as under hot reload.- “The site isn't running yet”: nothing listens on the port you shared. Start Vite, or share the port it printed.
Tested with Vite 8.3.3 on , with Node 24.21.0: the react-ts, vue-ts, svelte-ts, preact-ts and vanilla-ts starters from npm create vite@latest, each shared with ouicu share through ouicu's edge and opened in Chromium at its https link; and Vite 6.0.8 next to 6.0.9, for when the check came.
Sources
Prices, defaults and quotes about other products, and the day each was last checked at its source.
- Server Options, Vite docs. Checked .
- Building for Production, Vite docs. Checked .
- hostCheck.ts, Vite on GitHub. Checked .
- GHSA-vg6x-rcgg-rjx6 (CVE-2025-24010), Vite, GitHub advisory database. Checked .
- Preview Options, Vite docs. Checked .
- Virtual hosts, ngrok docs. Checked .
- client.ts, Vite on GitHub. Checked .
- packages/vite/CHANGELOG.md, Vite on GitHub. Checked .