Skip to main content
Two commands expose a service from a sandbox on a public HTTPS URL.
A service on 0.0.0.0 needs no flag. For a service that listens only on localhost, 127.0.0.1 or ::1, pass --localhost. See Services that listen on localhost.

boat host <sandbox-id> <port>

Expose a running service without an interactive SSH session:
The command does these steps:
  1. It opens the firewall for that port.
  2. It registers an HTTPS subdomain.
  3. It prints the URL.
If you run it again for the same sandbox and port, you get the same URL. Use --json to print a machine-readable object with sandboxId, port, url, access, isProtected and localhost. It is a single API call. This makes it the fastest way to host a port from a script:
For an ungated URL, pass {"public":true}. For a service that listens on localhost only, pass {"localhost":true}.
TypeScript

In-sandbox host <port>

Expose a running service on a stable HTTPS URL:
The command does these steps:
  1. It opens the firewall for that port.
  2. It registers an HTTPS subdomain.
  3. It prints the URL.
If you run it again for the same port, you get the same URL. A sandbox can host up to 50 ports. By default, host <port> creates a protected URL with a _token query parameter. This protection stays. If you host the same port again, the URL has the same _token, unless you pass --public. For raw access without HTTPS or a subdomain, open the port yourself with ufw. Then use http://<sandbox-ip>:<port> directly.

host list

Show the hosted ports of the current sandbox:
  • host list shows protected ports as (gated).
  • host list shows relayed ports as (localhost).
  • host list does not print the access token.
  • To print the full URL with _token=..., use host url <port>.

host url <port>

Wait until the HTTPS URL is ready, then print it:
For a protected port, it prints the full token-gated URL:
Use it when one service needs the public URL of another service:

host hide <port>

Take down the public URL:
  • It closes public access, unregisters the HTTPS route and turns off the localhost relay.
  • It does not stop the local server process. Stop the server yourself when you are done.
  • It keeps the access tokens. If you host the same port again, existing protected links stay valid.
To get an ungated URL after a port became protected, run host <port> --public.