NAiOS Tunnel
naios-tunnelv0.1.0Connect services that live on a PC or local server (SAP Service Layer, a database, an internal API, any TCP service) with NAiOS through an agent and a secure tunnel, without opening ports
Description
Install a small agent on the machine where the service runs (Windows with tray or Linux with systemd). The agent opens an OUTGOING connection to the NAiOS relay (tunnel.naios.net) — zero open ports — and from there you use it in two ways: 'MCP Custom' profiles that expose tools to the chat (SAP Service Layer, REST API, and read-only PostgreSQL/MySQL databases), or TCP forwards that open a local port for your own tools (psql, DBeaver…). Allowlist by device with port ranges, revocable tokens, and encrypted credentials. F0: superadmin only.
Features (4)
The client's machine agent connects outward; nothing needs to be opened on their router or firewall. Windows (tray) and Linux (systemd)
Own relay in NAiOS (no ngrok or Cloudflare); revocable token per device and allowlist of destinations with port ranges
MCP Custom profiles that expose tools: SAP Service Layer, REST API, and read-only PostgreSQL/MySQL databases
TCP forwards: open a port on your machine to the remote service (psql, DBeaver…), with a limited and expiring token