Open someone's local app — through an encrypted channel.
Advanced
The password is the only thing that decrypts this session.
Without it the code alone shows you nothing.
What makes this different
There is no public URL. The app you're about to see isn't published anywhere — a tunnel like ngrok creates an address the whole internet can reach, and scanners find those within minutes. This one has no address at all.
Nothing inbound is opened. The host machine only makes outbound connections. No port forwarding, no firewall change.
The relay carries ciphertext. Requests and responses are sealed with AES-256-GCM using a key derived from the password, in the browser and in the host process.
It ends when they say so. Close the porthole and the session is simply gone — there is no lingering endpoint to forget about.