CLI Reference
Auto-generated from the client source code. Do not edit manually. Client version:
0.1.0-dev
nullbore open
Open one or more tunnels to expose local ports
nullbore open <port>
nullbore open --port <port> [--name <name>] [--ttl <duration>]
nullbore open -p <port>[:<name>] [-p <port>[:<name>] ...]
nullbore open <port> [<port> ...]
Creates a tunnel on the server and relays traffic from the public URL to your local port. Stays open until the TTL expires or you press Ctrl+C.
With --tls-passthrough the relay forwards raw TLS bytes without decrypting them, so traffic is encrypted end-to-end. Your local service must serve TLS itself and visitors see its certificate. The relay cannot inspect requests or add basic auth, so --auth cannot be combined with it. Available on paid plans only.
Requires an API key.
Flags:
--auth Basic auth for tunnel access (user:pass)
--host Target host (for Docker/remote services) (default: localhost)
--name Tunnel name / custom subdomain (Dev+ plans)
--port Local port to expose (single tunnel)
--tls-passthrough End-to-end TLS passthrough: the relay forwards raw encrypted bytes and never decrypts them. Your local service must serve TLS itself (visitors see its certificate). The relay cannot inspect requests or add basic auth (--auth). Paid plans only
--ttl Time-to-live (e.g. 30m, 2h, 24h) (default: 1h)
-p <port> or <port>:<name> Repeatable. Open multiple tunnels.
Format: PORT or PORT:NAME
Example: -p 3000:api -p 8080:web
Examples:
nullbore open 3000 # expose localhost:3000
nullbore open --port 3000 --name myapp # with custom subdomain
nullbore open --port 3000 --ttl 30m # 30-minute TTL
nullbore open -p 3000:api -p 8080:web # multiple named tunnels
nullbore open 3000 8080 5432 # multiple tunnels (positional)
nullbore open --port 3000 --auth admin:s3cret # with basic auth
nullbore open --port 8443 --tls-passthrough # end-to-end TLS (local service serves TLS)
nullbore list
List active tunnels
nullbore list
Shows all tunnels currently open for your API key, with their IDs, slugs, ports, and expiry times.
Requires an API key.
nullbore close
Close a tunnel
nullbore close <tunnel-id-or-name>
Closes the specified tunnel. You can use the full tunnel ID, the short ID prefix from nullbore list, or the tunnel's slug/name.
Arguments: The tunnel ID (or first 8 chars), slug, or name.
Requires an API key.
nullbore requests
Inspect recent HTTP requests to a tunnel
nullbore requests <tunnel-id-or-slug> [--limit N]
Shows recent HTTP requests that hit your tunnel — method, path, body size, and source IP. Useful for debugging webhooks.
Arguments: The tunnel ID or slug to inspect.
Requires an API key.
Flags:
--limit Number of requests to show (default: 20)
nullbore status
Check server connection and auth status
nullbore status
Pings the tunnel server and reports its version. Shows whether an API key is configured.
nullbore daemon
Run in dashboard-driven persistent mode
nullbore daemon
Connects to the NullBore dashboard and manages tunnels based on your dashboard configuration. Tunnels activate/deactivate remotely without restarting the daemon.
For static/headless mode (Docker), set NULLBORE_TUNNELS instead:
NULLBORE_TUNNELS=host:port:slug,host:port:slug,...
Example: NULLBORE_TUNNELS=webapp:3000:my-app,db:5432:my-db
Append +tls-passthrough to an entry for end-to-end TLS passthrough (the service must serve TLS; paid plans): NULLBORE_TUNNELS=caddy:443:secure+tls-passthrough,webapp:3000:my-app
Requires an API key.
nullbore acme
ACME DNS-01 hook for publicly trusted end-to-end tunnel certificates
nullbore acme present [--no-wait] [--wait-timeout 120s] <fqdn> <value>
nullbore acme cleanup <fqdn> <value>
End-to-end (--tls-passthrough) tunnels are served at <tunnel>.<account>.e2e.nullbore.com, and your local service presents its own certificate. nullbore acme lets any ACME client obtain a publicly trusted certificate for that name, or the wildcard *.<account>.e2e.nullbore.com, using the DNS-01 challenge: present asks the NullBore server to publish the _acme-challenge TXT record, cleanup removes it. Only the challenge value is sent to NullBore; the private key is generated and stays on your machine. Paid plans only.
By default present then waits (up to --wait-timeout) until 1.1.1.1 and 8.8.8.8 serve the record, so ACME clients that don't check propagation still work. cleanup succeeds if the record is already gone.
The argument order matches lego's exec provider, which runs $EXEC_PATH present <fqdn> <value> and $EXEC_PATH cleanup <fqdn> <value>. Point EXEC_PATH at a two-line wrapper script:
#!/bin/sh
exec nullbore acme "$@"
Then serve the issued certificate and key (lego writes them to ~/.lego/certificates/ with --path ~/.lego) from your local TLS server.
Arguments: <fqdn> is the challenge name (e.g. _acme-challenge.ACCOUNT.e2e.nullbore.com; a trailing dot is accepted) and <value> the TXT value supplied by your ACME client.
Requires an API key.
Flags:
--no-wait Return as soon as the server accepts the record
--wait Wait for 1.1.1.1 and 8.8.8.8 to serve the record (default)
--wait-timeout <dur> Stop waiting after this long; the command still succeeds (default: 120s)
Examples:
printf '#!/bin/sh\nexec nullbore acme "$@"\n' > ~/bin/nullbore-acme-hook && chmod +x ~/bin/nullbore-acme-hook
EXEC_PATH=~/bin/nullbore-acme-hook lego run --accept-tos --path ~/.lego --dns exec --domains '*.ACCOUNT.e2e.nullbore.com'
nullbore acme present _acme-challenge.ACCOUNT.e2e.nullbore.com. TOKEN # manual
nullbore acme cleanup _acme-challenge.ACCOUNT.e2e.nullbore.com. TOKEN
nullbore update
Check for updates and self-update
nullbore update
nullbore update --check
Checks GitHub for a newer release. Without --check, downloads and replaces the binary.
Flags:
--check Only check for updates, don't install
nullbore version
Show client version
nullbore version
nullbore help
Show help
nullbore help
Environment Variables
Environment variables override config file values.
| Variable | Description | Default |
|---|---|---|
NULLBORE_SERVER | Tunnel server URL (must include https://) | https://tunnel.nullbore.com |
NULLBORE_API_KEY | API key for authentication | — |
NULLBORE_DASHBOARD | Dashboard URL (for daemon mode) | https://nullbore.com |
NULLBORE_TLS_SKIP_VERIFY | Skip TLS certificate verification (set to 1 or true) | — |
NULLBORE_TUNNELS | Static tunnel list for Docker/headless mode (format: host:port:slug,...; append +tls-passthrough to an entry for end-to-end TLS) | — |
NULLBORE_INSTALL_DIR | Override install directory for install.sh | ~/.local/bin |
NULLBORE_VERSION | Pin a specific version for install.sh | — |
Important: Use
exportwhen setting environment variables in your shell. Withoutexport, the variable is only a shell variable and won't be passed tonullbore.# Wrong: NULLBORE_API_KEY="nbk_..." # shell variable only nullbore open 3000 # won't see the key # Right: export NULLBORE_API_KEY="nbk_..." nullbore open 3000
Config File
The client reads ~/.config/nullbore/config.toml on startup.
Legacy path
~/.nullbore/config.tomlis still supported.
# ~/.config/nullbore/config.toml
server = "https://tunnel.nullbore.com"
api_key = "nbk_your_key_here"
default_ttl = "1h"
debug = false
# Persistent tunnels (managed by daemon)
[[tunnels]]
name = "api"
port = 3000
# auth = "user:pass" # optional: require basic auth on this tunnel
# mode = "tls-passthrough" # optional: end-to-end TLS (local service must serve TLS; not with auth)
Edit the file directly — there is no config set command.
Precedence
Environment variables > Config file > Defaults