CLI Reference

Auto-generated from the client source code. Do not edit manually. Client version: 0.1.0-dev

nullbore open

Open one or more tunnels to expose local ports

nullbore open <port>
nullbore open --port <port> [--name <name>] [--ttl <duration>]
nullbore open -p <port>[:<name>] [-p <port>[:<name>] ...]
nullbore open <port> [<port> ...]

Creates a tunnel on the server and relays traffic from the public URL to your local port. Stays open until the TTL expires or you press Ctrl+C.

With --tls-passthrough the relay forwards raw TLS bytes without decrypting them, so traffic is encrypted end-to-end. Your local service must serve TLS itself and visitors see its certificate. The relay cannot inspect requests or add basic auth, so --auth cannot be combined with it. Available on paid plans only.

Requires an API key.

Flags:

  --auth    Basic auth for tunnel access (user:pass)
  --host    Target host (for Docker/remote services) (default: localhost)
  --name    Tunnel name / custom subdomain (Dev+ plans)
  --port    Local port to expose (single tunnel)
  --tls-passthrough    End-to-end TLS passthrough: the relay forwards raw encrypted bytes and never decrypts them. Your local service must serve TLS itself (visitors see its certificate). The relay cannot inspect requests or add basic auth (--auth). Paid plans only
  --ttl    Time-to-live (e.g. 30m, 2h, 24h) (default: 1h)
  -p <port> or <port>:<name>    Repeatable. Open multiple tunnels.
                                Format: PORT or PORT:NAME
                                Example: -p 3000:api -p 8080:web

Examples:

nullbore open 3000                          # expose localhost:3000
nullbore open --port 3000 --name myapp      # with custom subdomain
nullbore open --port 3000 --ttl 30m         # 30-minute TTL
nullbore open -p 3000:api -p 8080:web       # multiple named tunnels
nullbore open 3000 8080 5432                # multiple tunnels (positional)
nullbore open --port 3000 --auth admin:s3cret  # with basic auth
nullbore open --port 8443 --tls-passthrough    # end-to-end TLS (local service serves TLS)

nullbore list

List active tunnels

nullbore list

Shows all tunnels currently open for your API key, with their IDs, slugs, ports, and expiry times.

Requires an API key.


nullbore close

Close a tunnel

nullbore close <tunnel-id-or-name>

Closes the specified tunnel. You can use the full tunnel ID, the short ID prefix from nullbore list, or the tunnel's slug/name.

Arguments: The tunnel ID (or first 8 chars), slug, or name.

Requires an API key.


nullbore requests

Inspect recent HTTP requests to a tunnel

nullbore requests <tunnel-id-or-slug> [--limit N]

Shows recent HTTP requests that hit your tunnel — method, path, body size, and source IP. Useful for debugging webhooks.

Arguments: The tunnel ID or slug to inspect.

Requires an API key.

Flags:

  --limit    Number of requests to show (default: 20)

nullbore status

Check server connection and auth status

nullbore status

Pings the tunnel server and reports its version. Shows whether an API key is configured.


nullbore daemon

Run in dashboard-driven persistent mode

nullbore daemon

Connects to the NullBore dashboard and manages tunnels based on your dashboard configuration. Tunnels activate/deactivate remotely without restarting the daemon.

For static/headless mode (Docker), set NULLBORE_TUNNELS instead:

NULLBORE_TUNNELS=host:port:slug,host:port:slug,...

Example: NULLBORE_TUNNELS=webapp:3000:my-app,db:5432:my-db

Append +tls-passthrough to an entry for end-to-end TLS passthrough (the service must serve TLS; paid plans): NULLBORE_TUNNELS=caddy:443:secure+tls-passthrough,webapp:3000:my-app

Requires an API key.


nullbore acme

ACME DNS-01 hook for publicly trusted end-to-end tunnel certificates

nullbore acme present [--no-wait] [--wait-timeout 120s] <fqdn> <value>
nullbore acme cleanup <fqdn> <value>

End-to-end (--tls-passthrough) tunnels are served at <tunnel>.<account>.e2e.nullbore.com, and your local service presents its own certificate. nullbore acme lets any ACME client obtain a publicly trusted certificate for that name, or the wildcard *.<account>.e2e.nullbore.com, using the DNS-01 challenge: present asks the NullBore server to publish the _acme-challenge TXT record, cleanup removes it. Only the challenge value is sent to NullBore; the private key is generated and stays on your machine. Paid plans only.

By default present then waits (up to --wait-timeout) until 1.1.1.1 and 8.8.8.8 serve the record, so ACME clients that don't check propagation still work. cleanup succeeds if the record is already gone.

The argument order matches lego's exec provider, which runs $EXEC_PATH present <fqdn> <value> and $EXEC_PATH cleanup <fqdn> <value>. Point EXEC_PATH at a two-line wrapper script:

#!/bin/sh
exec nullbore acme "$@"

Then serve the issued certificate and key (lego writes them to ~/.lego/certificates/ with --path ~/.lego) from your local TLS server.

Arguments: <fqdn> is the challenge name (e.g. _acme-challenge.ACCOUNT.e2e.nullbore.com; a trailing dot is accepted) and <value> the TXT value supplied by your ACME client.

Requires an API key.

Flags:

  --no-wait               Return as soon as the server accepts the record
  --wait                  Wait for 1.1.1.1 and 8.8.8.8 to serve the record (default)
  --wait-timeout <dur>    Stop waiting after this long; the command still succeeds (default: 120s)

Examples:

printf '#!/bin/sh\nexec nullbore acme "$@"\n' > ~/bin/nullbore-acme-hook && chmod +x ~/bin/nullbore-acme-hook
EXEC_PATH=~/bin/nullbore-acme-hook lego run --accept-tos --path ~/.lego --dns exec --domains '*.ACCOUNT.e2e.nullbore.com'
nullbore acme present _acme-challenge.ACCOUNT.e2e.nullbore.com. TOKEN   # manual
nullbore acme cleanup _acme-challenge.ACCOUNT.e2e.nullbore.com. TOKEN

nullbore update

Check for updates and self-update

nullbore update
nullbore update --check

Checks GitHub for a newer release. Without --check, downloads and replaces the binary.

Flags:

  --check    Only check for updates, don't install

nullbore version

Show client version

nullbore version

nullbore help

Show help

nullbore help

Environment Variables

Environment variables override config file values.

VariableDescriptionDefault
NULLBORE_SERVERTunnel server URL (must include https://)https://tunnel.nullbore.com
NULLBORE_API_KEYAPI key for authentication—
NULLBORE_DASHBOARDDashboard URL (for daemon mode)https://nullbore.com
NULLBORE_TLS_SKIP_VERIFYSkip TLS certificate verification (set to 1 or true)—
NULLBORE_TUNNELSStatic tunnel list for Docker/headless mode (format: host:port:slug,...; append +tls-passthrough to an entry for end-to-end TLS)—
NULLBORE_INSTALL_DIROverride install directory for install.sh~/.local/bin
NULLBORE_VERSIONPin a specific version for install.sh—

Important: Use export when setting environment variables in your shell. Without export, the variable is only a shell variable and won't be passed to nullbore.

# Wrong:
NULLBORE_API_KEY="nbk_..."    # shell variable only
nullbore open 3000             # won't see the key

# Right:
export NULLBORE_API_KEY="nbk_..."
nullbore open 3000

Config File

The client reads ~/.config/nullbore/config.toml on startup.

Legacy path ~/.nullbore/config.toml is still supported.

# ~/.config/nullbore/config.toml

server = "https://tunnel.nullbore.com"
api_key = "nbk_your_key_here"
default_ttl = "1h"
debug = false

# Persistent tunnels (managed by daemon)
[[tunnels]]
name = "api"
port = 3000
# auth = "user:pass"  # optional: require basic auth on this tunnel
# mode = "tls-passthrough"  # optional: end-to-end TLS (local service must serve TLS; not with auth)

Edit the file directly — there is no config set command.

Precedence

Environment variables > Config file > Defaults