relay·ssh

Remote access · behind NAT

An SSH tunnel is
all you need.

Reach your Raspberry Pis, routers, and servers hiding behind NAT or CGNAT. No public IP. No port forwarding. No VPN — one command, and you're in.

free while in beta · no card required

bedroom-pi — ssh
$ curl -fsSL https://relayssh.com/install/KEY/ | sudo sh
  agent installed — device online
$ ssh -p 20001 pi@relayssh.com
pi@bedroom-pi:~ $ 
1
line to install
~2 min
to first session
$1
per device / month
0
plaintext at the relay
Raspberry Pi Debian Ubuntu anything with systemd and sshd

How it works

Your device dials out. You dial in.

1

Install the agent — one line

Paste the install command on your device. It registers itself and shows up in your dashboard.

2

The device opens a reverse SSH tunnel

Outbound only — it works through NAT, CGNAT, and strict firewalls. The tunnel reconnects on its own.

3

You ssh to your port on the relay

Add a tunnel to port 22 and the relay hands it a port of its own, for good. Connect from anywhere; the relay passes your session straight through.

NAT / firewall your device outbound tunnel → :2002 relayssh.com ssh -p 20001 you · anywhere one port per tunnel · 20000–29999

Why RelaySSH

Simple on purpose.

No public IP needed

Your device connects out, so NAT, CGNAT, and carrier firewalls stop mattering. If it can reach the internet, you can reach it.

One line to install, one to update

A single command installs the agent and registers the device. Updates ship the same way.

Auth stays on your device

We never hold your logins. Keys and passwords are checked by your device's own SSH server — not by us.

SSH tunnels, nothing else

We only relay encrypted SSH traffic, end to end. There is nothing for us to decrypt and nothing for us to read.

Already using PiTunnel? Read RelaySSH compared with PiTunnel.

Security

Authentication is your right — and your responsibility.

The relay never terminates your SSH session. Your connection is encrypted from your keyboard to your device; the relay just moves ciphertext. Each device key is locked to the ports it was assigned, and who gets in is decided where it should be — by your device.

your key ciphertext ciphertext the relay — no keys, nothing to decrypt your device's key
Coming soon

Host a website from the Pi in your bedroom.

The same tunnel that carries your SSH session can carry a website. Point a domain at your tunnel and serve traffic from hardware you can physically kick — no public IP required.

Pricing

$1 / device / month

No tiers. No seats. No surprises. That's the whole pricing page.

free while in beta — billing coming soon

Put your first device online in two minutes.

New to Raspberry Pi? Set one up from scratch — flash the card, boot headless, connect from anywhere.

free while in beta · no card required