# RelaySSH vs Cloudflare Tunnel

Competitor details verified September 2026.

Cloudflare Tunnel puts a device behind Cloudflare's network under your own
domain, free for up to 50 users. For a website served from home it is the
best tool there is. For SSH it offers four setups, and three of them need
`cloudflared`, the Cloudflare One Client, or a Cloudflare login
on the machine you connect from. RelaySSH is
`ssh -p 20001 pi@relayssh.com` from anything, with no domain and
no Cloudflare account.

## Side by side

|  | RelaySSH | Cloudflare Tunnel |
| --- | --- | --- |
| Nothing to install where you connect from | Any SSH client. | Either `cloudflared` as a `ProxyCommand`, or the Cloudflare One Client enrolled in your organization. The browser terminal needs nothing. |
| No domain needed | The relay's hostname and a port. | "You must add a website to Cloudflare" — a zone you own, on Cloudflare's DNS. |
| Authentication stays on your device | Your sshd checks your key. The relay holds no logins. | Access checks your identity provider first. With self-managed keys your sshd still decides; Access for Infrastructure issues short-lived certificates instead. |
| Pricing shape | $1 per device per month. Free during the beta. | Free for up to 50 users; $7 per user per month beyond. Plus the domain. |
| Open-source agent | The agent is not open source today. | `cloudflared` is Apache-2.0 on GitHub. |
| Browser terminal | Bring your own SSH client. | Log in to Access at the hostname and a terminal renders in the browser. |
| A website on your own domain with HTTPS | A tunnel is a bare port. | What it is built for. |

Both agents connect out only and work through NAT and CGNAT. Cloudflare
Tunnel's SSH options are documented under Cloudflare One, which is a Zero
Trust product; the tunnel itself is free.

## When Cloudflare Tunnel is the better choice

When you are hosting a website. Your own domain, HTTPS handled at the edge,
Cloudflare's cache and protection in front, and no bill — nothing else on
this page comes close, and RelaySSH's
[host-a-website guide](https://relayssh.com/docs/host-a-website/)
says so too.

When you want an identity provider in front of SSH. Access can require a
Google, GitHub, or Okta login before any connection reaches sshd, for up to
50 people free, and the browser terminal means a colleague can get a shell
from a machine with no SSH client at all. If your organization already runs
on Cloudflare, the tunnel is one more thing in a dashboard you already open.

## When RelaySSH is the better choice

When you just want `ssh`. No `ProxyCommand` in every
`~/.ssh/config`, no client to install and enroll, no browser
window opening to sign in before `scp` works. `rsync`,
Ansible, a backup cron job, an editor's remote mode — anything that speaks
SSH connects to a host and a port and is done.

When there is no domain and no organization. A hobbyist with two Pis does
not want to buy a domain, move its DNS to Cloudflare, and set up a Zero
Trust organization to reach them; a device installer handing SSH access to
a customer does not want that customer enrolled in anything. And pricing
follows the devices, not the people who log in to them.

## Moving from Cloudflare Tunnel

Both agents only connect out, so RelaySSH runs next to
`cloudflared` without conflict.

1. Install the RelaySSH agent with the one-line command from your dashboard.
2. Add a tunnel to port 22 on the device's page. The relay assigns a port between 20000 and 29999.
3. Connect with `ssh -p 20001 pi@relayssh.com`. Remove the `ProxyCommand` line for that host from `~/.ssh/config`.

If you were using Access for Infrastructure, your sshd goes back to checking
keys, so make sure your public key is in `~/.ssh/authorized_keys`
on the device first. Keep the Cloudflare tunnel for the website; RelaySSH
does not replace it.
