RelaySSH vs Cloudflare Tunnel
Competitor details verified September 2026.
Cloudflare Tunnel puts a device behind Cloudflare's network under your own
domain, free for up to 50 users. For a website served from home it is the
best tool there is. For SSH it offers four setups, and three of them need
cloudflared, the Cloudflare One Client, or a Cloudflare login
on the machine you connect from. RelaySSH is
ssh -p 20001 pi@relayssh.com from anything, with no domain and
no Cloudflare account.
Side by side
| RelaySSH | Cloudflare Tunnel | |
|---|---|---|
| Nothing to install where you connect from | Any SSH client. |
Either cloudflared as a ProxyCommand, or the Cloudflare One Client enrolled in your organization. The browser terminal needs nothing. |
| No domain needed | The relay's hostname and a port. | "You must add a website to Cloudflare" — a zone you own, on Cloudflare's DNS. |
| Authentication stays on your device | Your sshd checks your key. The relay holds no logins. | Access checks your identity provider first. With self-managed keys your sshd still decides; Access for Infrastructure issues short-lived certificates instead. |
| Pricing shape | $1 per device per month. Free during the beta. | Free for up to 50 users; $7 per user per month beyond. Plus the domain. |
| Open-source agent | The agent is not open source today. |
cloudflared is Apache-2.0 on GitHub. |
| Browser terminal | Bring your own SSH client. | Log in to Access at the hostname and a terminal renders in the browser. |
| A website on your own domain with HTTPS | A tunnel is a bare port. | What it is built for. |
Both agents connect out only and work through NAT and CGNAT. Cloudflare Tunnel's SSH options are documented under Cloudflare One, which is a Zero Trust product; the tunnel itself is free.
When Cloudflare Tunnel is the better choice
When you are hosting a website. Your own domain, HTTPS handled at the edge, Cloudflare's cache and protection in front, and no bill — nothing else on this page comes close, and RelaySSH's host-a-website guide says so too.
When you want an identity provider in front of SSH. Access can require a Google, GitHub, or Okta login before any connection reaches sshd, for up to 50 people free, and the browser terminal means a colleague can get a shell from a machine with no SSH client at all. If your organization already runs on Cloudflare, the tunnel is one more thing in a dashboard you already open.
When RelaySSH is the better choice
When you just want ssh. No ProxyCommand in every
~/.ssh/config, no client to install and enroll, no browser
window opening to sign in before scp works. rsync,
Ansible, a backup cron job, an editor's remote mode — anything that speaks
SSH connects to a host and a port and is done.
When there is no domain and no organization. A hobbyist with two Pis does not want to buy a domain, move its DNS to Cloudflare, and set up a Zero Trust organization to reach them; a device installer handing SSH access to a customer does not want that customer enrolled in anything. And pricing follows the devices, not the people who log in to them.
Moving from Cloudflare Tunnel
Both agents only connect out, so RelaySSH runs next to
cloudflared without conflict.
- Install the RelaySSH agent with the one-line command from your dashboard.
- Add a tunnel to port 22 on the device's page. The relay assigns a port between 20000 and 29999.
- Connect with
ssh -p 20001 pi@relayssh.com. Remove theProxyCommandline for that host from~/.ssh/config.
If you were using Access for Infrastructure, your sshd goes back to checking
keys, so make sure your public key is in ~/.ssh/authorized_keys
on the device first. Keep the Cloudflare tunnel for the website; RelaySSH
does not replace it.