relay·ssh

RelaySSH vs Cloudflare Tunnel

Competitor details verified September 2026.

Cloudflare Tunnel puts a device behind Cloudflare's network under your own domain, free for up to 50 users. For a website served from home it is the best tool there is. For SSH it offers four setups, and three of them need cloudflared, the Cloudflare One Client, or a Cloudflare login on the machine you connect from. RelaySSH is ssh -p 20001 pi@relayssh.com from anything, with no domain and no Cloudflare account.

Side by side

RelaySSHCloudflare Tunnel
Nothing to install where you connect from Any SSH client. Either cloudflared as a ProxyCommand, or the Cloudflare One Client enrolled in your organization. The browser terminal needs nothing.
No domain needed The relay's hostname and a port. "You must add a website to Cloudflare" — a zone you own, on Cloudflare's DNS.
Authentication stays on your device Your sshd checks your key. The relay holds no logins. Access checks your identity provider first. With self-managed keys your sshd still decides; Access for Infrastructure issues short-lived certificates instead.
Pricing shape $1 per device per month. Free during the beta. Free for up to 50 users; $7 per user per month beyond. Plus the domain.
Open-source agent The agent is not open source today. cloudflared is Apache-2.0 on GitHub.
Browser terminal Bring your own SSH client. Log in to Access at the hostname and a terminal renders in the browser.
A website on your own domain with HTTPS A tunnel is a bare port. What it is built for.

Both agents connect out only and work through NAT and CGNAT. Cloudflare Tunnel's SSH options are documented under Cloudflare One, which is a Zero Trust product; the tunnel itself is free.

When Cloudflare Tunnel is the better choice

When you are hosting a website. Your own domain, HTTPS handled at the edge, Cloudflare's cache and protection in front, and no bill — nothing else on this page comes close, and RelaySSH's host-a-website guide says so too.

When you want an identity provider in front of SSH. Access can require a Google, GitHub, or Okta login before any connection reaches sshd, for up to 50 people free, and the browser terminal means a colleague can get a shell from a machine with no SSH client at all. If your organization already runs on Cloudflare, the tunnel is one more thing in a dashboard you already open.

When RelaySSH is the better choice

When you just want ssh. No ProxyCommand in every ~/.ssh/config, no client to install and enroll, no browser window opening to sign in before scp works. rsync, Ansible, a backup cron job, an editor's remote mode — anything that speaks SSH connects to a host and a port and is done.

When there is no domain and no organization. A hobbyist with two Pis does not want to buy a domain, move its DNS to Cloudflare, and set up a Zero Trust organization to reach them; a device installer handing SSH access to a customer does not want that customer enrolled in anything. And pricing follows the devices, not the people who log in to them.

Moving from Cloudflare Tunnel

Both agents only connect out, so RelaySSH runs next to cloudflared without conflict.

  1. Install the RelaySSH agent with the one-line command from your dashboard.
  2. Add a tunnel to port 22 on the device's page. The relay assigns a port between 20000 and 29999.
  3. Connect with ssh -p 20001 pi@relayssh.com. Remove the ProxyCommand line for that host from ~/.ssh/config.

If you were using Access for Infrastructure, your sshd goes back to checking keys, so make sure your public key is in ~/.ssh/authorized_keys on the device first. Keep the Cloudflare tunnel for the website; RelaySSH does not replace it.