# RelaySSH vs ngrok

Competitor details verified September 2026.

ngrok is a developer tunnel: it puts a local web app on a public URL for a
webhook, a demo, or a test, with TCP endpoints as one option among many.
RelaySSH is only that TCP part, built for SSH to devices that stay online
for months. For an afternoon of webhooks, ngrok. For a Pi in a cupboard or
fifty of them in the field, RelaySSH.

## Side by side

|  | RelaySSH | ngrok |
| --- | --- | --- |
| Port never changes | Held for as long as the tunnel exists, on every plan. | TCP endpoints get a random host and port each time. A fixed TCP address is a paid feature. |
| SSH on the free plan | Free during the beta, no card. | TCP endpoints need a payment method on file, and the address is random. |
| Flat price per device | $1 per device per month. | Hobbyist $10 a month with 1 fixed TCP address; Pay-as-you-go $20 a month plus usage. Extra addresses $0.005 an hour. |
| Unlimited devices | The eleventh device costs what the first did. | Free and Hobbyist: up to 3 online endpoints. Pay-as-you-go: unlimited. |
| No data cap | No published cap. | 1 GB free; 5 GB on paid plans, then $0.10 per GB. |
| Authentication stays on your device | Your sshd checks your key. The relay holds no logins. | A TCP endpoint forwards to port 22; your sshd decides. |
| Open-source agent | The agent is not open source today. | "There are no open source versions of the ngrok Agent." The 1.x agent on GitHub is unmaintained. |
| HTTP and TLS endpoints | TCP tunnels only. | Its main product: a public URL for a local web service. |

Both agents connect out only, so both work through NAT, CGNAT, and firewalls
that allow outbound traffic.

## When ngrok is the better choice

When the thing you are exposing speaks HTTP. A public URL for a local web
app, a webhook receiver for Stripe or GitHub, a demo for a client, a mobile
app pointed at a laptop — that is what ngrok is for, and it does it in one
command with a live view of every request. RelaySSH cannot do any of that:
a tunnel to port 80 gives you a bare port with no HTTPS and no hostname.

When the tunnel is short-lived. Three endpoints for a few hours costs
nothing, and a random address does not matter if you paste it into a
webhook setting and throw it away tonight.

## When RelaySSH is the better choice

When the device is the product and SSH is the job. A Pi that stays online
for months needs a port that is the same next month, on every device, and
ngrok charges for that: a fixed TCP address starts on the $10 plan, each
extra one is metered by the hour, and more than three online endpoints
means the $20 plan plus usage. On RelaySSH ten devices is $10.

When there is no per-gigabyte line on the invoice. An `rsync` of
a camera's footage or an `apt upgrade` across a fleet is
ordinary SSH traffic here, not metered transfer. And the dashboard shows
which devices are online and which port each one has, which is the question
you actually ask about a fleet.

## Moving from ngrok

Both agents only connect out, so RelaySSH can run next to ngrok while you
check that it works.

1. Install the RelaySSH agent with the one-line command from your dashboard.
2. Add a tunnel to port 22 on the device's page. This replaces `ngrok tcp 22`. The relay assigns a port between 20000 and 29999.
3. Connect with `ssh -p 20001 pi@relayssh.com`. Same username, same keys — only the host and port change.
4. Stop the ngrok agent. If you were paying for a TCP address, release it.

Keep ngrok for HTTP. RelaySSH does not replace a public URL, request
inspection, or TLS endpoints.
