RelaySSH vs reverse SSH on your own VPS
Competitor details verified September 2026.
RelaySSH is reverse SSH, run for you. ssh -R from the device to
a server with a public IP, kept alive by autossh, does the same
thing, and if you like running servers it costs about $4 a month for any
number of devices. RelaySSH is $1 per device, and you run nothing. This
page is the honest version of that trade.
Side by side
| RelaySSH | Your own VPS | |
|---|---|---|
| Authentication stays on your device | Your sshd checks your key. The relay holds no logins. | Same mechanism, same result. |
| Works with any SSH client |
ssh -p 20001 pi@relayssh.com |
ssh -p 20001 pi@your-vps |
| Nothing to run | The relay is patched, monitored, and rate-limited for you. | A server to update, an sshd to harden, and a login log to read. |
| Price | $1 per device per month. Free during the beta. | A 512 MiB DigitalOcean droplet is $4 a month, for any number of devices. Cheaper from the fifth device on. |
| Ports assigned and tracked | Each tunnel gets a free port from 20000–29999, shown on the device's page. |
You pick, you remember, you enable GatewayPorts. |
| Each device restricted to its own port |
Every key is written with permitlisten for exactly its port. |
Possible with the same authorized_keys options, if you write them. |
| Reconnects on its own | Backoff from 5 seconds to 5 minutes, reset after a minute of uptime. |
That is what autossh is for. |
| Which devices are online | Dashboard, heartbeat every 5 seconds. |
ss -tlnp on the VPS. |
| Open source | The agent is not open source today. |
OpenSSH and autossh, all the way down. |
When your own VPS is the better choice
When you already have one. A server that is already patched and already paid for makes the marginal cost of a reverse tunnel zero, and you keep every byte on infrastructure you control, with no third party in the path. From five devices up it is cheaper in cash on any month your time is free.
When you want more than one port per device without thinking about it.
-R takes as many forwards as you like, a -D SOCKS
proxy turns the device into a gateway to its whole LAN, and nothing stops
you forwarding UDP over a second tool. RelaySSH forwards one TCP port per
tunnel and nothing else.
When RelaySSH is the better choice
When you would rather not run a server. The VPS in the DIY setup is a public sshd that every scanner on the internet finds within the hour, and it needs updates, fail2ban, and someone to notice when it fills its disk. RelaySSH runs that box, rate-limits it, and gives each device a key that can do nothing on it except listen on its one assigned port.
When there is more than one device and more than one person. Port bookkeeping, per-device keys, and who-is-online-right-now are exactly the parts that turn into a spreadsheet at ten devices. The install is one line per device, and the dashboard answers the question you were about to ssh in to ask.
What the DIY setup looks like
So you can judge the trade with your eyes open. On the VPS, one restricted
key per device in ~/.ssh/authorized_keys:
restrict,port-forwarding,permitlisten="0.0.0.0:20001" ssh-ed25519 AAAA... bedroom-pi
GatewayPorts clientspecified in sshd_config, so the
forward can bind a public address. On the device, a systemd service that
runs:
autossh -M 0 -N -o ServerAliveInterval=30 -o ServerAliveCountMax=3 -o ExitOnForwardFailure=yes -R 0.0.0.0:20001:localhost:22 tunnel@your-vps
-M 0 turns off autossh's own monitor port and lets SSH's
keepalives detect a dead link instead. That is one device. Now do the key,
the port, and the unit for the next one, and keep a note of which port is
which. That note is the product.
Moving from your own VPS
This is the easiest migration on the site, because the device already does the same thing.
- Install the RelaySSH agent with the one-line command from your dashboard.
- Add a tunnel to port 22 on the device's page. The relay assigns a port between 20000 and 29999.
- Connect with
ssh -p 20001 pi@relayssh.com. - Disable the autossh unit on the device, and remove its key from the VPS.
Going the other way is just as easy, which is the point: nothing here is proprietary, so nothing here locks you in.