Back to Projects
libraryFeatured

Explita Tunnel

Secure reverse tunneling CLI & gateway with application-layer encryption (ECDH P-256 + AES-256-GCM), streaming HTTP proxying, full-duplex WebSockets, and a local web inspector.

Explita Tunnel

Overview

Explita Tunnel is a secure, high-performance reverse tunneling system and CLI engineered to expose local development servers to the internet with true defense-in-depth. While traditional tunneling tools terminate TLS at the public gateway and pass raw application traffic unencrypted internally, Explita Tunnel wraps every HTTP request, streamed chunk, header, and WebSocket frame in an authenticated AES-256-GCM inner encryption envelope negotiated via ephemeral ECDH (P-256) key exchange and HKDF-SHA-256.

Security is verifiable by design. When a session initiates, the client agent and the gateway exchange ephemeral public keys, derive a 256-bit symmetric session key, and compute a cryptographic session fingerprint (SHA-256("explita-tunnel-v1" || client_pubkey || server_pubkey)). Both endpoints display matching fingerprint digests on connect, enabling developers to visually verify key agreement integrity and completely eliminate Man-in-the-Middle (MITM) concerns. Tunnels feature an automatic 24-hour lifetime with seamless, zero-downtime key rotation upon reconnect.

Under the hood, Explita Tunnel is architected for high throughput and low latency. It features an O(1) centralized dispatcher that performs single-pass payload decoding on the gateway, eliminating redundant decryption overhead under high concurrent load. The streaming engine supports chunk-buffered streaming for large assets as well as zero-delay streaming for Server-Sent Events (SSE) and real-time APIs. It provides full-duplex WebSocket proxying out of the box, ensuring seamless Hot Module Replacement (HMR) and live-reloading across Next.js (Webpack and Turbopack), Vite, Remix, Nuxt, Astro, and custom Socket.IO servers.

For seamless local debugging, Explita Tunnel ships with a zero-dependency Local Web Inspector dashboard hosted at http://127.0.0.1:39755 (configurable with --inspect [port] or disabled via --no-inspect for headless/CI environments). The inspector streams real-time traffic over SSE, offering deep request and response inspection (headers, query parameters, timing, parsed JSON, raw bodies), image previews with transparency checkerboards, and one-click request replay to re-test webhooks without re-triggering external providers. Developers can also use interactive terminal shortcuts (r to replay the last request, c to clear screen).

Explita Tunnel includes production-grade access controls and guardrails: a high-speed IP / CIDR firewall engine powered by native 128-bit BigInt bitwise matching (-i, --allow-ip <cidr>) to restrict tunnel endpoints to authorized IPs or webhook providers (Stripe, GitHub, Shopify); nested multi-tenant subdomain routing via double hyphens (e.g. tenant1--myapp.tunnel.explita.ng) with injected x-explita-tenant headers; untrusted header sanitization to prevent spoofing; and per-tunnel rate limiting (100 req/s) with a 25MB payload ceiling.

Tech Stack

frontend

TypeScriptServer-Sent EventsHTML5CSS3

backend

Node.jsTypeScriptFastifyWebSocketsECDH / AES-256-GCMPrismaPostgreSQLRedis

Tags

#TypeScript#Tunnel#Reverse Proxy#WebSockets#CLI#Cryptography#Fastify#NPM Package#DevTools