Docs
Security
A public URL for a private machine, with as little exposed as possible.
Network
- The CLI makes an outbound-only secure WebSocket (
wss://) connection. Your machine accepts no inbound connections from the internet. - TLS is used everywhere and certificate verification cannot be disabled in release builds.
Access control
- Every request needs a consumer token. There are no open endpoints.
- Authenticated callers use their own account token, so usage is attributable to a person.
- Anonymous sessions get an auto-generated token, live 30 minutes, and are strictly rate limited (one session per IP, request rate and body size caps).
- Tokens are stored hashed, shown once, compared in constant time, and never logged.
What the tunnel can reach
- Only the model servers the CLI discovered or you configured with
--provider. - Only allow-listed API paths for each dialect. Callers cannot choose a host or arbitrary path, so there is no route into the rest of your LAN.
- Hop-by-hop headers are stripped before requests reach your runner.
Data handling
Request and response bodies pass through Tokmine to reach your machine and are not logged or stored. We keep usage counts (requests, token counts, bytes) per day for billing and your dashboard. See the privacy policy.
Abuse and reporting
Anonymous URLs can be blocked and killed if abused, see the acceptable use policy. To report a vulnerability, email [email protected].