Put your whole network within reach
Run a small agent on something you already have — a PC, a Raspberry Pi, an ESP32, or your own OpenWrt router. Then reach anything on your network from anywhere: no port forwarding, no public IP.
You, anywhere
Browser, Winbox or SSH
MikRouter
Your agent server
The agent
On your network
Your devices
Router, OLT, camera, PC
Every arrow starts from inside your network. Nothing connects in, so there is nothing to forward and nothing to open.
How it works
Online in three steps
No firewall rules, no static IP, and nothing to configure on your router.
Create the agent
Sign in, open Agents, and create one. Pick the agent server closest to you, then copy the tunnel host and device token — the token is shown once, so save it.
Set up the device
On a PC, Mac, Linux box or OpenWrt router, run the installer and paste the two values. On an ESP32, flash it over USB and fill them in on its setup Wi-Fi. Either way it then shows Online.
Add a mapping per service
Point a mapping at a device's address and port. A web mapping answers on your own HTTPS subdomain; a raw TCP one gives you a host and port for Winbox or SSH.
One agent covers the site
People often assume they need one agent per device. They do not. A single agent reaches TCP services anywhere your network routes — the local LAN and any VLAN or subnet your firewall rules permit. Add one mapping for each service you want to expose.
Features
Built for networks with no way in
The agent dials out
Nothing is opened on your firewall. The agent calls out and holds the line open, so it works behind CGNAT, on mobile data, and with no public address at all.
One agent, the whole site
One agent reaches every TCP service your network routes to — the LAN and any permitted VLAN or subnet. You do not need one per device.
Access password on web mappings
Web addresses are public by default. Tick “Require access password” and MikRouter asks for your account password first. Set that password before ticking — a protected mapping with none set stays shut.
Stable public addresses
A web mapping answers on your own HTTPS subdomain, with its own certificate. The address belongs to your account and survives restarts.
Web and raw TCP mappings
Anything with a browser interface gets an HTTPS subdomain. Anything that is not a web page — Winbox, SSH, a database — gets a host and port instead.
Use hardware you already own
A spare Windows PC, a Mac, a Raspberry Pi or Orange Pi, any Debian or Ubuntu box, a cheap ESP32 — or the site's own router, if it runs OpenWrt. One program, nothing else to install.
Live status from the device
The agent reports its own hardware, firmware, Wi-Fi signal, LAN address and active connections. Your dashboard shows what the device says, not a guess.
Encrypted end to end
The agent connects over TLS on 443 and every mapping is served over HTTPS. Tick “Device uses HTTPS” and the encrypted leg runs all the way to the device.
Updates from the dashboard
Agents check for their own releases and install them. An update pushed from the dashboard runs on trial — if the device does not come back, the previous release is restored.
Devices
Run it on what you already have
Three honest choices. A computer is the reliable one and a board is the cheap one — and if your router already runs OpenWrt, it can be the agent itself, with no extra hardware at all.
Computers
Wired, fast, and best for daily use
A Windows PC, a Mac, or any Debian or Ubuntu host — Raspberry Pi and Orange Pi included. One self-contained program, it can take a network cable, and it starts at 64 connections at once.
OpenWrt routers
No extra hardware — check your router first
Your router becomes the agent, so there is nothing extra to buy or power. One command over SSH, and it keeps routing exactly as before — Wi-Fi, DHCP, DNS and firewall untouched. 64 connections at once, and no Wi-Fi hop.
ESP32 boards
Cheapest, lowest power, one job at a time
A cheap board flashed over USB, on 2.4 GHz Wi-Fi. Best for one router page or Winbox where you would rather not leave a computer running — but only a handful of connections, and no LAN port.
Worth knowing before you buy a board
An ESP32 joins over 2.4 GHz Wi-Fi only and holds a small number of connections at once, and every image, script and request on a page is its own connection. A heavy router interface can therefore load slowly through a board, and going over the limit makes requests queue rather than fail. For several mappings, daily use, more than one person, or a heavy device page, use a computer agent — or the router itself, if it runs OpenWrt.
For developers
Your localhost, on a stable address
A mapping does not have to point at a router — it can point at the agent's own computer. Install the agent on your development machine, map 127.0.0.1 and your dev server's port, and it answers on your own HTTPS subdomain. The address belongs to your account and does not change when the server or the machine restarts.
- Receive webhooks from a payment gateway or GitHub in code running on your own machine — breakpoints and all.
- Show work in progress to a client or tester without deploying anything.
- Test from a phone on mobile data, or from another office.
- WebSockets, hot reload and live reload keep working — connection upgrades pass through untouched.
$ npm run dev ▲ Next.js 16.0.0 - Local: http://localhost:3000 ✓ Ready in 1.4s POST /api/webhooks/stripe 200 in 38ms host: my-api.test.mikrouter.comlocalhost. Only the host the request arrives with is different.Your dev API's address
https://my-api.test.mikrouter.com → 127.0.0.1:3000
A real certificate is issued for it, so Stripe or GitHub accept the URL as-is.
Put a local dev server or API online→Pricing
One price per agent
Every account gets one free agent, limited to one per internet connection. Pay per agent after that, with Credits, GCash, Maya, ShopeePay, GrabPay, QR Ph or PayPal.
Free agent
One per account and connection, no expiry
- 10 web mappings
- 3 raw TCP mappings
- Any supported device
- Access password included
Monthly Starter
Billed monthly, per agent
- 10 web mappings
- 3 raw TCP mappings
- Any supported device
- Access password included
Monthly Plus
Billed monthly, per agent
- 20 web mappings
- 6 raw TCP mappings
- Any supported device
- Access password included
Yearly Starter
Billed yearly, per agent
- 10 web mappings
- 3 raw TCP mappings
- Any supported device
- Access password included
- Lowest per-month rate
A mapping is one service you expose — a router UI, Winbox, a camera. One agent can serve every mapping in its allowance. Agent plans are separate from the MikroTik VPN remotes, which have their own plans.
Accepted payment methods
Agent servers
Pick the one closest to you
You choose an agent server when you create the agent. Distance is the single biggest thing you control — a nearer server is noticeably faster, especially on a board.
Singapore
Singapore
More locations soon
We are adding agent servers in more regions.
Guides
Step-by-step for every device
Start with the overview to see how the pieces fit together, then follow the guide for the device you have. Each one is written for someone doing it for the first time.
Agent Tunnel — Overview
What an agent is, and how the pieces fit together.
Flash an ESP32
Flash a board over USB with the desktop flasher — nothing else to install.
Connect ESP32 agent
Join the board's setup Wi-Fi and point it at your agent server.
Set up an agent on Linux (Debian/Ubuntu/etc)
One command on any Debian or Ubuntu host, including Raspberry Pi and Orange Pi.
Set up an agent on a Windows PC
Set up an agent on a Windows PC, with or without a background service.
Set up an agent on a Mac
Set up an agent on a Mac — download the app or use the one-line installer.
Set up an agent on an OpenWrt router
One command on the router itself — no extra box, and the whole network behind it.
Set up an agent on a small-flash OpenWrt router
For routers with almost no free flash, where the agent will not fit at all.
Put a local dev server or API online
Give the app on your own laptop a public HTTPS address, ngrok-style.
FAQ
Common questions
Do I need a MikroTik router for this?
No. The Agent Tunnel is a separate product from our MikroTik VPN remotes. The agent runs on a device you already have, and it can reach any TCP service your network routes to — whatever brand the equipment is.
Does it work behind CGNAT or a dynamic IP?
Yes. The agent dials out and keeps that connection open, so nothing has to reach your network from the internet. No public IP, no port forwarding, and no firewall rules to open.
Is one agent enough for a whole site?
Usually, yes. One agent reaches TCP services across every routable part of the network — the local LAN and any VLAN or subnet your routing and firewall rules allow. You add one mapping per service you want to expose, within your plan's allowance.
Are my addresses public?
A web mapping's address is public by default. Tick “Require access password” on the mapping and MikRouter asks for your account access password before anything reaches the device. Set that password before ticking the box — a protected mapping with no password set stays closed rather than opening. Raw TCP mappings have no unlock page and rely on the device's own login.
Which device should I use?
Check the site's router first: if it already runs OpenWrt it can be the agent itself, with nothing extra to buy. Otherwise a Windows PC, Mac or Linux box you already own is the best choice for daily or multi-user access — it can be wired and handles far more simultaneous connections. Choose an ESP32 for a single router UI or Winbox at low cost and low power, where the Wi-Fi signal is good.
Can my own router be the agent?
Yes, if it runs OpenWrt 18.06 or newer. One command over SSH installs the agent as a package, and the router carries on being a router — the agent leaves the Wi-Fi, DHCP, DNS and firewall alone. It needs about 600 KB free on the router's writable flash; a router with less takes a second route instead, which needs only about 20 KB — it keeps the settings on flash and loads the agent into memory at every boot, so it works on routers with well under 80 KB free. Neither works on a manufacturer's own stock firmware, and MikRouter does not install OpenWrt for you.
Can I put a local development server online?
Yes. Install the agent on your development machine and add a web mapping to 127.0.0.1 and your dev server's port. You get a stable HTTPS address for webhooks, client previews and testing from a phone — WebSockets and hot reload keep working.
Your first agent is free
Create it, install the agent on something you already own, and add your first mapping. No card, no port forwarding, no MikroTik.