---
title: Published ports
description: Serve a web app or API from a sandbox over HTTPS, privately with a login link or publicly for anyone.
---

Publish a port to reach a server in the sandbox over HTTPS at `https://<sandbox>-<port>.on.pols.so`, where `<sandbox>` is the sandbox ID with `-` in place of `_`.

```sh
pols exec web -- tmux new-session -d -s dev 'cd ~/app && npm run dev -- --host 0.0.0.0 --port 3000'
pols host web 3000               # publish privately; prints a login link
pols host web 8080 --public      # publish for anyone who has the URL
pols host web                    # list published ports
pols host web 8080 --remove      # stop publishing
```

The edge terminates TLS with a certificate for `*.on.pols.so` and forwards requests to the port over the host's private network, while the sandbox runs. Unpublished ports are not reachable at all.

The server must listen on the sandbox's network interface, for example `0.0.0.0`, not only on `127.0.0.1`. Many development servers listen on localhost by default; look for a `--host` option.

## Private ports

A port is private unless you publish it with `--public`. To open a private port, you need a login link:

```sh
pols host web 3000
# https://sbx-...-3000.on.pols.so/...?token=...
```

`pols host` prints a fresh link each time you run it for a published port; over the API, `POST /v1/sandboxes/{sandbox}/ports/{port}/link` returns one. The link:

- must be opened within 5 minutes, and only works for that port of that sandbox;
- logs your browser in with a cookie for that one host name, which lasts 12 hours;
- stops working, together with the session it started, when the API key that created it is revoked or expires, or when the port is unpublished.

The link is a credential: hand it to the person who should see the page, and do not post it publicly. The session cookie is `Secure`, `HttpOnly` and bound to the exact host name, and the edge removes it before forwarding requests, so your app never sees it. The session only counts for requests from that address's own pages, not from other sandbox addresses.

## Public ports

A public port is open to anyone who knows its URL, with no login. Use it for webhooks, demos and APIs that do their own authentication. Switch an existing port between private and public by publishing it again with or without `--public`.

## Over the API

| Call | Does |
| --- | --- |
| `PUT /v1/sandboxes/{sandbox}/ports/{port}` | publish a port, with `{"public": true}` for a public one |
| `GET /v1/sandboxes/{sandbox}/ports` | list published ports with their URLs |
| `POST /v1/sandboxes/{sandbox}/ports/{port}/link` | a login link for a private port |
| `DELETE /v1/sandboxes/{sandbox}/ports/{port}` | stop publishing; open connections stay open |

Port 6080 is reserved for the [desktop](/access/desktop/). Sandboxes cannot reach `*.on.pols.so` themselves, so test a published port from your own machine, not from inside a sandbox.
