Skip to content
pols.so docs
Esc
↑↓navigate↵open⌘Jpreview
On this page

Published ports

Serve a web app or API from a sandbox over HTTPS, privately with a login link or publicly for anyone.

Publish a port to reach a server in the sandbox over HTTPS at https://<sandbox>-<port>.on.pols.so, where <sandbox> is the sandbox ID with - in place of _.

pols exec web -- tmux new-session -d -s dev 'cd ~/app && npm run dev -- --host 0.0.0.0 --port 3000'
pols host web 3000               # publish privately; prints a login link
pols host web 8080 --public      # publish for anyone who has the URL
pols host web                    # list published ports
pols host web 8080 --remove      # stop publishing

The edge terminates TLS with a certificate for *.on.pols.so and forwards requests to the port over the host’s private network, while the sandbox runs. Unpublished ports are not reachable at all.

The server must listen on the sandbox’s network interface, for example 0.0.0.0, not only on 127.0.0.1. Many development servers listen on localhost by default; look for a --host option.

Private ports

A port is private unless you publish it with --public. To open a private port, you need a login link:

pols host web 3000
# https://sbx-...-3000.on.pols.so/...?token=...

pols host prints a fresh link each time you run it for a published port; over the API, POST /v1/sandboxes/{sandbox}/ports/{port}/link returns one. The link:

  • must be opened within 5 minutes, and only works for that port of that sandbox;
  • logs your browser in with a cookie for that one host name, which lasts 12 hours;
  • stops working, together with the session it started, when the API key that created it is revoked or expires, or when the port is unpublished.

The link is a credential: hand it to the person who should see the page, and do not post it publicly. The session cookie is Secure, HttpOnly and bound to the exact host name, and the edge removes it before forwarding requests, so your app never sees it. The session only counts for requests from that address’s own pages, not from other sandbox addresses.

Public ports

A public port is open to anyone who knows its URL, with no login. Use it for webhooks, demos and APIs that do their own authentication. Switch an existing port between private and public by publishing it again with or without --public.

Over the API

Call Does
PUT /v1/sandboxes/{sandbox}/ports/{port} publish a port, with {"public": true} for a public one
GET /v1/sandboxes/{sandbox}/ports list published ports with their URLs
POST /v1/sandboxes/{sandbox}/ports/{port}/link a login link for a private port
DELETE /v1/sandboxes/{sandbox}/ports/{port} stop publishing; open connections stay open

Port 6080 is reserved for the desktop. Sandboxes cannot reach *.on.pols.so themselves, so test a published port from your own machine, not from inside a sandbox.