Free Cloudflare tunneling + self-hosted Relay tunneling, one tool for every use case
Zero-cost HTTP/WS tunnels with Cloud mode, plus self-hosted TCP/UDP Relay tunnels
Cloudflare Tunnel for free HTTP/HTTPS/WebSocket tunnels with automatic TLS and global CDN acceleration
Self-hosted frp Relay for TCP/UDP tunnels, ideal for game servers, SSH, databases, and more
Run cftunnel quick 3000 to tunnel localhost:3000 instantly
Use --share for a QR code, clipboard copy, and Telegram share link
macOS / Linux / Windows, with ARM64 + AMD64 builds
Bind your domain with automatic DNS and TLS configuration
Register launchd / systemd / Windows Service for startup on boot
Detect your platform and download the right binary automatically
Upgrade to the latest version with cftunnel update
Cross-platform Go tail for real-time tunnel logs
MIT licensed, fully open source, and community-driven
Enable password protection with --auth and the built-in auth proxy
Manage tunnels in a GUI if you prefer not to use the command line
Two tunnel paths for different scenarios
Choose the right tunnel mode for your scenario
| Feature | Cloud Mode | Relay Mode |
|---|---|---|
| Protocols | HTTP / HTTPS / WebSocket | TCP / UDP / All protocols |
| Requires | Cloudflare account (free) | One public server |
| Domain | Free random domain / custom domain | Direct server IP |
| Encryption | Automatic TLS + Cloudflare CDN | Built-in frp encryption |
| Cost | Completely free | Server cost |
| Typical use cases | Web development, API debugging, Webhooks | Game servers, SSH, databases, RDP |
| Start command | cftunnel quick 3000 | cftunnel quick 25565 --relay |
Common commands for both modes
Common fixes for frequent issues
Some networks block UDP/443. Fix: set --protocol http2 to fall back to HTTP/2, or check your firewall rules.
The fake-IP mode in Clash and similar proxies may hijack Cloudflare DNS. Fix: add trycloudflare.com to your direct-connection rules.
Cloudflare Argo Tunnel error, usually caused by a mismatched tunnel configuration. Fix:cftunnel down then run cftunnel up,or delete and recreate the tunnel.
DNS points to the wrong tunnel. Fix: verify that the DNS CNAME targets the correct tunnel UUID, then use cftunnel remove to clean it up and add it again.
Choose your platform and run one command
# Uses a mirror automatically when available curl -fsSL https://raw.githubusercontent.com/qingchencloud/cftunnel/main/install.sh | bash # If GitHub is slow, download from a mirror manually: # curl -fsSL https://ghfast.top/https://github.com/qingchencloud/cftunnel/releases/latest/download/cftunnel_linux_amd64.tar.gz -o cftunnel.tar.gz # tar xzf cftunnel.tar.gz && sudo install -m 755 cftunnel /usr/local/bin/
irm https://raw.githubusercontent.com/qingchencloud/cftunnel/main/install.ps1 | iex
git clone https://github.com/qingchencloud/cftunnel.git cd cftunnel go build -o cftunnel .
Go from zero to a tunnel in 3 minutes
No Cloudflare account needed; get a random URL for quick sharing and debugging
cftunnel quick 3000
Bind your domain with a Cloudflare account and API Token
cftunnel init cftunnel create mytunnel cftunnel add myapp 8080 --domain app.example.com cftunnel up
Run your own Relay server for full TCP/UDP tunneling
cftunnel relay init cftunnel relay add mc --local 25565 --proto tcp cftunnel relay up
Deploy frps on your public server as a Relay node
# Install the server and configure the client with one local command cftunnel relay server setup --host YOUR_SERVER_IP --user root # Key authentication cftunnel relay server setup --host 1.2.3.4 --key ~/.ssh/id_ed25519 # Password authentication (entered interactively, not saved in shell history) cftunnel relay server setup --host 1.2.3.4 --password # Fully interactive mode cftunnel relay server setup
curl -fsSL https://raw.githubusercontent.com/qingchencloud/cftunnel/main/install-relay.sh | bash
# 1. Download the configuration files mkdir -p cftunnel-relay && cd cftunnel-relay curl -fsSLO https://raw.githubusercontent.com/qingchencloud/cftunnel/main/docker/relay-server/docker-compose.yml curl -fsSLO https://raw.githubusercontent.com/qingchencloud/cftunnel/main/docker/relay-server/frps.toml.example cp frps.toml.example frps.toml # 2. Edit frps.toml and set auth.token # bindPort = 7000 # auth.token = "YOUR_TOKEN" # 3. Start docker compose up -d