Public IPs for all your devices
Give any device a real public IP address. Host services that browsers trust like a bank — not a tunnel URL. Works from behind CGNAT, double-NAT, or corporate firewalls.
# Expose localhost:3000 to the internet
freehold --relay freehold.lit.app:9999 --port 443 --backend 127.0.0.1:3000
Your service is now reachable at a real IP address. No dynamic DNS. No tunnel subdomains. Just a clean, trusted address.
eBPF/XDP processes packets in the kernel before they hit userspace. No overhead, no bottleneck.
HMAC cookie challenge prevents registration spoofing without storing session state.
BGP announces your prefix globally. Traffic automatically routes to the nearest relay.
UDP-based registration opens paths through restrictive NATs. No port forwarding required.