Start Free
For home servers, NAS boxes and homelabs

Remote Access to Your Home Server — Without Opening a Port

One machine at home, several services running on it. Pluggie gives each service its own HTTPS address that opens in any browser, from anywhere — no port forwarding, no router changes, and nothing to install on the device you are connecting from.

Free forever tier · No email or credit card required

How it usually goes

  • Forward ports on the router and hope nothing else is listening
  • Remember which port is the NAS and which is Jellyfin
  • Issue and renew a certificate by hand, per service
  • Bolt on dynamic DNS because the public IP keeps changing
  • Discover your ISP put you behind CGNAT and none of it works

How it goes with Pluggie

  • The router stays closed — the agent dials outward
  • Every service gets its own hostname, not a port number
  • Certificates are issued and renewed automatically
  • No public IPv4 address needed on your side
  • Restrict access by country or IP range from the dashboard

Built for a box that runs more than one thing

📁

One address per service

Your NAS interface, Jellyfin, Grafana and Nextcloud each get a hostname of their own. No port numbers to memorise, no reverse proxy to maintain.

📱

Nothing to install at the far end

Open a normal HTTPS link in any browser — a work laptop, a borrowed phone, a machine where you have no administrator rights. This is the part a mesh VPN cannot do.

🌐

Your own domain

Point a CNAME and keep your registrar and nameservers where they are. Included on paid plans from $6/month.

🔒

Geo and IP filtering built in

Limit access to a country or an IP range, with HTTP Basic Auth on top, configured in the dashboard rather than in firewall rules.

Three steps, about five minutes

Everything happens on the machine you already own. The router is never touched.

1

Run the agent on your server

A single Docker container on the same box your services already run on. Home Assistant users can install it as an add-on instead of a container.

2

Point a tunnel at a service

Give the tunnel the local address of the thing you want to reach — for example http://192.168.1.10:8096 for Jellyfin, or https://192.168.1.10:5001 for DSM.

3

Open the address

The service is live on its own HTTPS URL with a valid certificate. Add another tunnel for the next service and repeat.

Works with whatever is already on the box

If it serves a web interface on your LAN, it can have a public address. Pluggie does not care what produced it.

Synology DSM Unraid TrueNAS Proxmox OpenMediaVault Jellyfin Plex Nextcloud Immich Grafana Portainer Pi-hole Home Assistant qBittorrent Vaultwarden Node-RED

Synology

Container Manager runs the agent directly on the NAS. Point one tunnel at DSM on port 5001 and, if you want, more at Synology Photos, Drive or anything else you have installed.

Unraid

Add the container from Community Applications. One tunnel for the Unraid web UI, one each for the services on the array — they do not have to share a hostname.

Proxmox

Run the agent in a small LXC container or VM on the host and expose the Proxmox web UI, plus any guest that serves a web interface.

TrueNAS

The agent runs as an app or in a jail alongside your shares, and the web UI gets its own address instead of a port on your router.

Plain Docker

On any Linux box — a mini PC, an old laptop, a VPS you keep at home — a single docker run is enough. Everything else is configured from the dashboard.

Common questions about home server access

Run the Pluggie container on the NAS itself through Container Manager, or on any other machine on the same LAN, and point the tunnel at DSM’s local address. You get an HTTPS hostname that works from any browser. Nothing is forwarded on the router, and QuickConnect is not involved.
Yes. Install the container from Community Applications or add it as a normal Docker container, then create one tunnel per service you want reachable — the Unraid web UI, Jellyfin, Nextcloud, whatever is running on the array.
Yes, and that is the usual setup. Each service gets its own hostname rather than a port number you have to remember. The free tier covers one tunnel; each paid tunnel unlocks two more free ones, so a typical homelab runs a mix.
It still works. The agent opens the connection outward, so there is no inbound port to forward and no public IPv4 address needed on your side. CGNAT is one of the main reasons people end up here.
No. A VPN means installing a client and signing in on every device you want to connect from. Pluggie publishes a normal HTTPS address, so a browser is enough — including on a work laptop or a phone you do not manage.
Not to start. The free tier gives you a pluggie.net subdomain. On paid plans you can point your own domain with a single CNAME — no DNS transfer, your registrar and nameservers stay where they are.
Certificates are generated and stored on your own device, and our relay forwards the encrypted stream without decrypting or storing it. The integrity of that connection is checked continuously and the status is shown in the dashboard and in the local UI.
There is a free tier with one tunnel and 1 GB at full speed per 30 days, with no email address and no card required — after the cap it throttles rather than cutting you off. Paid plans start at $6/month and add custom domains and more bandwidth.

Try it on one service first

Free tier, no email, no card. Five minutes to find out whether it fits the way your server is set up.

Start Free