CLI reference

One binary, addtothese, is everything you need: log in, open tunnels and forward TCP ports. Your login is stored in ~/.addtothese/config.yaml (%USERPROFILE%\.addtothese\config.yaml on Windows).

addtothese login

addtothese login --token att_...

Saves an API token. Without --token it asks for the token on standard input. addtothese logout forgets it.

addtothese http

addtothese http <port|host:port|url> [--subdomain name]

Exposes a local HTTP service. Without --subdomain you get a random endpoint. With it, the tunnel uses a name you reserved in the dashboard. The CLI reconnects on its own after network drops and refreshes its credentials before they expire.

FlagDefaultMeaning
--subdomainrandomReserved name to use
--timeout10sTimeout forwarding each request to your service
--access-logtruePrint each proxied request
--log-levelwarndebug, info, warn or error

Protect a URL with email codes

addtothese http 4321 --allowed-email ana@gmail.com --allowed-email '*@company.com'

Only the people you list can open the URL. A visitor enters their email; if it is on the list they receive a 6-digit code, valid for 10 minutes, and stay signed in for 24 hours. *@company.com allows a whole domain. Repeat the flag for each address or domain.

Your service receives the verified address in the X-AddToThese-Email header. Each run replaces the list, so running without --allowed-email makes the URL public again. You can also edit the list on the endpoint page of the dashboard.

addtothese tcp

addtothese tcp 5432 --subdomain mydb

Exposes a raw TCP port such as Postgres, SSH or RDP. People who need to reach it run the forwarder on their side, which opens a local port connected to your service:

addtothese forward tcp 5432 mydb --connect.url https://mydb.addtothese.com

They can then connect to localhost:5432 as if the database were on their machine.

Environment variables

VariableMeaning
ADDTOTHESE_TOKENAPI token, overrides the saved one
ADDTOTHESE_CONFIGPath to an alternative config file