Pricing

A flat monthly price for each project

Start free with the managed service, then move to a predictable Pro plan with included tunnel capacity and bandwidth. Enterprise and Integrator options cover dedicated or partner-operated deployments.

Managed plans

Hosted public and private connectivity with the dashboard, managed policy, logs, API, and support.

Basic

Ideal for individuals and small projects that need hosted access, WebTTY, and 24-hour logs.

Free

  • HTTPS tunnels
  • WebSocket support
  • Registered WebTTY servers
  • 24-hour WebTTY logs
  • 24-hour connection logs
  • Token-protected access
  • Fine-grained access tokens
  • 5 GB bandwidth per month
  • 2 simultaneous tunnels
Start now

Pro

Designed for small teams requiring full protocol support, strong security controls, and support.

$99 / month

$49 / month

Limited launch offerlocked forever for early users

  • Everything in Basic
  • Global and regional routing
  • Private tunnels
  • TLS, QUIC and DTLS endpoints
  • Published TCP tunnels and reserved addresses
  • Custom domains
  • rstream Auth (interactive HTTP auth)
  • mTLS Tunnel access
  • Challenge mode (HTTP)
  • IP and Geo access policies
  • 30-day connection logs
  • 30-day WebTTY logs
  • Project webhooks
  • Analytics
  • Email support
  • 200 GB bandwidth per month
  • 50 simultaneous tunnels
Start now

Enterprise

For organizations requiring dedicated capacity, workspace-level billing, protected data, audit, and source review.

Custom

  • Everything in Pro
  • Dedicated runtime clusters
  • Optional dedicated or on-premises control plane
  • Workspace-level billing
  • Unlimited enterprise projects
  • Unlimited bandwidth
  • Unlimited tunnels
  • Workspace Protection
  • Trusted browsers and devices
  • Workspace Recovery Kit
  • Activity audit logs and exports
  • Server source code audit or escrow
  • Dedicated support
Contact sales

Prices are listed in US dollars. Applicable taxes may be added. Invoices are provided in the dashboard after purchase. Delete a paid project from the dashboard to stop its future billing.

Integrator Edition

Operate rstream capabilities inside your own managed service, private platform, or customer deployment model.

Integrator Edition

Commercial partner edition for integrators, MSPs, and infrastructure platforms that want to deliver rstream capabilities inside their own customer environments and operating model.

Custom

  • Source access under contract
  • Customer environment deployment rights
  • Partner-operated runtime infrastructure
  • White-label and private-label options
  • Product adaptation rights by agreement
  • Secure tunnels, WebTTY, policy, logs, and APIs
  • Partner enablement and technical onboarding
Contact sales

Need a standalone runtime?

Engine Community Edition is a free self-hosted runtime with direct JWT agent authentication, static TLS, and Prometheus metrics. It does not include the hosted dashboard, managed policies, or managed support.

Learn about Community Edition

Compare plans

High-level feature differences across tunnels plans.

FeatureBasic

Price

Commercial entry point before taxes, usage adjustments, or custom contract terms.

Free

Outbound-only connectivity

No inbound ports or public IPs required.

Yes

Zero-trust edge enforcement

Consistent identity, encryption, and policy enforcement across hosted HTTP, TLS, QUIC, and DTLS entrypoints.

Yes

Identity-based access

Use rstream Auth, scoped tokens, or mutual TLS on hosted and private managed deployments. CE uses local JWT agent authentication.

Yes

Managed platform

Hosted control plane API with management dashboard.

Yes

Workspace collaboration

Shared projects for users in the same workspace.

Yes

Runtime infrastructure

Tunnel and WebTTY clusters used by hosted projects.

Shared managed

Global and regional routing

Choose a fixed region or use the Global edge network when available.

Regional

Control plane

Dashboard, API, database, and telemetry deployment model.

Shared managed

Billing model

How usage is commercially attached to projects or workspaces.

Per project

Project allocation

Enterprise workspaces can create projects against dedicated workspace capacity.

Plan per project

Support

Support level included with the plan.

No

Public tunnels

Internet-facing tunnels with a public endpoint.

Yes

Private tunnels

Unpublished tunnels for remote access to SSH, dashboards, homelabs, and internal services.

No

Bytestream tunnels

Stream-oriented tunnels for HTTP, TLS, raw TCP, and private protocols.

Yes

Datagram tunnels

UDP-like tunnels (datagram transport).

No

HTTPS tunnels

Public HTTP tunnels with edge TLS (HTTPS).

Yes

TLS tunnels

Published TLS endpoints with terminated or passthrough mode.

No

Published TCP tunnels

Raw TCP endpoints for application protocols that provide their own security.

No

Reserved TCP addresses

Stable project-scoped hostname and port reservations for published TCP tunnels.

No

QUIC / DTLS tunnels

Published QUIC and DTLS endpoints.

No

WebSocket support

WebSocket upgrade over HTTP tunnels.

Yes

rstream WebTTY

Browser terminal access for servers and devices.

Yes

WebTTY session logs

Managed session recording and replay for registered WebTTY servers.

24 hours

Active WebTTY sessions

Live session visibility, spectator access, and control transfer.

Listing only

Token auth (HTTP)

Require scoped access tokens for identity-based access on hosted HTTP tunnels.

Yes

rstream Auth (HTTP)

Browser-based identity and access for human or operator HTTP access.

No

Challenge mode (HTTP)

Additional auth challenge on HTTP tunnels.

No

HTTP/3 upstream

HTTP/3 upstream support.

No

Least-privilege tokens

Scoped tokens with granular permissions for discovery, creation, and access.

Yes

IP/Geo restrictions

Trusted IP ranges or country allow/deny policies.

No

Workspace Protection

Workspace-level key custody for Enterprise workspaces, with trusted browsers, trusted devices, and Recovery Kit recovery.

No

WebTTY E2E encryption

End-to-end encryption for WebTTY terminal content, using explicit server keys or workspace-managed keys when available.

Explicit keys

Agent key authentication

Authenticate rstream agents and SDK clients with certificate-backed identities.

Yes

Connection logs

Hosted tunnel connection history and retention.

24 hours

Project webhooks

Signed lifecycle event delivery to HTTPS endpoints with delivery history and attempt diagnostics.

No

Activity audit logs

Workspace activity trail, exports, and review workflows for actions performed by users and agents.

No

Server source code access

Server source code access for audit or escrow review under contract; IP remains licensed.

No

Monthly bandwidth

Plan quota used in hosted usage.

5 GB / month

Managed STUN / TURN

Hosted STUN discovery and TURN relay service for WebRTC and ICE connectivity.

5 GB / month

Simultaneous tunnels

Max tunnels per project.

2 tunnels

Frequently asked questions

Can’t find the answer you’re looking for? Reach out to our customer support.