Pricing
Managed plans
rstream edge network with hosted tunnels, dashboard, API, and analytics.
Basic
Ideal for individuals and small projects that need hosted access, WebTTY, and 24-hour logs.
Free
- HTTPS tunnels
- WebSocket support
- Registered WebTTY servers
- 24-hour WebTTY logs
- 24-hour connection logs
- Token-protected access
- Fine-grained access tokens
- 5 GB bandwidth per month
- 2 simultaneous tunnels
Pro
Designed for small teams requiring full protocol support, strong security controls, and support.
$49 / month
Limited launch offer — locked forever for early users
- Everything in Basic
- Private tunnels
- 30-day WebTTY logs
- 30-day connection logs
- TLS, QUIC and DTLS endpoints
- Published TCP tunnels and reserved addresses
- Custom domains
- rstream Auth (interactive HTTP auth)
- mTLS Tunnel access
- Challenge mode (HTTP)
- IP and Geo access policies
- Project webhooks
- Analytics
- Email support
- 200 GB bandwidth per month
- 50 simultaneous tunnels
Enterprise
For organizations requiring dedicated capacity, workspace-level billing, protected data, audit, and source review.
Custom
- Everything in Pro
- Dedicated runtime clusters
- Optional dedicated or on-premises control plane
- Workspace-level billing
- Unlimited enterprise projects
- Unlimited bandwidth
- Unlimited tunnels
- Workspace Protection
- Trusted browsers and devices
- Workspace Recovery Kit
- Activity audit logs and exports
- Server source code audit or escrow
- Dedicated support
Prices are listed in US dollars. Applicable taxes may be added. Invoices are provided in dashboard after purchase. Subscriptions may be cancelled at any time.
Integrator Edition
Operate rstream capabilities inside your own managed service, private platform, or customer deployment model.
Integrator Edition
Commercial partner edition for integrators, MSPs, and infrastructure platforms that want to deliver rstream capabilities inside their own customer environments and operating model.
Custom
- Source access under contract
- Customer environment deployment rights
- Partner-operated runtime infrastructure
- White-label and private-label options
- Product adaptation rights by agreement
- Secure tunnels, WebTTY, policy, logs, and APIs
- Partner enablement and technical onboarding
Self-hosted option
Run the rstream Engine Community Edition in infrastructure you operate.
Self-hosted
Free Community Edition engine for operators who want a direct runtime deployment without the hosted Control plane, managed dashboard, Enterprise workspace features, or managed support.
Free
- Standalone Community Edition engine
- Direct JWT agent authentication
- Static TLS certificate configuration
- Prometheus metrics
- No hosted dashboard or managed support
Compare plans
High-level feature differences across tunnels plans.
| Feature | Basic |
|---|---|
Price Commercial entry point before taxes, usage adjustments, or custom contract terms. | Free |
Outbound-only connectivity No inbound ports or public IPs required. | Yes |
Zero-trust edge enforcement Consistent identity, encryption, and policy enforcement across hosted HTTP, TLS, QUIC, and DTLS entrypoints. | Yes |
Identity-based access Use rstream Auth, scoped tokens, or mutual TLS on hosted and private managed deployments. CE uses local JWT agent authentication. | Yes |
Managed platform Hosted control plane API with management dashboard. | Yes |
Workspace collaboration Shared projects for users in the same workspace. | Yes |
Runtime infrastructure Tunnel and WebTTY clusters used by hosted projects. | Shared managed |
Control plane Dashboard, API, database, and telemetry deployment model. | Shared managed |
Billing model How usage is commercially attached to projects or workspaces. | Per project |
Project allocation Enterprise workspaces can create projects against dedicated workspace capacity. | Plan per project |
Support Support level included with the plan. | No |
Public tunnels Internet-facing tunnels with a public endpoint. | Yes |
Private tunnels Unpublished tunnels for remote access to SSH, dashboards, homelabs, and internal services. | No |
Bytestream tunnels Stream-oriented tunnels for HTTP, TLS, raw TCP, and private protocols. | Yes |
Datagram tunnels UDP-like tunnels (datagram transport). | No |
HTTPS tunnels Public HTTP tunnels with edge TLS (HTTPS). | Yes |
TLS tunnels Published TLS endpoints with terminated or passthrough mode. | No |
Published TCP tunnels Raw TCP endpoints for application protocols that provide their own security. | No |
Reserved TCP addresses Stable project-scoped hostname and port reservations for published TCP tunnels. | No |
QUIC / DTLS tunnels Published QUIC and DTLS endpoints. | No |
WebSocket support WebSocket upgrade over HTTP tunnels. | Yes |
rstream WebTTY Browser terminal access for servers and devices. | Yes |
WebTTY session logs Managed session recording and replay for registered WebTTY servers. | 24 hours |
Active WebTTY sessions Live session visibility, spectator access, and control transfer. | Listing only |
Token auth (HTTP) Require scoped access tokens for identity-based access on hosted HTTP tunnels. | Yes |
rstream Auth (HTTP) Browser-based identity and access for human or operator HTTP access. | No |
Challenge mode (HTTP) Additional auth challenge on HTTP tunnels. | No |
HTTP/3 upstream HTTP/3 upstream support. | No |
Least-privilege tokens Scoped tokens with granular permissions for discovery, creation, and access. | Yes |
IP/Geo restrictions Trusted IP ranges or country allow/deny policies. | No |
Workspace Protection Workspace-level key custody for Enterprise workspaces, with trusted browsers, trusted devices, and Recovery Kit recovery. | No |
WebTTY E2E encryption End-to-end encryption for WebTTY terminal content, using explicit server keys or workspace-managed keys when available. | Explicit keys |
Agent key authentication Authenticate rstream agents and SDK clients with certificate-backed identities. | Yes |
Connection logs Hosted tunnel connection history and retention. | 24 hours |
Project webhooks Signed lifecycle event delivery to HTTPS endpoints with delivery history and attempt diagnostics. | No |
Activity audit logs Workspace activity trail, exports, and review workflows for actions performed by users and agents. | No |
Server source code access Server source code access for audit or escrow review under contract; IP remains licensed. | No |
Monthly bandwidth Plan quota used in hosted usage. | 5 GB / month |
Managed STUN / TURN Hosted STUN discovery and TURN relay service for WebRTC and ICE connectivity. | 5 GB / month |
Simultaneous tunnels Max tunnels per project. | 2 tunnels |
| Feature | Basic | Pro | Enterprise | Self-hosted (CE) | |
|---|---|---|---|---|---|
Price Commercial entry point before taxes, usage adjustments, or custom contract terms. | Free | $49 / month | Custom | Free | |
Outbound-only connectivity No inbound ports or public IPs required. | Yes | Yes | Yes | Yes | |
Zero-trust edge enforcement Consistent identity, encryption, and policy enforcement across hosted HTTP, TLS, QUIC, and DTLS entrypoints. | Yes | Yes | Yes | N/A | |
Identity-based access Use rstream Auth, scoped tokens, or mutual TLS on hosted and private managed deployments. CE uses local JWT agent authentication. | Yes | Yes | Yes | JWT agent auth | |
Managed platform Hosted control plane API with management dashboard. | Yes | Yes | Yes | No | |
Workspace collaboration Shared projects for users in the same workspace. | Yes | Yes | Yes | No | |
Runtime infrastructure Tunnel and WebTTY clusters used by hosted projects. | Shared managed | Shared managed | Dedicated clusters | Self-operated | |
Control plane Dashboard, API, database, and telemetry deployment model. | Shared managed | Shared managed | Shared, dedicated, or on-premises | N/A | |
Billing model How usage is commercially attached to projects or workspaces. | Per project | Per project | Workspace contract | N/A | |
Project allocation Enterprise workspaces can create projects against dedicated workspace capacity. | Plan per project | Plan per project | Unlimited projects | Operator-defined | |
Support Support level included with the plan. | No | Email support | Dedicated support | No | |
Public tunnels Internet-facing tunnels with a public endpoint. | Yes | Yes | Yes | Yes | |
Private tunnels Unpublished tunnels for remote access to SSH, dashboards, homelabs, and internal services. | No | Yes | Yes | Yes | |
Bytestream tunnels Stream-oriented tunnels for HTTP, TLS, raw TCP, and private protocols. | Yes | Yes | Yes | Yes | |
Datagram tunnels UDP-like tunnels (datagram transport). | No | Yes | Yes | No | |
HTTPS tunnels Public HTTP tunnels with edge TLS (HTTPS). | Yes | Yes | Yes | Yes | |
TLS tunnels Published TLS endpoints with terminated or passthrough mode. | No | Yes | Yes | Yes | |
Published TCP tunnels Raw TCP endpoints for application protocols that provide their own security. | No | Yes | Yes | Yes | |
Reserved TCP addresses Stable project-scoped hostname and port reservations for published TCP tunnels. | No | Yes | Yes | No | |
QUIC / DTLS tunnels Published QUIC and DTLS endpoints. | No | Yes | Yes | No | |
WebSocket support WebSocket upgrade over HTTP tunnels. | Yes | Yes | Yes | Yes | |
rstream WebTTY Browser terminal access for servers and devices. | Yes | Yes | Yes | Yes | |
WebTTY session logs Managed session recording and replay for registered WebTTY servers. | 24 hours | 30 days | Custom retention | N/A | |
Active WebTTY sessions Live session visibility, spectator access, and control transfer. | Listing only | Join and control | Join and control | N/A | |
Token auth (HTTP) Require scoped access tokens for identity-based access on hosted HTTP tunnels. | Yes | Yes | Yes | No | |
rstream Auth (HTTP) Browser-based identity and access for human or operator HTTP access. | No | Yes | Yes | No | |
Challenge mode (HTTP) Additional auth challenge on HTTP tunnels. | No | Yes | Yes | No | |
HTTP/3 upstream HTTP/3 upstream support. | No | Yes | Yes | No | |
Least-privilege tokens Scoped tokens with granular permissions for discovery, creation, and access. | Yes | Yes | Yes | No | |
IP/Geo restrictions Trusted IP ranges or country allow/deny policies. | No | Yes | Yes | No | |
Workspace Protection Workspace-level key custody for Enterprise workspaces, with trusted browsers, trusted devices, and Recovery Kit recovery. | No | No | Yes | No | |
WebTTY E2E encryption End-to-end encryption for WebTTY terminal content, using explicit server keys or workspace-managed keys when available. | Explicit keys | Explicit keys | Explicit keys and workspace-managed | Explicit keys | |
Agent key authentication Authenticate rstream agents and SDK clients with certificate-backed identities. | Yes | Yes | Yes | No | |
Connection logs Hosted tunnel connection history and retention. | 24 hours | 30 days | Custom | No | |
Project webhooks Signed lifecycle event delivery to HTTPS endpoints with delivery history and attempt diagnostics. | No | Yes | Yes | No | |
Activity audit logs Workspace activity trail, exports, and review workflows for actions performed by users and agents. | No | No | Logs and exports | No | |
Server source code access Server source code access for audit or escrow review under contract; IP remains licensed. | No | No | Audit or escrow | No | |
Monthly bandwidth Plan quota used in hosted usage. | 5 GB / month | 200 GB / month | Unlimited | N/A | |
Managed STUN / TURN Hosted STUN discovery and TURN relay service for WebRTC and ICE connectivity. | 5 GB / month | 200 GB / month | Unlimited | N/A | |
Simultaneous tunnels Max tunnels per project. | 2 tunnels | 50 tunnels | Unlimited | N/A | |
Frequently asked questions
Can’t find the answer you’re looking for? Reach out to our customer support.