ngrok Agent 3.39.11
Moved to ngrok-go v2.1.1
| Jun | Jul | Aug | Sep | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Sunday | No releases on May 24, 2026 | No releases on May 31, 2026 | No releases on Jun 7, 2026 | No releases on Jun 14, 2026 | No releases on Jun 21, 2026 | No releases on Jun 28, 2026 | No releases on Jul 5, 2026 | No releases on Jul 12, 2026 | No releases on Jul 19, 2026 | No releases on Jul 26, 2026 | No releases on Aug 2, 2026 | No releases on Aug 9, 2026 | No releases on Aug 16, 2026 | No releases on Aug 23, 2026 | No releases on Aug 30, 2026 | No releases on Sep 6, 2026 |
| Monday | No releases on May 25, 2026 | 1 release on Jun 1, 2026 | No releases on Jun 8, 2026 | No releases on Jun 15, 2026 | No releases on Jun 22, 2026 | No releases on Jun 29, 2026 | No releases on Jul 6, 2026 | No releases on Jul 13, 2026 | No releases on Jul 20, 2026 | No releases on Jul 27, 2026 | No releases on Aug 3, 2026 | No releases on Aug 10, 2026 | No releases on Aug 17, 2026 | No releases on Aug 24, 2026 | No releases on Aug 31, 2026 | No releases on Sep 7, 2026 |
| Tuesday | 1 release on May 26, 2026 | No releases on Jun 2, 2026 | 1 release on Jun 9, 2026 | 1 release on Jun 16, 2026 | 1 release on Jun 23, 2026 | No releases on Jun 30, 2026 | No releases on Jul 7, 2026 | No releases on Jul 14, 2026 | No releases on Jul 21, 2026 | No releases on Jul 28, 2026 | No releases on Aug 4, 2026 | No releases on Aug 11, 2026 | No releases on Aug 18, 2026 | No releases on Aug 25, 2026 | No releases on Sep 1, 2026 | No releases on Sep 8, 2026 |
| Wednesday | No releases on May 27, 2026 | No releases on Jun 3, 2026 | No releases on Jun 10, 2026 | No releases on Jun 17, 2026 | No releases on Jun 24, 2026 | No releases on Jul 1, 2026 | No releases on Jul 8, 2026 | No releases on Jul 15, 2026 | 1 release on Jul 22, 2026 | No releases on Jul 29, 2026 | No releases on Aug 5, 2026 | 1 release on Aug 12, 2026 | No releases on Aug 19, 2026 | No releases on Aug 26, 2026 | No releases on Sep 2, 2026 | |
| Thursday | No releases on May 28, 2026 | No releases on Jun 4, 2026 | No releases on Jun 11, 2026 | No releases on Jun 18, 2026 | No releases on Jun 25, 2026 | No releases on Jul 2, 2026 | No releases on Jul 9, 2026 | No releases on Jul 16, 2026 | No releases on Jul 23, 2026 | No releases on Jul 30, 2026 | No releases on Aug 6, 2026 | No releases on Aug 13, 2026 | No releases on Aug 20, 2026 | No releases on Aug 27, 2026 | No releases on Sep 3, 2026 | |
| Friday | No releases on May 29, 2026 | No releases on Jun 5, 2026 | No releases on Jun 12, 2026 | No releases on Jun 19, 2026 | No releases on Jun 26, 2026 | No releases on Jul 3, 2026 | No releases on Jul 10, 2026 | No releases on Jul 17, 2026 | No releases on Jul 24, 2026 | No releases on Jul 31, 2026 | No releases on Aug 7, 2026 | No releases on Aug 14, 2026 | No releases on Aug 21, 2026 | No releases on Aug 28, 2026 | No releases on Sep 4, 2026 | |
| Saturday | No releases on May 30, 2026 | No releases on Jun 6, 2026 | No releases on Jun 13, 2026 | No releases on Jun 20, 2026 | No releases on Jun 27, 2026 | No releases on Jul 4, 2026 | No releases on Jul 11, 2026 | No releases on Jul 18, 2026 | No releases on Jul 25, 2026 | No releases on Aug 1, 2026 | No releases on Aug 8, 2026 | No releases on Aug 15, 2026 | No releases on Aug 22, 2026 | No releases on Aug 29, 2026 | No releases on Sep 5, 2026 |
28 releases in the last year
Moved to ngrok-go v2.1.1
From ngrok
Corrected stale dashboard.ngrok.com links shown in ngrok --help and CLI error output.
Only includes internal release pipeline changes
From ngrok
Remove broad filesystem write virtualization permission for ngrok on the Microsoft App Store
From ngrok
Update libraries and Go version to patch most recent round of CVEs Add new crl_url configuration option to allow using a custom CRL
Updated OpenTelemetry dependencies to patch security vulnerabilities
Internal improvements to the build process, no functional changes
Patch various CVEs
Various security improvements
Fix crash on startup for Windows Store builds
Added support for AI Gateway provider keys
Upgraded internal dependencies
Internal improvements to the build process, no functional changes
Internal improvements to the build process, no functional changes
Fix a regression in macOS configuration paths
From ngrok
Disable updates for Windows App Store builds Fix config file location for Microsoft Store installs Add ai-gateway-api-keys CLI commands
Fix for upstream.proxy_protocol field in V3 configuration
From ngrok
Change agent self update link (was: update.equinox.io, is now: update.ngrok-agent.com). Deprecated flags that are made obsolete by Traffic Policies. Such flags can still be used, but are not shown in --help output and will display deprecation warnings if used. Hid the deprecated ngrok tunnel command from --help output. Please use ngrok http, ngrok tcp, or ngrok tls instead.
Honor custom DNS if provided.
From ngrok
Fix a bug with the *-file and *-url flags that was overwriting flag values with nil
Deprecate the --terminate-at command-line option
Fix a bug where inspector is filled with error logs when not in use
Fix a bug that could result in pooling being disabled via the API or Dashboard
From ngrok
Allow local_storage config option to disable local inspector Allow setting RLIMIT_NOFILE when running as a systemd service
From ngrok
Rename Bot users to Service users. Update billing urls. Can now use vault name or id when creating a secret.
From ngrok
A new agent HTTP API, /api/endpoints, has been introduced that corresponds to the agent config version 3 format Endpoints and tunnels deleted via the agent API will be properly reflected in the Dashboard
Blocked creating tunnels with duplicate names via the agent HTTP API
Updated Docker build base Restored support for PROXY in TCP/TLS tunnels
Optimized agent ui. Added get-secrets-by-vault path to vaults api
From ngrok
Added support for supplying a Traffic Policy to endpoints created with ngrok http and ngrok api using the --traffic-policy-url flag
From ngrok
Allow specifying a file for secrets, rather than requiring them to be passed on the command line
From ngrok
Debian Bookworm support added. This release is functionally identical to 3.24.0.
From ngrok
This version includes critical security fixes for users of mTLS that exists in agent version 3.19 through 3.23. ngrok strongly encourages anyone who uses mTLS to upgrade immediately. Allow for configuring maximum and minimum TLS versions Allow enforcing mTLS certificate checks
Updates and improvements to --help text
Improve Windows diagnostics
Correct names for vaults and secrets API commands.
From ngrok
Add API command support for vaults and secrets. Add audit events to vaults and secrets.
Fix CLI help/descriptions for endpoints create command.
From ngrok
Fixed a bug where TCP KeepAlive support could cause a crash on old versions of Windows
Add TCP KeepAlive configuration option.
Add bindings to v3 configs.
Add tls termination to v3 agent configs.
Fixed a bug causing the --url flag require an explicit scheme.
Fixed agent diagnose return codes.
From ngrok
Fixed ngrok diagnose —region all report. Fixed scheme proto defaulting. Added 128 character limit to usernames for agent basic auth.
From ngrok
Adds binary execution path to the host system metrics collected. Fixed a bug where 4 character time zones were not handled properly in the console UI.
From ngrok
Added --name field for endpoints and tunnels when created from the agent config or CLI.
From ngrok
Added endpoint create/update/delete subcommands to the ngrok api command. Added support for policy phases like on_tcp_connect, on_http_request and on_http_response. Fixed a bug where TLS was incorrectly passed as the endpoint proto rather than HTTP(S).
Added windows arm64 agent binary.
From ngrok
Releasing the features originally released by 3.15.0 Added --url agent CLI flag for creation of HTTP(S), TLS, and TCP protocol endpoints. Deprecated --domain, --scheme, and --remote-addr agent CLI flags, which have been replaced by --url. Added --metadata and --description agent CLI flags when using --url. Added endpoints: as a new field used for endpoint creation. A new agent: field has been added to the agent configuration format for V3. v3 supports both tunnels and endpoints. Tunnels are now considered deprecated when using config v3. Some agent configuration fields have been renamed in v3. v2 is still supported, but does not support the new endpoints: , or agent: fields. Added support for endpoint fields in ngrok's api. Update config commands to support new configuration version 3, including upgrade, add-authtoken, and add-api-key
From ngrok
Added --url agent CLI flag for creation of HTTP(S), TLS, and TCP protocol endpoints. Deprecated --domain, --scheme, and --remote-addr agent CLI flags, which have been replaced by --url. Added --metadata and --description agent CLI flags when using --url. Added endpoints: as a new field used for endpoint creation. A new agent: field has been added to the agent configuration format for V3. v3 supports both tunnels and endpoints. Tunnels are now considered deprecated when using config v3. Some agent configuration fields have been renamed in v3. v2 is still supported, but does not support the new endpoints: , or agent: fields. Added support for endpoint fields in ngrok's api.
From ngrok
Restores the functionality and compatibility for version 3.14.0 due to bugs in the previous release. An updated version with the changes from 3.15.0 will be released early next week.
Resolved an issue with mTLS detection.
From ngrok
Added support for traffic_policy field in agent config for Traffic Policy configuration. Deprecated policy Added EndpointTrafficPolicy module to Edge API.
From ngrok
In some cases, adds additional headers on error responses to ngrok that can be used to customize the content.
From ngrok
Fixed a bug in ngrok diagnose that would cause a panic if a server IP and the agent had TLS connectivity issues. Added --traffic-policy-file flag that accepts Traffic Policy configuration for HTTP, TCP, or TLS traffic. Deprecated --policy-file flag
Errors now have links to ngrok error page.
ngrok http now has timestamps for incoming requests.
From ngrok
Requests to TLS endpoints using proto: tls and terminate_at: agent succeed after the agent session goes through a reconnection.
From ngrok
ACTION MAY BE REQUIRED: The domain used for Certificate Revocation List (CRL) checks is now crl.ngrok-agent.com to align it with the domain used for session connections. This may require changes to your firewall or proxy settings to allow this outbound connection on port 80, or setting crl_noverify: true in the agent config file. Added CLI API support for Service Users.
From ngrok
Added a /api/status endpoint to the local agent API that returns the agent's current status The agent will check the Certificate Revocation List (CRL) on Session initiation. If a custom Connect URL is being used that has an invalid CRL in the chain, the crl_noverify: true option can be used to override this check, if desired Certificate Revocation List (CRL) checking for certain Let's Encrypt certificate chains has been fixed
Added json support to Traffic Policy configuration Moved to ngrok-go v1.9.1
From ngrok
Fixed an issue where ngrok diagnose --region all would return an error for eu-lon-1 Fixed a typo in default usage output Moved to ngrok-go v1.9.0
From ngrok
Added --policy-file flag that accepts Traffic Policy configuration for HTTP, TCP, or TLS traffic. Added support for policy field in agent config for Traffic Policy configuration. Added concise help text when ngrok is run without any args Removed support for Windows 7 and Windows 8 (support for Windows 7 and 8 was dropped in Go 1.21)
Improve ux of CLI errors. Correct error scheme on errors.
From ngrok
The --region flag has been deprecated, ngrok automatically chooses the region with lowest latency The upstream tls configs have been renamed, with backwards compatibility: --verify-upstream-tls is now --upstream-tls-verify --upstream-ca-path is now --upstream-tls-verify-cas An option for --app-protocol of the upstream, which can be set to http2, has been added The StopTunnel message is now handled by the agent
From ngrok
Added support for upstream TLS verification when forwarding to https:// or tls:// addresses. --verify-upstream-tls enables TLS verification of server TLS certificates --upstream-ca-path sets the certificate authority used to verify upstream server certificates
From ngrok
Added support for the User Agent Filter module (now deprecated by Traffic Policy) that allows or denies traffic to HTTPS endpoints based on incoming user agents. Added --ua-filter-allow and --ua-filter-deny flags that accept a list of regular expression strings
From ngrok
Fixed a bug where the agent running as a service would log to syslog even when another log destination was specified Fixed a bug where the agent could incorrectly ignore dns_resolver_ips
From ngrok
Added new us-cal-1 region which will reduce latency for users in the western half of North America
Added support for the Datadog event destination in ngrok api
From ngrok
Fixed a bug where colons in request header and response header values were not allowed (for example, --request-header-add "Access-Control-Allow-Origin:https://developer.mozilla.org") Fixed a bug introduced in v3.3.0 where --terminate-at edge was not using the correct TLS certificate
From ngrok
Added new default tunnel ingress names: the agent now connects to connect.ngrok-agent.com when starting a session Improved ngrok diagnose output to check that the DNS entry for localhost resolves Added the command ngrok config add-server-addr for configuring custom Connect URLs Re-wrote the tunnel and session backend to use the ngrok-go library
Fixed a bug introduced in v3.2.1 with tab complete for command line flags
From ngrok
Deprecated the --subdomain and --hostname flags. Updated all --subdomain and --hostname examples to use --domain. Fixed a bug where the agent did not resolve local DNS correctly on macOS arm64 Allow specifying ngrok --region=auto to pick the closest region (defaults to auto) Support for the NGROK_API_KEY environment variable when using the ngrok api subcommand --log-format=json now results in more output being formatted as json
From ngrok
Expanded diagnosis coverage when running ngrok diagnose to include testing against all regions and additional debug information of the underlying system. Updated --config option to be accepted in any position with cli command. Fixed ngrok config add-authtoken to also save the default version if it does not exist in the config file. Fixed rare race condition where agent would crash unexpectedly. Added DNS rebinding protection which includes web_allow_hosts configuration.
From ngrok
Started signing Windows executables with a code signing certificate. Includes polish for Windows executable properties like description and icon. Updated the root CA recognized by new agent versions. Improves incident recovery and mitigation options.
From ngrok
Added --region flag to the ngrok diagnose command. Including support for --region all to diagnose all regions. Ignore the --config flag when passed to a command that does not support it.
From ngrok
Fixed issues with replay not displaying requests in the ngrok Agent web UI, console UI, and API. Fixed null pointer issues with ngrok diagnose command.
From ngrok
Fixed a formatting issue in the inspector web UI for the header navigation. Updated the start tunnel API to allow starting labeled tunnels using a list of strings as labels.
From ngrok
Added the ability to provide messages to users via the agent console. ngrok config edit will now allow you to edit an invalid configuration file. Updated the display of the latency number in the console UI to be more human readable.
From ngrok
Fixed a bug on Windows where running the agent from explorer did not open a cmd prompt.
Fixed a bug that was not allowing users to start tunnels via the API.
From ngrok
Added ngrok config edit command to open the config file in your default editor. Removed invalid --proxy-proto flag from the ngrok start command. Added a migration to the ngrok config upgrade command to convert basic auth config parameters. The ngrok agent API will now error if invalid values are passed to it. Previously it ignored them.
From ngrok
For more information about upgrading from previous versions of the agent to v3.0, see the upgrade guide. Fixed an issue where an agent would not reconnect after removing a reserved domain from your account. Added ngrok completion to enable autocomplete for the cli. Added proxy_proto option for enabling and specifying the HAProxy's PROXY protocol version. Added the ability to set the connect_interface for the agent. Renamed bind_tls to schemes. The agent UI now display ping time. Added the ngrok diagnose command to the agent for troubleshooting connection issues. Added the ngrok config command for managing the configuration file. Added the ability to call the ngrok API from the agent using ngrok api. Added the ngrok service command to manage the ngrok agent as a service. All ngrok agent configuration files must now include a version number to indicate the format. Added the ability to start Labeled Tunnels to the agent that work with the new Tunnel Group backend. Renamed the "Clear" button to "Clear Requests" in the inspect UI to make it clear as to what it's doing. Fixed an issue where running ngrok authtoken would make changes to your tunnel definitions. The inspect UI will now pretty-print content types ending in +json. Fixed an issue where the inspect UI was adding unwanted HTML tags to JSON bodies when replayed. The ngrok agent now logs to stdout by default when console_ui: false. Command line arguments must use single hyphen for single letter options, and double hyphen for longer names. The ngrok agent now fails when there are keys in the config file it doesn't understand. Previously it ignored unknown options. Using the --host-header rewrite option puts the original host header value into the X-Forwarded-Host header field instead of the X-Original-Host header in an attempt to be more standard. Combined http_proxy and socks5_proxy configuration options into a single option
Fair-code workflow automation, self-hosted or cloud.
Production-grade container orchestration for automated deployment and scaling.
A fast reverse proxy that exposes a local server behind NAT or a firewall to the internet.
The container runtime that packages software into portable images.
Open-source home automation that puts local control first.
One tool to manage every AWS service from the command line, and script them.