Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use a version 3 YAML configuration file to define reusable ngrok endpoints, then start one by its name with ngrok start <name>. The file is useful when you need repeatable settings, multiple endpoints, or service-managed startup; for a quick one-off tunnel, a command such as ngrok http 8080 is simpler.

When to use an ngrok config file

A config file lets you keep agent authentication and endpoint definitions together in a repeatable setup. It is a good fit when you recreate the same tunnel, manage more than one endpoint, declare a stable public URL or traffic policy, or want ngrok to run as a service. A one-off command is faster for temporary testing.

ngrok describes its localhost workflow as creating “a secure tunnel from a public URL to a service running on your local machine.” For a temporary HTTP tunnel, authenticate and run ngrok http 8080, replacing 8080 with your application’s actual port, then open the assigned ngrok.app URL. See ngrok’s localhost sharing guide.

Create a version 3 YAML configuration

The current official endpoint example uses a version 3 YAML file with an agent block and a list of named endpoints. For example:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
version: 3
agent:
  authtoken: $NGROK_AUTHTOKEN
endpoints:
  - name: my-endpoint
    url: https://your-subdomain.ngrok.app
    upstream:
      url: http://localhost:8080

Save the file as ngrok.yml. The example uses environment-variable substitution for the token; set NGROK_AUTHTOKEN in the environment where the agent runs. The url is the public endpoint, and upstream.url identifies the local service that should receive traffic. The hostname shown is illustrative: use a URL available to your ngrok account and setup. The official Creating Endpoints guide also demonstrates placing a traffic policy under an endpoint.

Authenticate the ngrok agent

The agent needs an authtoken to connect to ngrok. You can add it through the documented CLI command:

ngrok config add-authtoken "<YOUR_AUTHTOKEN>"

Alternatively, provide it in agent.authtoken in the YAML configuration, preferably through an environment substitution such as $NGROK_AUTHTOKEN rather than a live token committed to a repository. ngrok’s Linux download page documents the authentication command and service workflow.

Start an endpoint from the file

Use the endpoint’s name exactly as it appears in the YAML. For the sample above, run:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
ngrok start my-endpoint

For a file containing several endpoint entries, select the one you want by its name with ngrok start <name>. The name is a selector, not the public URL or the upstream address.

Run ngrok as a service

For unattended operation, install the service with the configuration file and then start it:

Rank #4
The SQL Programming Language: .
  • Used Book in Good Condition
ngrok service install --config ./ngrok.yml
ngrok service start

Run the install command in the environment where the file is available, and point --config to its actual path. Service installation connects that configuration to the local service setup; starting the service runs the agent in the background. The exact installation environment and service behavior depend on the operating system, so follow the relevant instructions on ngrok’s Linux download page when using Linux.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Protect tokens and public endpoints

A config file can make a tunnel easy to recreate, so treat it as deployable configuration rather than harmless sample text.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Do not commit a live authtoken. Substitute it from an environment variable or an approved secret mechanism.
  • Use ngrok’s recommended authtoken access-control lists (ACLs) and IP policies to limit where agents and endpoints can be used.
  • Protect dashboard administration with SSO and MFA, as recommended in ngrok’s security guidance.
  • Where appropriate, use traffic policies to control requests. ngrok documents options including OAuth, OpenID Connect, basic authentication, and webhook verification in its Linux examples and endpoint guide.
  • Review changes to both the config and any referenced policy files, and document which upstream service each endpoint expects.

Quick checks if an endpoint does not work

  • Agent cannot authenticate: confirm the token is set in the environment used to launch ngrok, or that agent.authtoken is populated correctly.
  • The wrong endpoint starts: check the endpoint’s YAML name and pass that exact name to ngrok start.
  • The public URL opens but the app does not respond: check that upstream.url points to the correct host and port and that the service is running and reachable from the agent.
  • Service startup cannot find the configuration: verify the path passed to --config is valid in the environment where you run ngrok service install.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.