Connect with your Agent
A terminal-capable AI coding agent can install the PortLark CLI and connect a tunnel for you. You stay in control: the agent never needs your password, and you approve every device in your browser.
Before you start
- Create a tunnel in the dashboard first, or be ready to choose one during approval.
- The agent must run on the computer or network where your local service is reachable. A cloud-hosted agent's
localhostis not your computer.
Steps
- Open Dashboard → Use with an Agent and copy the instructions into your agent. They point the agent to https://portlark.com/agent.txt.
- The agent installs the official CLI (version 1.4.0 or later) and runs
portlark agent login --json. - The agent shows you a link and a pairing code. Open the link, sign in, check that the pairing code matches, select your tunnel and approve.
- The agent runs
portlark agent login --wait --jsonuntil it reportsauthorized, then starts the tunnel withportlark agent up --id <tunnel-id> --json. - The agent checks both your local service and the public HTTPS URL and reports the result.
Only approve pairing requests that you started yourself. A pairing request is valid for one hour.
One-time codes
As an alternative to browser pairing, the dashboard can generate a one-time code that starts with tg_boot_. It is valid for one hour and can be redeemed by one device. The agent must send it through standard input:
portlark agent redeem --code-stdin --json
Never paste a code into a URL or command-line argument, and never share your account password or persistent tokens in chat.
What the agent can do
Each agent credential is limited to the single tunnel you approved. The agent can start, check, read logs for and stop that tunnel:
portlark agent status --id <tunnel-id> --json
portlark agent logs --id <tunnel-id> --json
portlark agent stop --id <tunnel-id> --json
stop does not delete the tunnel or the credential; up can start it again while your access is active. The background process does not restart after a reboot.
Check the result yourself
"state": "connected" means the client is connected to PortLark. "local_reachable": true means your local service accepts connections. Open the public URL to confirm the whole path works: an error page from your own application (for example 401 or 404) still means the tunnel works.
Revoke access
Agent credentials appear in Dashboard → Client Tokens. Revoke one when you no longer trust the device; the tunnel then disconnects. See Client tokens and the full command list in the CLI reference.
Last updated
Report an issue with this page