PortLark CLI reference

portlark is the command-line client. It connects tunnels you created in the dashboard to services on your computer. It always connects to the official service at https://portlark.com; there is no option to point it at a different server.

Install and update

PlatformInstallerInstalled to
Windows (x64, ARM64)https://portlark.com/download/install-portlark.ps1%LOCALAPPDATA%\PortLark\bin\portlark.exe
macOS (Apple silicon, Intel)https://portlark.com/download/install-portlark.sh~/.local/bin/portlark
Linux (x64, ARM64, ARMv7)https://portlark.com/download/install-portlark.sh~/.local/bin/portlark

The installers verify the SHA256 checksum before replacing a binary and need no administrator rights. To install somewhere else, set INSTALL_PATH (shell script) or pass -InstallPath (PowerShell script). To update, run the installer again. Manual downloads and checksums are on https://portlark.com/downloads.

The installers do not modify your PATH. Run the CLI by its full path, or add the install folder to your PATH. The examples below assume portlark is on your PATH.

Commands

CommandWhat it does
portlarkConnects using the saved configuration. If there is none, it starts setup.
portlark setupInteractive sign-in and tunnel selection. Saves the configuration, then offers to connect.
portlark connectConnects the tunnels in the saved configuration. Runs in the foreground until you press Ctrl+C.
portlark statusShows the saved configuration. It does not contact the server.
portlark logoutDeletes the saved configuration from this computer.
portlark --token <token> --tunnel <id[,id...]>Connects without a saved configuration.
portlark agent <subcommand>Non-interactive commands for AI agents and scripts. See below.
portlark --versionPrints the client version, for example PortLark CLI 1.4.0.
portlark --helpPrints usage.

Flags can be written with one or two dashes (-version or --version).

setup

portlark setup

setup asks for:

  1. Your PortLark email and password (not a client token).
  2. Tunnel setup: Use existing tunnel lets you select one or more of your tunnels; Create new tunnel asks for the tunnel type (default http), a name, the local address (default 127.0.0.1:3000) and, for HTTP, a subdomain.

It then creates a client token for this computer (labeled with its hostname), saves the configuration, and asks Connect now? (default yes). Running setup again replaces the saved configuration. Old tokens stay valid until you revoke them in Dashboard → Client Tokens.

connect

portlark connect

The client prints Handshake OK followed by the access details of each tunnel:

[HTTP] my-app
  Local service: 127.0.0.1:3000
  Public URL: https://my-app.tunnel.portlark.com
  Public host: my-app.tunnel.portlark.com
  Public port: 443

The public address works only while the client is running. If no configuration exists, connect exits with no config found; run "portlark setup" first.

status

portlark status

Prints the configuration path, service URL, the number and IDs of the saved tunnels, when the configuration was created, and whether a token is present. The token itself is never printed.

logout

portlark logout

Deletes the local configuration file. It does not revoke the client token on the server; revoke it in Dashboard → Client Tokens if the computer is no longer trusted.

Connect with a token

portlark --token <client-token> --tunnel <tunnel-id>
portlark --token <client-token> --tunnel <tunnel-id-1>,<tunnel-id-2>

Uses a token you created in Dashboard → Client Tokens without saving anything. Both flags are required. Tunnel IDs are shown in the dashboard. Command-line arguments can be visible to other users on the same computer and are stored in shell history, so prefer setup on shared machines.

Agent commands

These commands are designed for AI coding agents and scripts. They never prompt, print only JSON to standard output, and manage one tunnel per credential. See Connect with your Agent for the full flow.

CommandWhat it does
portlark agent login --jsonStarts browser authorization and returns a link and pairing code (authorization_pending), or authorized if this computer already has a valid credential.
portlark agent login --wait --jsonPolls for your approval for up to about 30 seconds. Repeat while it returns authorization_pending.
portlark agent login --new --jsonStarts a fresh authorization request, for example for another tunnel.
portlark agent redeem --code-stdin --jsonExchanges a one-time code read from standard input for a tunnel credential.
portlark agent up --id <tunnel-id> --jsonStarts the tunnel in a background process and waits up to 25 seconds for it to connect.
portlark agent status --id <tunnel-id> --jsonReports the state of the background process.
portlark agent logs --id <tunnel-id> --jsonReturns the last 32 KB of the tunnel log, with the credential redacted.
portlark agent stop --id <tunnel-id> --jsonStops the background process. The tunnel and its credential are kept.

--json and --background are accepted for compatibility: output is always JSON, and up always runs in the background. status returns:

FieldMeaning
statestopped, connecting, connected or error
public_urlThe tunnel's public address
local_addrThe local address the tunnel forwards to
local_reachableWhether the client can open a TCP connection to local_addr
public_reachabilityAlways not_checked; verify the public URL yourself
errorA short error description, if any
log_pathLocation of the tunnel log

Files and locations

WhatWindowsmacOSLinux
Configuration (setup, connect)%USERPROFILE%\.config\portlark\config.json~/.config/portlark/config.json~/.config/portlark/config.json
Agent credentials and logs%APPDATA%\portlark\agent\~/Library/Application Support/portlark/agent/$XDG_CONFIG_HOME/portlark/agent/ (default ~/.config/portlark/agent/)

The configuration file contains your client token and the selected tunnel IDs. On macOS and Linux it is created with mode 0600 in a 0700 directory. The Agent directory is restricted to your user account (an ACL on Windows, mode 0700 elsewhere). Agent logs are rotated at 5 MB. Never share these files.

Exit codes

CodeMeaning
0Success, or the tunnel was stopped with Ctrl+C
1Runtime error, such as missing configuration, rejected token, failed handshake or lost connection
2Invalid command or flags (usage is printed)

Agent commands exit with 0 on success and 1 on error. Errors are written to standard error as JSON, for example {"error":"profile not found; redeem the authorization code first"}.

Keep a tunnel running

The CLI does not install itself as a service. On Linux you can run it with systemd after completing portlark setup as the same user:

[Unit]
Description=PortLark tunnel
After=network-online.target
Wants=network-online.target

[Service]
User=youruser
ExecStart=/home/youruser/.local/bin/portlark connect
Restart=on-failure
RestartSec=10

[Install]
WantedBy=multi-user.target

On Windows, Task Scheduler can start portlark.exe connect at logon. Agent-managed tunnels started with agent up keep running in the background but do not restart after a reboot.

Last updated

Report an issue with this page