DOCS

Security

Use passwords, short expiry, target approval, address rotation, quotas, and immediate revocation for sensitive publications.

GUIDE

Security

Choose the smallest target, audience, and duration that completes the task. Every endpoint has independent password, expiry, address, Relay, quota, status, and revoke controls.

Before you begin

Decide whether the target contains confidential data, credentials, administrative access, or a sensitive LAN service. Confirm that you are authorized to publish it and that the application has its own authentication where needed.

Shortest path

command or instruction
pubto publish --port 3000 --duration 30m

Protect the endpoint

Use a password for sensitive browser content, select a short expiry, share the address only with intended recipients, and keep database or TCP credentials outside the public link.

Watch and revoke

Review requests, traffic, visitors, active connections, and endpoint status. Stop, delete, or rotate the address immediately if the audience changes or a link is forwarded unexpectedly.

Publish responsibly

Do not use Pubto for phishing, malware, credential theft, unauthorized scanning, or access to systems you do not own or administer. Report suspicious endpoints through Support.

Before you share

  • The owner authorized the target
  • Password and expiry match the risk
  • Application credentials remain protected
  • A revoke plan exists before sharing

A public address is not a secret. Passwords, application authentication, short duration, usage limits, and prompt revocation provide the actual access boundary.

Download PubtoStill stuck? Contact support