1. Localhost. Online. Without opening your network.
  2. Documentation home
  3. Configuration and multi-route environments

Secure public endpoints for local development

Configuration and multi-route environments

Configuration and multi-route environments: practical workflow, product behavior, limits, evidence and the exact next step with Oxaa.

Fast answer

Configuration and multi-route environments is an execution page, not a marketing summary. It states the supported scope, prerequisites, exact states, expected result, failure paths, cleanup and the next technical task.

Commands used on this page

oxaa start
oxaa config explain

Technical details

  • named routes
  • configuration precedence
  • independent route state
  • supervisor reconnect
  • background service
  • secret handling
  • versioned schema and migration

Route identity and the selected-service boundary

The enrolled device initiates the connection. Locally generated device identity, proof of possession, short-lived route generations and exact-host matching bind the hostname to the current route. Unknown, malformed, revoked or stale ownership fails closed instead of being forwarded to an uncertain destination.

Oxaa publishes only the configured local target. Private-network destinations require explicit authorization, while public, metadata, link-local, multicast and other unsafe destination classes remain blocked by policy.

Troubleshooting

Start with the local process, port and scheme. Then check authentication and clock, DNS, UDP/443, TCP/443 fallback, corporate proxy or TLS interception, route ownership and edge readiness. Use oxaa routes list, oxaa diagnose --network and stable error IDs; review diagnostic output before sharing it and remove secrets, bodies and private paths.

Cleanup and production handoff

Remove the external callback, preview URL or DNS binding; rotate test credentials; delete local captures; stop the route; and revoke the device or session when appropriate. Move production traffic to the deployed application, production ingress or event-delivery platform designed for that job.

What Oxaa is - and is not

Oxaa is development connectivity for a selected local HTTP or HTTPS service while the enrolled device and authenticated route are live. It is not application hosting, a general VPN, a forward proxy, permanent production deployment, raw TCP/UDP tunneling, arbitrary TLS passthrough, a CDN/WAF replacement or a production webhook delivery platform.