1. Localhost. Online. Without opening your network.
  2. Pricing and packaging

Secure public endpoints for local development

Pricing and packaging

Pricing and packaging: practical workflow, product behavior, limits, evidence and the exact next step with Oxaa.

Fast answer

Choose by recurring workflow: evaluate one real endpoint, establish an individual development routine, then govern a shared workspace. Final prices, quotas, taxes, payment methods and country availability must come from the live billing source of truth.

Plan structure

PlanBest fit
StarterEvaluate one real local endpoint without breaking webhook/API responses.
DeveloperRepeat individual workflows with more routes, devices, inspection and stable identity.
TeamCentralize members, routes, devices, domains, quotas, billing, revocation and audit.
BusinessOnly after SSO, SCIM, region controls, procurement and support capabilities actually exist.

Definitions that prevent surprises

  • Active endpoint: one currently published and edge-ready route.
  • Trusted device: an enrolled device with current credentials and revocation state.
  • Custom domain: a verified customer-owned hostname with managed certificate lifecycle.
  • Transfer, concurrency, capture and audit: exact measured units with warnings, reset and enforcement behavior.

Free plan compatibility

One real webhook, API or browser workflow must complete without a universal HTML warning page or response mutation. Accountability, rate limits and abuse controls must protect the service without breaking legitimate machine traffic.

How traffic and Inspector data are handled

Oxaa's public edge terminates public HTTPS so it can resolve the exact hostname, identify the current authenticated route and forward the request. The session between the enrolled device and Oxaa is encrypted; the selected local service receives the request through that session.

Oxaa retains bounded account, route, usage, security, billing, support and diagnostic metadata required to operate and protect the service. Inspector body capture is a separate, explicit debugging action: the bounded request or response body copy shown by the local Inspector remains on the developer device and can be redacted, deleted or allowed to expire. Public traffic still has to be processed by the edge, so the accurate claim is local Inspector copies-not “Oxaa cannot see traffic.”

Availability and commercial eligibility

Language preference, account country, billing country, service region, payment eligibility and support language are separate values. Show the current result before signup or checkout and never infer commercial availability from the page language alone.

Frequently asked questions

Does Oxaa deploy my application?

No. The application continues to run on the enrolled device. Oxaa forwards requests to the selected local service only while the authenticated route is live.

Do I need to open an inbound port?

Normally no. The enrolled device initiates the session. A restrictive network can still block DNS, UDP/443, TCP/443 or intercept TLS, so diagnostics remain important.

Where do Inspector body copies live?

When bounded capture is explicitly enabled, the copy displayed by the local Inspector remains on the developer device. Oxaa still processes public traffic and retains bounded operational metadata.

Is this production hosting?

No. Use a deployed application, production ingress or event-delivery platform for production traffic.