Fast answer
Teams and workspace governance explains the feature as a visible, testable workflow: what the user can do, which states and limits apply, how failures behave and which evidence supports each material claim.
Technical details
This page covers:
workspace membership and role boundariesroute, device, owner and domain inventoryinvitation and offboarding workflowrevocation and audit historyusage, quota, billing and invoice visibilitystable names and environment templatesprocurement evidence without unshipped enterprise claims
Route identity and the selected-service boundary
The enrolled device initiates the connection. Locally generated device identity, proof of possession, short-lived route generations and exact-host matching bind the hostname to the current route. Unknown, malformed, revoked or stale ownership fails closed instead of being forwarded to an uncertain destination.
Oxaa publishes only the configured local target. Private-network destinations require explicit authorization, while public, metadata, link-local, multicast and other unsafe destination classes remain blocked by policy.
Troubleshooting
Start with the local process, port and scheme. Then check authentication and clock, DNS, UDP/443, TCP/443 fallback, corporate proxy or TLS interception, route ownership and edge readiness. Use oxaa routes list, oxaa diagnose --network and stable error IDs; review diagnostic output before sharing it and remove secrets, bodies and private paths.
Cleanup and production handoff
Remove the external callback, preview URL or DNS binding; rotate test credentials; delete local captures; stop the route; and revoke the device or session when appropriate. Move production traffic to the deployed application, production ingress or event-delivery platform designed for that job.
What Oxaa is - and is not
Oxaa is development connectivity for a selected local HTTP or HTTPS service while the enrolled device and authenticated route are live. It is not application hosting, a general VPN, a forward proxy, permanent production deployment, raw TCP/UDP tunneling, arbitrary TLS passthrough, a CDN/WAF replacement or a production webhook delivery platform.
Frequently asked questions
Does Oxaa deploy my application?
No. The application continues to run on the enrolled device. Oxaa forwards requests to the selected local service only while the authenticated route is live.
Do I need to open an inbound port?
Normally no. The enrolled device initiates the session. A restrictive network can still block DNS, UDP/443, TCP/443 or intercept TLS, so diagnostics remain important.
Where do Inspector body copies live?
When bounded capture is explicitly enabled, the copy displayed by the local Inspector remains on the developer device. Oxaa still processes public traffic and retains bounded operational metadata.
Is this production hosting?
No. Use a deployed application, production ingress or event-delivery platform for production traffic.
