A connection from your private network to your cloud agents. Bring your MCP servers and internal APIs within reach.
Last updated October 7, 2026
SparkTun connects your services through an outbound-only connection. A connector runs near your service and establishes a connection to SparkTun. A route tells SparkTun which private destination belongs to that tunnel.
Your agent uses the destination you configure. The connector forwards requests to the service inside your network, without requiring a public address on that service.
How it works
Cloud agentRequests a destination
SparkTunSelects the route
ConnectorInside your network
Private serviceMCP server or API
Request path · The connector initiates the connection out to SparkTun.
Choose a service your connector can reach.
Create a tunnel and define its destination and service address.
Run a connector inside that network to establish the outbound connection.
Send agent traffic to the configured destination through SparkTun.
Core concepts
Tunnel
A named connection between your network and SparkTun, such as prod-mcp.
Connector
A running replica that connects outward and forwards traffic to your service.
Route
A destination mapped to a tunnel and the service that handles its requests.
A destination is the published HTTP hostname a visitor wants to reach. A service is the address the connector uses inside your network. For example, demo.localhost can point to http://127.0.0.1:3001.
Use cases
Private MCP servers. Give cloud agents a path to tools running in your own environment.
Internal APIs. Route requests to a service on a VM, workstation, or private application network.
Development environments. Keep a named destination for a local service while you iterate on an agent integration.
Keep the two addresses separate
The published hostname does not need to match the local service host. 127.0.0.1 refers to the connector's machine; use a reachable network address when the service runs elsewhere.
Tunnel health
The dashboard distinguishes tunnel health from connector replicas. A tunnel is Healthy when at least one of its connectors is online.
Status
Meaning
Healthy
The connection node reports the route online and the connector has a current readiness heartbeat.
Inactive
No connector is connected.
Connection health alone does not verify the origin response. Check the destination, service address, and application response when validating a route.
Build the SparkTun binary from this project, then run it on the machine that can reach your service. Save the connector token file from the creation dialog; it is shown once.
Use the actual downloaded token filename and control URL from the console. A remote control service requires HTTPS. Keep the connector running and wait for Healthy.
Outbound connections
The connector initiates the connection to SparkTun. Your service does not need an inbound port opened to the Internet. The connector must be able to reach both SparkTun and the local service.
3Review your route
A route maps the published hostname to its connector. In Routes, check the hostname and connector. The local service address is configured on the connector with --origin.
Field
Example
Tunnel
production-mcp
Destination
demo.localhost
Service
http://127.0.0.1:3001
Use the address as seen from the connector. A service on the same machine can use http://localhost:3001. For a service on another machine, use its reachable address, such as http://10.0.4.12:3001.
Confirm the tunnel is Healthy and a connector replica is online.
Open the published URL from Routes. In the local demo, visit http://demo.localhost:8090.
Check that your application returns the expected response.
Open Logs to review connector and route events.
Your service is now reachable through its configured SparkTun route. A Healthy tunnel confirms the connector connection; an application response confirms the complete request path.
Next steps
Review Connectors to inspect replica status.
Open Administration to configure the default publication domain and service addresses. DNS and public certificates are configured separately.
Use Logs to investigate connection and routing events.