outbound only
No inbound ports
Your Kryton opens an outbound HTTP/2 tunnel to our edge. Nothing listens on your home network. NAT, CGNAT, mobile hotspot — all fine.
wildcard tls
HTTPS by default
Every *.my.kryton.ai tunnel terminates on a real Let’s Encrypt certificate we renew for you. No mixed-content warnings, no manual cert dance.
optional, always
Self-host route still works
Kryton is fully self-hostable on your own domain with your own certs. Connect just removes the networking friction for people who’d rather not deal with it.
how it works
Three steps. No port-forwarding, no firewall rules.
$0 · forever
Self-host
Run Kryton on your own server, your own domain, your own certs. The whole codebase is Apache 2.0.
- Full Kryton app + MCP server
- No traffic limits
- You manage TLS & DNS
- Community support
$2 · per month · billed yearly
Connect
The networking goes away. Get a subdomain, managed TLS, and an outbound tunnel that survives ISP reconnects.
- Everything in self-host
- you.my.kryton.ai subdomain
- Auto-renewed wildcard TLS
- Managed outbound tunnel
- Up to 50 GB / month transfer
- Email support · 24h response