Ngrok for AI agents

Ngrok creates secure tunnels to locally hosted applications, enabling developers to share and test webhooks or services without complex network configuration. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Developer toolsAPI keyMCP + RESTngrok.com
AUDIT LOG · NGROKPOLICY: acme-support
09:41:07 · claude · u_8f2read
ngrok.list_vaults
List Vaults✓ allowed · 212ms
09:41:08 · claude · u_8f2read
ngrok.get_vault
Get Vault✓ allowed · 164ms
09:41:09 · claude · u_8f2write
ngrok.create_vault
Create Vault✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
ngrok.delete_vault
Delete Vault✕ blocked · policy: deny
EVERY NGROK CALL, ON THE RECORD
01 · USE CASES

What agents do in Ngrok.

01

Check an endpoint's configuration

Look up an endpoint's current settings before debugging a tunnel issue, read-only.

02

Create a tunnel credential

Create a new credential so a local service can establish a secure tunnel.

03

Approve before deleting an edge

Require approval before deleting an HTTPS edge, since it would take down any routes built on it.

02 · ACTIONS

102 Ngrok actions, graded by risk.

Every Ngrok action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

56

Look things up. Allowed by default.

  • ngrok.get_vault
    Get Vault
  • ngrok.get_secret
    Get Secret
  • ngrok.get_api_key
    Get API Key
  • ngrok.list_vaults
    List Vaults
  • ngrok.get_endpoint
    Get Endpoint
  • ngrok.list_tunnels
    List Active Tunnels
  • ngrok.list_api_keys
    List API Keys
  • ngrok.get_https_edge
    Get HTTPS Edge
  • ngrok.list_bot_users
    List Bot Users
  • ngrok.list_endpoints
    List All Endpoints
  • ngrok.list_tcp_edges
    List TCP Edges
  • ngrok.list_tls_edges
    List TLS Edges
  • ngrok.get_credentials
    Get Credentials
  • ngrok.get_event_source
    Get Event Source
  • ngrok.list_credentials
    List Tunnel Credentials
  • ngrok.list_https_edges
    List HTTPS Edges
+ 40 MORE

write

26

Create and change things. Allow, or ask the user first.

  • ngrok.create_vault
    Create Vault
  • ngrok.update_vault
    Update Vault
  • ngrok.update_secret
    Update Secret
  • ngrok.create_api_key
    Create API Key
  • ngrok.update_api_key
    Update API Key
  • ngrok.create_endpoint
    Create Endpoint
  • ngrok.update_endpoint
    Update Endpoint
  • ngrok.create_credential
    Create Tunnel Credential
  • ngrok.create_https_edge
    Create HTTPS Edge
  • ngrok.update_credentials
    Update Credentials
  • ngrok.create_event_source
    Create Event Source
  • ngrok.create_vault_secret
    Create Vault Secret
  • ngrok.create_ssh_credential
    Create SSH Credential
  • ngrok.update_ssh_credential
    Update SSH Credential
  • ngrok.update_reserved_domain
    Update Reserved Domain
  • ngrok.create_https_edge_route
    Create HTTPS Edge Route
+ 10 MORE

destructive

20

Delete, cancel or archive. Ask first, or deny outright.

  • ngrok.delete_vault
    Delete Vault
  • ngrok.delete_secret
    Delete Secret
  • ngrok.delete_api_key
    Delete API Key
  • ngrok.delete_endpoint
    Delete Endpoint
  • ngrok.delete_https_edge
    Delete HTTPS Edge
  • ngrok.delete_credentials
    Delete Credentials
  • ngrok.delete_event_source
    Delete Event Source
  • ngrok.delete_ssh_credentials
    Delete SSH Credentials
  • ngrok.delete_https_edge_route
    Delete HTTPS Edge Route
  • ngrok.delete_event_subscription
    Delete Event Subscription
  • ngrok.delete_edge_route_saml_module
    Delete Edge Route SAML Module
  • ngrok.delete_reserved_domain_certificate
    Delete Reserved Domain Certificate
  • ngrok.delete_edge_route_compression_module
    Delete Edge Route Compression Module
  • ngrok.delete_edge_route_circuit_breaker_module
    Delete HTTPS Edge Route Circuit Breaker Module
  • ngrok.delete_edge_route_request_headers_module
    Delete Edge Route Request Headers Module
  • ngrok.delete_edge_route_response_headers_module
    Delete Edge Route Response Headers Module
+ 4 MORE
03 · HOW IT WORKS

Ngrok in three steps.

  1. 01Your users connect NgrokThey add their Ngrok api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “create Vault” can wait for the user, and “delete Vault” can be denied outright.
  3. 03Any agent can actYour agent calls Ngrok through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('ngrok', {
  read: 'allow',
  write: 'ask',        // create_vault
  destructive: 'deny',  // delete_vault
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Ngrok connects.

Users add their Ngrok api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same Ngrok connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Ngrok from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Ngrok and Arc0, answered.

Q01

Can I use Ngrok with Claude, ChatGPT or Cursor?

Yes. Connect Ngrok to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Ngrok actions you allow.

Q02

How do users connect Ngrok?

Users add their Ngrok api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which Ngrok actions can my agent take?

102 in total: 56 read, 26 write and 20 destructive, such as “create Vault”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Ngrok?

Yes. Actions like “delete Vault” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Ngrok too?

Yes. The same Ngrok connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Ngrok into your agent.

Your users connect Ngrok once, under your brand. Your agent gets 102 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan