WireCanal™
No open ports. Connect from anywhere. Secure tunnel and AI / MCP gateway
Reach services on your local machine from outside, without opening inbound ports or building a VPN
WireCanal lets you securely access services running on your local PC, internal servers and IoT devices such as Raspberry Pi from the outside.
A small resident program (the Agent) placed on your side opens a single outbound tunnel by itself, so there is no need to open inbound ports on your router or firewall. All your network has to allow is outbound 443.
There are two ways to use it. As a secure tunnel, it publishes localhost, internal web apps, RDP, SSH and databases over HTTPS or raw TCP. As an AI / MCP gateway, it turns your in-house MCP server into a remote MCP URL that Claude, ChatGPT, Grok and Bestllam can use. Both run on the same single tunnel.
The relay infrastructure (Edge) is operated on servers in Japan. Your existing servers and applications stay untouched. You only place the Agent and one configuration file. Single binaries for Windows and Linux (x86_64, arm64, armv6/armv7) install with a one-liner.
Key Features of WireCanal™
No inbound port openings
Not a single port to open. No router configuration, no DMZ, no port-opening requests, no static IP. The entrance can be restricted to the fixed IPs of legitimate callers only.
No VPN
No site-to-site VPNs or leased lines. One authenticated tunnel passes only the endpoints you allow, and keeps working across dynamic IPs, multiple sites and line changes.
An MCP gateway that shows AI only the tools you allow
Even if your in-house MCP server has 20 tools, only the ones you allow are visible to outside AI. The allowlist lives in a configuration file on your side, so the cloud provider cannot widen it (two-key). OAuth authentication required by the ChatGPT and Claude connectors is built in.
Fixed forwarding destinations and fail-closed design
The Agent never connects to destinations other than those you allow, and entrance credentials are never handed to the forwarding destination. Eight kinds of access protection (IP restriction, country restriction, BASIC auth, Bearer token, time-window publishing, path restriction, auto-block and stealth mode) are available on every plan.
Protocols and Environments
- HTTPS canal (publish web apps over HTTPS as they are; certificates are issued and renewed automatically)
- TCP canal (RDP / SSH / databases and more; Pro plan and above)
- MCP canal (turn an in-house MCP server into a remote MCP URL; available on all plans)
- Verified AI services: Bestllam, Claude (claude.ai / Claude Code), ChatGPT, Grok, Gemini CLI
- Agent: single binary for Windows / Linux (under 10MB, around 10MB resident memory). Runs on Raspberry Pi 5/4/3/Zero 2 W and 32-bit ARM boards
- Corporate proxies are handled with one line in the config file. Runs as a Windows service or under systemd
Pricing (JPY, tax included, annual billing shown as monthly equivalent)
Anyone can register for free, and the Free plan has no time limit. Paid plans are also available on monthly billing (Lite 1,580 yen, Pro 3,580 yen, Premium 11,800 yen).
| Plan | Monthly | Canals | Highlights |
|---|---|---|---|
| Free | 0 yen | 1 | MCP integration, access protection, access logs (latest 1,000). Random hostname that expires 72 hours after the Agent's last connection |
| Lite | 1,280 yen | 1 | Persistent hostname with your preferred subdomain. For one permanent fixed URL |
| Pro | 2,980 yen | 3 | Persistent subdomains, TCP canal (RDP/SSH/DB), API, canal transfer |
| Premium | 9,980 yen | 20 | 1Gbps line, bring your own domain, individual support, access logs (latest 10,000) |
| Team | 4,980 yen per seat, from 10 seats | 200 (shared by the team) | Premium-level features for every member. 49,800 yen/month for 10 seats |
| Enterprise | Custom quote | 100 to 1,000 in bulk | Seat-based contract, invoice billing, dedicated servers, consulting on MCP design |
Additional canal add-on: 1,980 yen/month (paid plans). Paid plans have no transfer cap in principle; the Free plan is guided at 10GB/month. See the WireCanal pricing page for the latest terms (transcribed as of 2026-09-08).
FAQ (excerpt)
Does it really work without opening inbound ports?
Yes. The Agent only opens an outbound tunnel from your side, so no inbound ports are needed on your router or firewall. Proxy-only environments are supported with a single setting.
How is it different from ngrok?
The basics such as HTTPS publishing, TCP, custom domains and IP restriction exist in both. The differences are three: relay servers located in Japan, eight kinds of access protection on every plan, and an MCP gateway that exposes only the tools you choose from your in-house MCP server.
Do I need to modify existing servers or apps?
No. WireCanal carries raw traffic as a plain pipe, so no configuration changes or code changes are required on the servers you publish.
Product Site / Free Sign-up
No credit card required. Create your first canal right away.
Go to WireCanal Official SiteEnterprise and MCP Design Inquiries
For Team / Enterprise deployment or designing MCP access to your internal systems, please contact us below
Go to Contact Form