Runtime

What is SSH port forwarding?

SSH port forwarding carries a TCP connection through an SSH session, so a port on one machine answers as if it were a port on another.

runtime sandbox port-forward <id> 5432 makes localhost:5432 on your machine the database inside a Runtime sandbox, through the API, with no port opened to the internet. Any TCP port works, not only HTTP: Redis, a debugger, a dev server that uses WebSockets (forward ports).

Local and remote forwarding

RFC 4254, the SSH connection protocol, defines both directions as channel types:

Direction Channel What it does
Local direct-tcpip A port on your machine reaches a host and port the server can see
Remote tcpip-forward, then forwarded-tcpip A port on the server reaches back to your machine

With OpenSSH, ssh -L 5432:localhost:5432 server is local forwarding and ssh -R 8080:localhost:3000 server is remote.

When to forward, and when to publish

A forward is private: only the machine that runs it can use the port, and it lasts until you press Ctrl-C. To let others reach a service, publish it instead.

You want On Runtime
Your own tools on a sandbox's database runtime sandbox port-forward
A link to a web app for someone else A preview URL, private by default
A raw TCP port anyone can reach A TCP port, on a paid account (open a TCP port)
Private traffic with your own servers A WireGuard tunnel, $5 a 30-day month

Keep the server running

A forward needs something listening. Start the server with runtime sandbox spawn <id> -- <command> so it keeps running; a process started by exec ends with its command. The forward says so when nothing listens on the port.

Sources

Checked 27 September 2026.