Development previewFeatures and availability may change while we test.

PREVIEW · NOT YET IN PRODUCTION

Still allowlisting IP and MAC addresses in the age of AI?

AI makes address spoofing cheap. Beam makes trust hardware-bound.

Stop treating an address—or a copyable certificate file—as an identity.

BetaService publishing

Beam Publish

Beta

The diagram shows the mechanism, its current result, and the limit that remains in force.

  1. Step 1 of 3Enrollment and mTLS survive address churn

    An endpoint keeps its enrolled identity and active mTLS credential while DHCP, NAT, or interface addresses change. Route and location decisions depend on configuration and are verified separately.

  2. Step 2 of 3Stable identity, separately authorized path

    An address change does not rename the enrolled endpoint. The consuming product keeps its own policy, while stronger membership and location checks are verified separately.

  3. Step 3 of 3Limits

    Stronger membership and location-authorization checks are built but not yet turned on in production.

Mechanism

An endpoint keeps its enrolled identity and active mTLS credential while DHCP, NAT, or interface addresses change. Route and location decisions depend on configuration and are verified separately.

Platform state

Publish is in beta. Having the command and service in our code does not mean it is publicly available.

Limits

Stronger membership and location-authorization checks are built but not yet turned on in production.

Before you start

Still needed before launch: a validated installer and setup, abuse controls, domain and certificate setup, package distribution, and a final operations sign-off.

Evidence reviewed 2026-08-26

Install, publish a local port, get a URL.

Beam publishes a loopback port over an outbound connection. Three platforms have a published, signed installer that carries the agent. One of them has an end-to-end run on record, and the page says which.

Beam Publish install to URL journey

Beta, verified end to end

Install and enroll the agent, publish a loopback port, open the issued URL, and check the free plan's visibility and idle limits.

  1. Step 1 of 5Install and enroll

    Install the agent and enroll it. The command shown is the one this platform actually publishes.

    curl -fsSL https://get.arivaran.ai/install.sh | sh -s -- aagit
  2. Step 2 of 5Publish a loopback port

    List the local ports you could publish, then publish one loopback target.

    sudo /usr/local/bin/aasetup publish localhost:3000
  3. Step 3 of 5Receive the issued URL

    The relay issues a hostname and acknowledges the registration before the route counts as ready.

    https://<slug>.beam.arivaran.dev
  4. Step 4 of 5Open the local application

    A visitor loads the local application through that hostname over HTTPS.

  5. Step 5 of 5Check who can reach it

    The publish stays up while it is used, inside your plan's limits, until you stop it.

    sudo /usr/local/bin/aasetup publish stop <slug-or-port>

No account? Publish with an invite.

Install the agent the same way, skip enrollment, and publish one URL for up to 2 hours. You need an invite code issued by Arivaran and an email address that can receive a code. Without an invite, enroll the agent with an account. Measured end to end on Linux; the macOS package includes it, but no run on a Mac is recorded yet.

  1. Run the publish with your invite

    Pass the invite code and your email address, and the service emails you a 6-digit code. In a terminal the command asks for it. In a script it exits, and a second run finishes. On a shared machine, let it ask: other local users can read a command's arguments.

    aasetup publish localhost:3000 --invite <code> --email <address>
  2. Enter the emailed code

    The code works for 10 minutes and 5 tries. A correct code spends one use of the invite and issues a grant for up to 2 hours.

    aasetup publish localhost:3000 --code <6 digits>
  3. Share the issued URL

    The relay issues a random HTTPS hostname and serves your loopback port through it until the grant ends.

    https://<slug>.beam.arivaran.dev
  4. Stop it with Ctrl-C

    Press Ctrl-C in the terminal running the publish. An invite publish has no stop command: aasetup publish stop refuses it (anonymous_publish_only, exit 40). The grant also ends it when it expires.

What one grant allows

  • 1 live URL at a time
  • 256 MiB of traffic per grant, at up to 250 kB/s
  • 600 requests per minute
  • Stops after 300 seconds without traffic
  • Torn down when the grant ends, at most 2 hours after you enter the code

No visitor sign-in, reserved name, custom domain or provider-blind mode. Those need an enrolled agent.

When invite publishing is off
hosted_anonymous_disabled is the answer an unenrolled machine gets from a service that has not turned invite publishing on. Enroll the agent with an account to publish there.

The origin opens no inbound port.

The installed agent dials outward for the Beta publish path, so the origin does not open an inbound port for the public visitor.

Required configuration
Installed and enrolled agent; loopback HTTP target; outbound relay connection

Provider-blind has exceptions. These are them.

Publishing where the relay cannot read your traffic is an opt-in route that runs in production, and that route cannot ask visitors to sign in. A plain browser rejects its certificate unless the visitor checks the fingerprint the agent prints.

The default publish, invite publishes, and every publish with visitor sign-in or address rules let the relay terminate TLS and read HTTP, so they are not provider-blind.

These options turn off provider-blind mode

  • --allow-ip <cidr>
  • --policy-file <path>
  • --geo-policy <directive>

Compare the publish paths.

Three rows from the full comparison, each backed by a dated source on the vendor's own site.

Sources verified 2026-10-02

  • Public reach

    Arivaran Beam Publish

    With an already installed and enrolled agent, the reviewed Beta publish command can request a public HTTPS URL.

    Tailscale Funnel

    Tailscale Funnel shares a local service over the public internet with tailscale funnel and a target.

    NetBird Reverse Proxy

    NetBird Reverse Proxy exposes a peer or network resource through a public domain without opening ports on the target machine.

  • First-use path

    Arivaran Beam Publish

    On Linux and macOS, first use is the published install command, an agent sign-in, and then aasetup publish localhost:3000. On Windows, the signed installer replaces the install command.

    Tailscale Funnel

    The official example uses tailscale funnel localhost:3000.

    NetBird Reverse Proxy

    The official temporary-service example uses netbird expose 8080.

  • Origin network path

    Arivaran Beam Publish

    The installed agent dials outward for the Beta publish path, so the origin does not open an inbound port for the public visitor.

    Tailscale Funnel

    Tailscale Funnel shares a local service over the public internet with tailscale funnel and a target.

    NetBird Reverse Proxy

    NetBird Reverse Proxy exposes a peer or network resource through a public domain without opening ports on the target machine.

See the full comparison

Scoped to Beam Publish. Platform paths measured 2026-09-12.

Release-ready. Saved on this browser.