Frameworks
Share a Next.js, Vite, Django, Rails, Laravel, Flask, FastAPI or Express dev server, or a Docker container, through a Horizon tunnel.
Run your framework's dev server as usual, then point hrzn tunnel at its port.
Horizon sends your app its own local address as the Host header, so most "host not allowed" checks pass without changes. The public host arrives in X-Forwarded-Host, and the browser's Origin is still the public URL. That's why a few frameworks need one setting, listed below.
| Framework | Default port | What to change |
|---|---|---|
| Next.js | 3000 | allowedDevOrigins in next.config |
| Vite | 5173 | Nothing |
| Express | 3000 | trust proxy, to read the public host |
| Expo and React Native | 3000 (your API) | Point EXPO_PUBLIC_API_URL at the tunnel |
| Django | 8000 | CSRF_TRUSTED_ORIGINS for POST forms |
| Flask | 5000 | ProxyFix for the public host |
| FastAPI | 8000 | Nothing for most apps |
| Rails | 3000 | config.hosts and the CSRF origin check |
| Laravel | 8000 | Trusted proxies and an HTTPS scheme |
| Docker | Your published port | Nothing |
| Docker Compose | Your published port | Nothing |
| NGINX | Your listen port | Tunnel to the server_name host |
| MAMP, WAMP and XAMPP | 8888 or 80 | Tunnel to the virtual host name |
Test Better Auth social login behind a tunnel
Run Better Auth social sign-in on localhost behind a Horizon tunnel, with baseURL, trustedOrigins and the right callback path.
Share a Next.js dev server
Share a Next.js dev server (next dev) through a Horizon tunnel, with the allowedDevOrigins setting that stops the blocked cross-origin warning.