Keep it where it runs
Put the application online. Keep control of the server.
First, connect outward. Your host or Edge connector establishes the WireGuard tunnel to Fibmesh before visitors use the link.
studio-portal.publish.fibmesh.example127.0.0.1:3000studio-api.publish.fibmesh.example127.0.0.1:8080studio-preview.publish.fibmesh.example127.0.0.1:5173The host connector forwards requests to the selected app on the same machine. The app handles its own login or API authentication.
Illustrative Fibmesh subdomains · .example addresses are not live. The production suffix is not final.
- Public link
- The HTTPS address a visitor opens. Each app can have a different address.
- Connector
- Background software on a supported application host or LAN connector. It connects to Fibmesh and forwards requests to the chosen app.
- Publication
- The saved link between a hostname, connector and selected application. The application checks visitor access.
What would you publish?
A business application deserves more than a temporary workaround.

Illustrative scenario / self-hosted portal
The app stays in your office. The link reaches your customer.
Publish connects a selected web app on your own compute. The visitor follows an HTTPS link and signs in with the application’s account.
- Customer browser
- Public HTTPS URL
- Connector → your portal
APIs & webhooks
Give the other system somewhere to call.
Receive HTTP requests at a stable endpoint, including integrations whose sender cannot join your private network. Validate API tokens and webhook signatures in the application.
Reviews & development
Share the working app.
Let a client review a preview without deploying another copy. Use test data, limit the audience and retire the publication when the review ends.
Customer-site equipment
Reach its web interface through Edge.
Give an approved web interface a separate public address through a connector on the LAN. A device’s video, discovery or native-client protocols need their own compatibility check.
One host / several publications
Manage the app’s address separately from its machine.
Publish maps each selected HTTP application and port to a Fibmesh-managed subdomain. Several publications can share one connector: a portal, an API and a preview, each with its own address. A domain you own is a planned extension.
Pause or remove a preview without affecting the API beside it. Retarget a hostname when you move the application, then verify the new destination before sending users there. The application checks users and API credentials; Fibmesh-managed visitor access is a planned extension.
Persistent publications run through the background connector service, so closing an administrative terminal does not end an otherwise healthy connection. The proposed CLI workflow is a separate automation reference.
Explore the CLI and automation design →Choose the right connection
A web address, a private network or a public IP?
Publish
Use a selected HTTP application through an HTTPS hostname. The public gateway routes the request; a dedicated public IPv4 address is not required for each app.
Addresses and access →Networks or Public IPs
Use Networks for private resource access by enrolled devices. Choose Public IPs when clients need address-level reachability or protocols outside the web publishing model.
Compare the options →Before you begin
A reachable app. A supported connector. An explicit audience.
The application and connector need to remain online. A connector on the application host reaches an app on localhost; a supported LAN connector reaches a selected service on another device without changing that device’s address or software. Confirm connector support and application compatibility during setup. Edge hardware remains a development and pilot option.
The connector needs an internet path that permits WireGuard traffic and a route to the chosen application. It initiates the tunnel outward, so the connection does not need an inbound port-forward on the site router. Publish carries application requests and their replies while leaving the host’s ordinary outgoing route in place.
Keep application accounts, data permissions and backups under your control. Verify access controls before sharing a link.
Prepare your first publication →