Publish a port of a Kiste at its own unguessable HTTPS address under kiste.stream, list and stop it.
Kiste Stream gives a port of a Kiste its own address on the web:
Anyone who has the address reaches the port over HTTPS and WebSocket, until you stop it. Use it to show a dev server to a colleague, open a notebook on your phone, or receive webhooks from another service.
Publish, list, stop
The console lists every published port of your account under Stream, with its address and a button to stop it.
Make your app listen on all interfaces
Kiste Stream connects to the port on the Kiste's network interface, not on its
loopback address. An app that listens only on 127.0.0.1 or localhost can't
be reached; start it on 0.0.0.0:
Many dev servers also check the Host header. The request arrives with the
public *.kiste.stream host name; allow it in the app (for example Vite's
server.allowedHosts, Django's ALLOWED_HOSTS).
How the address works
- Each published port gets a random 52-character label; the label is the permission. It can't be guessed, and nobody can list published ports.
- The address stays the same while the port is published, also across stopping and starting the Kiste. A stopped Kiste's address answers S04 until the Kiste runs again.
kiste stream stopends it at once. A stopped address is never reused; publish the port again to get a new one.- The app is served from the root path, like on any site of its own:
https://<label>.kiste.stream/is the app's/.
Public means public
Everyone who has the address can use the app, with no sign-in in front of it. Publish only what you would put on the internet, protect the app itself when it needs protection (most notebooks and admin tools have a token or password setting), and stop the port when you're done.
What reaches your app
Apps behave as on a site of their own: cookies, local storage, WebSockets, service workers, CORS and redirects work as usual. Requests arrive with:
| Header | Value |
|---|---|
Host, X-Forwarded-Host | The public host, <label>.kiste.stream |
X-Forwarded-Proto | https |
Cookie, Authorization, Origin | As the browser sent them |
Kiste's own headers and hop-by-hop headers are removed in both directions. Isolation explains how apps are kept apart from kiste.run and from each other.
Desktop and Stream
Kiste Stream is for apps. To share your desktop with yourself on another device, use a desktop link: it opens only for your account.