> Documentation index: https://docs.kiste.run/llms.txt, a list of every page in this documentation.

# Overview

> Publish a port of a Kiste at its own unguessable HTTPS address under kiste.stream, list and stop it.

Kiste Stream gives a port of a Kiste its own address on the web:

```bash
kiste stream 8888
```

```text
https://k7q2…(52 characters)….kiste.stream
```

Anyone who has the address reaches the port over HTTPS and WebSocket, until
you stop it. Use it to show a dev server to a colleague, open a notebook on
your phone, or receive webhooks from another service.

## Publish, list, stop

```bash
kiste stream 3000                              # the current Kiste
kiste stream 3000 --instance build             # another Kiste
kiste stream 8888 --description "JupyterLab"   # say what runs there
kiste stream ls                                # the ports a Kiste streams, with their addresses
kiste stream stop 3000                         # the address stops answering at once
```

The console lists every published port of your account under **Stream**, with
its address and a button to stop it.

## Make your app listen on all interfaces

Kiste Stream connects to the port on the Kiste's network interface, not on its
loopback address. An app that listens only on `127.0.0.1` or `localhost` can't
be reached; start it on `0.0.0.0`:

```bash
python3 -m http.server 8000 --bind 0.0.0.0
npm run dev -- --host 0.0.0.0
jupyter lab --ip 0.0.0.0 --no-browser
```

Many dev servers also check the `Host` header. The request arrives with the
public `*.kiste.stream` host name; allow it in the app (for example Vite's
`server.allowedHosts`, Django's `ALLOWED_HOSTS`).

## How the address works

- Each published port gets a **random 52-character label**; the label *is* the
  permission. It can't be guessed, and nobody can list published ports.
- The address stays the same while the port is published, also across stopping
  and starting the Kiste. A stopped Kiste's address answers
  [S04](https://docs.kiste.run/errors/s.md#s04) until the Kiste runs again.
- `kiste stream stop` ends it at once. A stopped address is never reused; publish
  the port again to get a new one.
- The app is served from the root path, like on any site of its own:
  `https://<label>.kiste.stream/` is the app's `/`.

> **Warning:** Public means public
>
> Everyone who has the address can use the app, with no sign-in in front of it.
> Publish only what you would put on the internet, protect the app itself when
> it needs protection (most notebooks and admin tools have a token or password
> setting), and stop the port when you're done.

## What reaches your app

Apps behave as on a site of their own: cookies, local storage, WebSockets,
service workers, CORS and redirects work as usual. Requests arrive with:

| Header | Value |
| --- | --- |
| `Host`, `X-Forwarded-Host` | The public host, `<label>.kiste.stream` |
| `X-Forwarded-Proto` | `https` |
| `Cookie`, `Authorization`, `Origin` | As the browser sent them |

Kiste's own headers and hop-by-hop headers are removed in both directions.
[Isolation](https://docs.kiste.run/stream/isolation.md) explains how apps are kept apart from kiste.run
and from each other.

## Desktop and Stream

Kiste Stream is for apps. To share your **desktop** with yourself on another
device, use a [desktop link](https://docs.kiste.run/desktop.md#desktop-links): it opens only for your
account.

## Related topics

- [Isolation and cookies](https://docs.kiste.run/stream/isolation.md)
- [Limits](https://docs.kiste.run/stream/limits.md)
- Previous: [Browser terminal](https://docs.kiste.run/ssh/browser-terminal.md)
- Next: [Isolation and cookies](https://docs.kiste.run/stream/isolation.md)
