Linkdocs

Your own relay

Put Link's relay on your Cloudflare account in one command, for networks where no direct path forms.

Most of the time the phone reaches your computer without a relay. A relay is for the networks where it can't: strict mobile carriers, guest Wi-Fi, office networks. Link puts the relay on your own Cloudflare account (the free plan is enough), so nobody else runs a server in your path.

Deploy it

Make a Cloudflare API token. In the Cloudflare dashboard, open My Profile → API Tokens, choose Create Token, and use the Edit Cloudflare Workers template.

Deploy the relay:

link-host relay deploy

It asks for the token without showing it (or reads CLOUDFLARE_API_TOKEN), uploads the relay as a Worker named link-relay, waits for its workers.dev address to answer, and prints it:

Your relay is running at wss://link-relay.you.workers.dev
Pair your phone through it:
  link-host ssh setup --relay wss://link-relay.you.workers.dev

If the token can see several Cloudflare accounts, choose one with --account ACCOUNT_ID.

Pair through it with the command it printed. The relay address is remembered, so later link-host ssh setup runs use it too.

Link Host keeps the token only for the deploy; it isn't stored.

What the relay sees

  • Ciphertext. The phone's SSH connection is encrypted to your computer's SSH server; the relay splices bytes it can't read.
  • Who's connecting, and when. It admits only phones whose token your computer registered at pairing, and holds only hashes of those tokens.
  • Addresses, to introduce the two sides. When both sides can punch a direct path, the relay hands each the other's addresses and steps out; the session then doesn't pass through it.

TURN, for the strictest networks

When both the phone and the computer sit behind NATs that defeat punching, a Cloudflare Realtime TURN key on the relay gives the computer short-lived TURN credentials. It then offers a TURN address as one more way in, still carrying only encrypted SSH. Create a TURN key in the dashboard (Realtime → TURN Server) and deploy with it:

LINK_TURN_KEY_ID=… LINK_TURN_KEY_API_TOKEN=… link-host relay deploy

A later deploy without these variables keeps the key already on the relay.

Updating or removing it

Run link-host relay deploy again after updating Link Host to update the relay's code. To remove it, delete the Worker in the Cloudflare dashboard; phones paired through it then need pairing again without --relay.

On this page