Guides

Open your agent's dev server on your Mac

Updated 3 October 2026. What it says about other tools was checked that day.

Your agent ran npm run dev on the server and says the app is at http://localhost:5173. That's the server's localhost, not your Mac's. To see it in your own browser, you carry that port across your SSH connection.

The standard way: ssh -L

ssh -N -L 5173:localhost:5173 myserver

Then open http://localhost:5173 on your Mac. Replace myserver with the host you SSH into and 5173 with the port your agent reported. -N means no shell, just the tunnel: leave it running while you look, and press ⌃C to close it. Hot reload goes through the same tunnel.

Keep the same port number on both sides. The app's links, cookies and sign-in redirects expect it, and a different local port breaks them in ways that look like bugs in the app.

When it says “administratively prohibited”

The tunnel starts, but the page doesn't load, and ssh prints:

channel 2: open failed: administratively prohibited: open failed

The server has port forwarding turned off (AllowTcpForwarding no in its sshd_config). Hardened servers do this, and it's Alpine Linux's default.

  • If the server is yours, set AllowTcpForwarding local, which allows -L but not -R, and reload sshd.
  • If it isn't, carry each connection through a command the server already has. With socat on your Mac (brew install socat):
socat TCP-LISTEN:5173,bind=127.0.0.1,reuseaddr,fork \
  EXEC:"ssh myserver nc 127.0.0.1 5173"

Every browser connection opens its own SSH session running nc on the server. It works, but without ControlMaster in your ssh config each one pays for a new login, and pages load slowly.

Other ways

  • VS Code's Remote-SSH forwards a port for you when a dev server starts in its terminal. Handy if you already work in VS Code.
  • Open it to the network. Start the dev server on every address (--host for Vite) and visit the server's address. On a public server that puts your work in progress on the internet, so do it only on a private network such as Tailscale. Visit it by name rather than IP address and Vite answers “Blocked request. This host is not allowed” until you add the name to server.allowedHosts.

With Hostbeam

Open Hostbeam's menu-bar popover. It asks the current host which ports your SSH user is listening on (your dev servers, not the host's own services) and lists them. Click Open, and the page opens in your browser at 127.0.0.1, on the same port when it's free.

  • It works where ssh -L is refused, using nc, bash or perl already on the server. Nothing is installed or left behind.
  • It looks only when you open the popover. While a page is open, one connection stays up, shown in the popover and the menu bar, until you click Stop.
  • The page is reachable from your Mac only, never from your network.

Mac only, in Hostbeam 0.1.33 or later.

Try Hostbeam

Free, with no limit and no account, on macOS 13 and later. It uses the SSH keys and ~/.ssh/config you already have, and installs nothing on the server.

Download for macOS or brew install --cask punkabeat/tap/hostbeam