Open your agent's dev server on your Mac
Updated 3 October 2026. What it says about other tools was checked that day.
Your agent ran npm run dev on the server and says the app is at
http://localhost:5173. That's the server's localhost, not your Mac's.
To see it in your own browser, you carry that port across your SSH connection.
The standard way: ssh -L
ssh -N -L 5173:localhost:5173 myserver
Then open http://localhost:5173 on your Mac. Replace
myserver with the host you SSH into and
5173 with the port your agent reported.
-N means no shell, just the tunnel: leave it running while you
look, and press ⌃C to close it. Hot reload goes through the same
tunnel.
Keep the same port number on both sides. The app's links, cookies and sign-in redirects expect it, and a different local port breaks them in ways that look like bugs in the app.
When it says “administratively prohibited”
The tunnel starts, but the page doesn't load, and ssh prints:
channel 2: open failed: administratively prohibited: open failed
The server has port forwarding turned off (AllowTcpForwarding no
in its sshd_config). Hardened servers do this, and it's Alpine
Linux's default.
- If the server is yours, set
AllowTcpForwarding local, which allows-Lbut not-R, and reload sshd. - If it isn't, carry each connection through a command the server already has. With
socaton your Mac (brew install socat):
socat TCP-LISTEN:5173,bind=127.0.0.1,reuseaddr,fork \ EXEC:"ssh myserver nc 127.0.0.1 5173"
Every browser connection opens its own SSH session running nc on
the server. It works, but without ControlMaster in your ssh config
each one pays for a new login, and pages load slowly.
Other ways
- VS Code's Remote-SSH forwards a port for you when a dev server starts in its terminal. Handy if you already work in VS Code.
- Open it to the network. Start the dev server on every address
(
--hostfor Vite) and visit the server's address. On a public server that puts your work in progress on the internet, so do it only on a private network such as Tailscale. Visit it by name rather than IP address and Vite answers “Blocked request. This host is not allowed” until you add the name toserver.allowedHosts.
With Hostbeam
Open Hostbeam's menu-bar popover. It asks the current host which ports your SSH user is
listening on (your dev servers, not the host's own services) and lists them. Click
Open, and the page opens in your browser at 127.0.0.1, on
the same port when it's free.
-
It works where
ssh -Lis refused, usingnc,bashorperlalready on the server. Nothing is installed or left behind. - It looks only when you open the popover. While a page is open, one connection stays up, shown in the popover and the menu bar, until you click Stop.
- The page is reachable from your Mac only, never from your network.
Mac only, in Hostbeam 0.1.33 or later.
Try Hostbeam
Free, with no limit and no account, on macOS 13 and later. It uses the SSH keys and
~/.ssh/config you already have, and installs nothing on the
server.