Reach your local PC, in-house MCP servers and IoT devices securely from the outside.
WireCanal crosses NAT with a single outbound tunnel from inside your network — without opening a single inbound port. Its authenticated MCP tunnel mode lets you connect major AI services such as ChatGPT and Claude to your internal systems safely. It also supports HTTPS and TCP protocols (RDP, SSH, and more), so you can use it with confidence for a wide range of workloads.
* Publishing on your own custom domain is available on the Premium plan.

WireCanal is both a secure tunnel and a gateway for AI / MCP integration. Both stand on the same mechanism: a single outbound tunnel.
app.example.co.jp)*Manage HTTPS, MCP, and TCP canals — all different kinds — in a single dashboard. Connection status, the AI services currently linked, and pause / resume are all one click away.

You want to share localhost, or let outside SaaS and AI use your internal systems. WireCanal builds that pathway without opening a single inbound port.
To let the outside reach your network, you used to open inbound ports on the router or stretch VPNs across sites. And if you wanted AI to use internal data, you also had to run your own GPU/LLM stack. Every option came with heavy setup and operations.
An Agent placed inside your network opens a persistent tunnel outward, by itself. No inbound ports, no VPN — HTTP, TCP, and MCP all ride the same single tunnel. The allowed destinations, tools, and paths stay entirely in your hands. The relay infrastructure is operated on servers in Japan.
WireCanal removes the heavy prerequisites that used to be taken for granted when connecting to the outside.
Not a single port to open. The Agent simply connects outward. No router configuration, no DMZ, no port-opening requests, no static IP. The entrance can be restricted to the fixed IPs of legitimate callers only.
No site-to-site VPNs, no leased lines. One authenticated tunnel passes only the endpoints you allow. It keeps working across dynamic IPs, multiple sites, and line changes — freeing you from building and operating VPNs.
No need to build and run your own GPU servers for AI integration. Connect leading cloud AI — GPT-5.5, Claude Opus 4.8, Gemini 3.1 Pro — directly to your internal systems.
To callers, it looks like an ordinary remote URL or remote port. Behind that public entrance, requests travel through a persistent tunnel opened from your side, reach localhost or your internal systems, and the results come back along the same path. Because the Agent only makes outbound connections, no inbound hole is ever opened. HTTP, TCP (RDP, SSH, databases, and more), and MCP all ride this same single tunnel.

WireCanal is designed around defense in depth centered on fixed forwarding destinations, with a fail-closed principle: when in doubt, shut it down. The keystones are the fixed forwarding destination and source-IP restriction that narrows the entrance.
WireCanal's public entrance (Edge) can be restricted to accept access only from the fixed IPs of legitimate callers. A public endpoint in form, effectively a leased line in practice. Caller token authentication adds a second layer on top. An entrance that is "public, yet as good as not public."
The Agent never connects to destinations other than those you allow. We verify on every release, through regression tests, that the tunnel cannot become a pathway into your network.
Entrance authentication is verified by WireCanal, and those credentials are never passed to the forwarding destination. Your internal systems can keep running locally without holding any authentication of their own.
Incoming access is recorded per canal. You can trace who came, when, and from where — via the API or as CSV.
If you have an in-house MCP server that queries your sales database, one canal turns it into a remote MCP URL. Then just ask your AI.

Prices are in US dollars (USD); annual billing is about 2 months cheaper. Anyone can sign up for free. If you are located in Japan, you will be billed in Japanese yen at the yen prices shown on the Japanese page.
1 canal, MCP integration, access protection. The place to start small.
Lite $9.99/mo1 canal, persistent, subdomain of your choice. $99/yr with annual billing.
Recommended Pro $22.99/mo3 canals, persistent subdomains, TCP (RDP, SSH, databases, and more). $229/yr with annual billing.
Premium $74.99/mo20 canals, bring your own custom domain, individual support. $749/yr with annual billing.
200 canals shared across the team. $31.99 per seat per month, from 10 seats ($319.90/month for 10 people; $319 per seat per year with annual billing). Premium-grade features for every member. From sign-up to member invitations, everything is completed on the web.
Yes. The Agent simply opens an outbound tunnel from your local machine or internal network, so there is no need to open inbound ports on your router or firewall. Proxy-only environments are supported with a single configuration entry.
Yes. Even if your in-house MCP server has 20 tools, only the few you allow are shown to the outside AI. The allowlist lives in your own configuration file, so it can never be widened from the cloud side.
The Free plan has no time limit and lets you try the core features: 1 canal, MCP integration, and access protection.
Sign-up is free. No credit card required — create your first canal right now.
Sign up free and get started