ax-check.com
by Gauge
N
ngrok
ngrok.ai
ax-check.com
Checked 6 October 2026
A
100/100
Agents need your login
Agents can get ngrok.ai running and priced with no detours.
21 of 23 checklist items pass: quickstart, SDK code, and pricing are all readable without logging in first. All 3 coding sessions finished and reported pricing correctly.
1 fix to start with
Concrete changes, backed by what we found.
Recorded coding sessions
Same task, 3 models, no ngrok.ai account. Recorded 6 October 2026 on Pi.
3 recorded · 39s
39s · recorded
Session findings
Select a finding to see it in context.
›Thinking…
Let me first look at the current repo to understand the context.
Let me be honest and helpful. The user wants a simple ngrok example, pricing info, and whether it's easy for me (an agent) to manage. Also constraints: no local service stacks, no long-running commands.
Key issue: ngrok requires an authtoken and a running local service to tunnel to (ngrok agent forwarding to localhost). The ngrok SDKs (ngrok-agent SDK, ngrok-node, etc.) actually require running a local agent process and a local service. There's no "hosted product you can just call via API" that does anything useful without a local endpoint. Well — ngrok has an API for managing the account (API keys, edge routes, domains, cloud endpoints). Cloud Endpoints is a feature where ngrok hosts... actually "Cloud Endpoints" lets you define an ngrok edge that forwards to a cloud service (AWS Lambda, etc.) without running an agent. That could be managed purely via API.
But realistically: to build a "simple example using ngrok", you need a local service + agent running as a long-running process. That violates the constraint. I should check the repo first, then say plainly.
Let me check the repo state.
pwd; ls -la; echo "---"; git log --oneline -5 2>/dev/null | head; echo "---"; cat README.md 2>/dev/null | head -40
/sandbox/repo
/sandbox/repo total 16 drwxr-xr-x 3 root root 4096 Sep 18 08:00 . drwxr-xr-x 7 root root 4096 Oct 6 19:28 .. drwxr-xr-x 8 root root 4096 Sep 24 20:05 .git -rw-r--r-- 1 root root 408 Sep 18 08:00 .gitignore --- 9ebf5fb Initial workspace ---
Recorded tool call
{
"type": "tool_call",
"seq": 3,
"ts": "2026-10-06T19:29:01.179Z",
"name": "bash",
"turn": 1,
"input": {
"command": "pwd; ls -la; echo \"---\"; git log --oneline -5 2>/dev/null | head; echo \"---\"; cat README.md 2>/dev/null | head -40"
},
"run_id": "cmux2nra7002u0iwpr3u7mhmy",
"tool_id": "chatcmpl-tool-82e973b0f06de8d9",
"tool_kind": "shell"
}Recorded tool result
{
"type": "tool_result",
"seq": 5,
"ts": "2026-10-06T19:29:01.179Z",
"turn": 1,
"output": {
"content": [
{
"text": "/sandbox/repo\ntotal 16\ndrwxr-xr-x 3 root root 4096 Sep 18 08:00 .\ndrwxr-xr-x 7 root root 4096 Oct 6 19:28 ..\ndrwxr-xr-x 8 root root 4096 Sep 24 20:05 .git\n-rw-r--r-- 1 root root 408 Sep 18 08:00 .gitignore\n---\n9ebf5fb Initial workspace\n---\n",
"type": "text"
}
]
},
"run_id": "cmux2nra7002u0iwpr3u7mhmy",
"tool_id": "chatcmpl-tool-82e973b0f06de8d9",
"is_error": false,
"tool_kind": "shell"
}env | grep -iE "ngrok|authtoken" ; echo "exit=$?"; which ngrok; python3 --version; node --version
exit=1
exit=1 Python 3.12.3 v22.23.2
Recorded tool call
{
"type": "tool_call",
"seq": 4,
"ts": "2026-10-06T19:29:01.179Z",
"name": "bash",
"turn": 1,
"input": {
"command": "env | grep -iE \"ngrok|authtoken\" ; echo \"exit=$?\"; which ngrok; python3 --version; node --version"
},
"run_id": "cmux2nra7002u0iwpr3u7mhmy",
"tool_id": "chatcmpl-tool-a8f7082bde4d23a5",
"tool_kind": "shell"
}Recorded tool result
{
"type": "tool_result",
"seq": 6,
"ts": "2026-10-06T19:29:01.179Z",
"turn": 1,
"output": {
"content": [
{
"text": "exit=1\nPython 3.12.3\nv22.23.2\n",
"type": "text"
}
]
},
"run_id": "cmux2nra7002u0iwpr3u7mhmy",
"tool_id": "chatcmpl-tool-a8f7082bde4d23a5",
"is_error": false,
"tool_kind": "shell"
}›Thinking…
Empty repo. No ngrok authtoken. Let me quickly verify network access to ngrok API to see if we're blocked. But there's no API key either.
Let me check if there's network at all and whether ngrok API is reachable (unauthenticated will 401, which is fine — proves reachability).
curl -sS -m 10 -o /dev/null -w "api.ngrok.com:%{http_code}\n" https://api.ngrok.com/agent_authtokens 2>&1; curl -sS -m 10 -o /dev/null -w "pypi:%{http_code}\n" https://pypi.org/simple/ngrok/ 2>&1api.ngrok.com:404
api.ngrok.com:404 pypi:200
Recorded tool call
{
"type": "tool_call",
"seq": 9,
"ts": "2026-10-06T19:29:03.008Z",
"name": "bash",
"turn": 1,
"input": {
"command": "curl -sS -m 10 -o /dev/null -w \"api.ngrok.com:%{http_code}\\n\" https://api.ngrok.com/agent_authtokens 2>&1; curl -sS -m 10 -o /dev/null -w \"pypi:%{http_code}\\n\" https://pypi.org/simple/ngrok/ 2>&1"
},
"run_id": "cmux2nra7002u0iwpr3u7mhmy",
"tool_id": "chatcmpl-tool-ad25f76faa0ebf26",
"tool_kind": "shell"
}Recorded tool result
{
"type": "tool_result",
"seq": 12,
"ts": "2026-10-06T19:29:04.222Z",
"turn": 1,
"output": {
"content": [
{
"text": "api.ngrok.com:404\npypi:200\n",
"type": "text"
}
]
},
"run_id": "cmux2nra7002u0iwpr3u7mhmy",
"tool_id": "chatcmpl-tool-ad25f76faa0ebf26",
"is_error": false,
"tool_kind": "shell"
}›Thinking…
Network works. But no ngrok account credentials, and crucially:
ngrok's core value = tunnel a public URL to a local service. Any real example requires:
- A local service running (long-running) — explicitly forbidden.
- An ngrok agent/tunnel process running (long-running) — explicitly forbidden.
- An ngrok account + authtoken/API key — not present.
So per instructions, I should say so plainly and stop. But I should still deliver the value I can: pricing, and the manageability assessment. And I can write a small ready-to-run example that they can run themselves when they have creds — that's light, no service stack started by me. Actually the instruction says "if the quickstart requires either [local service stacks or long-running commands], say so plainly and stop." So I should stop rather than build. But writing files that don't run anything is arguably fine and helpful. The instruction says "stop" — I'll say plainly and stop, but I'll still give pricing + manageability + note what's blocked, and optionally leave a minimal scaffold? I think the cleanest: report plainly, give pricing and manageability, and stop without creating long-running stuff. I could offer a scaffold file that they run later — that's not starting anything. I'll keep it minimal: one file, not executed. Hmm, "say so plainly and stop" — I'll honor that literally: no code changes. I'll just report. That's safest and respects the instruction.
Let me get pricing accurate. ngrok pricing (as of my knowledge): Free plan — 1 user, 1 agent? Let me recall: ngrok pricing tiers: Free, Personal ($8/mo), Pro ($20/mo? or $20 per user), Enterprise. Recent ngrok pricing: Free ($0), Personal ($8/mo per user?), Pro ($20/mo), Enterprise custom. Limits: Free: 1 online agent/session, 20 online endpoints? Actually free: 1 agent, 20 endpoints, 1 GB egress? Hmm. I shouldn't fabricate precise numbers. Let me check if I can fetch ngrok.com/pricing — probably JS-rendered but let's try quickly. That's a light read-only call.
cd /tmp && curl -sSL -m 15 https://ngrok.com/pricing -o p.html -w "%{http_code}\n" && wc -c p.html && python3 - <<'EOF'
import re,html
t=open('/tmp/p.html',encoding='utf-8',errors='ignore').read()
t=re.sub(r'<script.*?</script>|<style.*?</style>','',t,flags=re.S)
t=html.unescape(re.sub(r'<[^>]+>',' ',t))
t=re.sub(r'\s+',' ',t)
for kw in ['Free','Personal','Pro','Enterprise','$']:
for m in re.finditer(kw,t):
print(repr(t[max(0,m.start()-60):m.start()+90]))
break
print('---DOLLARS---')
print(sorted(set(re.findall(r'\$\d[\d,]*(?:\.\d\d)?',t))))
EOF200
200 251183 p.html 'utes, or talk with us for contracts, compliance, and scale. Free Get it online fast and free $5 of one-time included usage No additional usage beyond ' 'unnels & Kubernetes Ingress Skip to main content ngrok home Products Problems We Solve Resources Docs Download Pricing Log in Sign up Products Gateway' ', and more... $20 monthly + additional usage Start building Enterprise Same ngrok your devs already love—plus the contracts, compliance, and humans on' 'inkedIn YouTube RSS All systems operational We use cookies. ' ---DOLLARS--- ['$0', '$0.01', '$0.02', '$0.06', '$0.10', '$0.25', '$0.27', '$1', '$1,000', '$10', '$10,000', '$12,000', '$15', '$2', '$2,400', '$20', '$200', '$24', '$5', '$900']
Recorded tool call
{
"type": "tool_call",
"seq": 15,
"ts": "2026-10-06T19:29:08.845Z",
"name": "bash",
"turn": 1,
"input": {
"command": "cd /tmp && curl -sSL -m 15 https://ngrok.com/pricing -o p.html -w \"%{http_code}\\n\" && wc -c p.html && python3 - <<'EOF'\nimport re,html\nt=open('/tmp/p.html',encoding='utf-8',errors='ignore').read()\nt=re.sub(r'<script.*?</script>|<style.*?</style>','',t,flags=re.S)\nt=html.unescape(re.sub(r'<[^>]+>',' ',t))\nt=re.sub(r'\\s+',' ',t)\nfor kw in ['Free','Personal','Pro','Enterprise','$']:\n for m in re.finditer(kw,t):\n print(repr(t[max(0,m.start()-60):m.start()+90]))\n break\nprint('---DOLLARS---')\nprint(sorted(set(re.findall(r'\\$\\d[\\d,]*(?:\\.\\d\\d)?',t))))\nEOF"
},
"run_id": "cmux2nra7002u0iwpr3u7mhmy",
"tool_id": "chatcmpl-tool-ba72b90d88a71eca",
"tool_kind": "shell"
}Recorded tool result
{
"type": "tool_result",
"seq": 17,
"ts": "2026-10-06T19:29:10.258Z",
"turn": 1,
"output": {
"content": [
{
"text": "200\n251183 p.html\n'utes, or talk with us for contracts, compliance, and scale. Free Get it online fast and free $5 of one-time included usage No additional usage beyond '\n'unnels & Kubernetes Ingress Skip to main content ngrok home Products Problems We Solve Resources Docs Download Pricing Log in Sign up Products Gateway'\n', and more... $20 monthly + additional usage Start building Enterprise Same ngrok your devs already love—plus the contracts, compliance, and humans on'\n'inkedIn YouTube RSS All systems operational We use cookies. '\n---DOLLARS---\n['$0', '$0.01', '$0.02', '$0.06', '$0.10', '$0.25', '$0.27', '$1', '$1,000', '$10', '$10,000', '$12,000', '$15', '$2', '$2,400', '$20', '$200', '$24', '$5', '$900']\n",
"type": "text"
}
]
},
"run_id": "cmux2nra7002u0iwpr3u7mhmy",
"tool_id": "chatcmpl-tool-ba72b90d88a71eca",
"is_error": false,
"tool_kind": "shell"
}›Thinking…
Pricing has changed to usage-based: "$5 of one-time included usage" for Free, "$20 monthly + additional usage" for... let me extract the plan blocks more carefully to be accurate.
cd /tmp && python3 - <<'EOF'
import re,html
t=open('p.html',encoding='utf-8',errors='ignore').read()
t=re.sub(r'<script.*?</script>|<style.*?</style>','',t,flags=re.S)
t=html.unescape(re.sub(r'<[^>]+>',' ',t)); t=re.sub(r'\s+',' ',t)
i=t.find('Free Get it online fast')
print(t[i:i+2600])
EOFFree Get it online fast and free $5 of one-time included usage No additional usage beyond credit Up to 3 online endpoints Up to 1GB data transfer Up to 20k HTTP
Free Get it online fast and free $5 of one-time included usage No additional usage beyond credit Up to 3 online endpoints Up to 1GB data transfer Up to 20k HTTP/S requests Interstitial page on HTTP/S endpoints Assigned dev domain for public endpoints 1 team member $0 Start for free Hobbyist For solo devs, home labs, game servers $10 of monthly included usage No additional usage beyond credit Up to 3 online endpoints 5GB data transfer included (more w/ credit) 100k HTTP/S reqs included (more w/ credit) No Interstitial page on HTTP/S endpoints ngrok-branded domains for public endpoints 1 team member Save $24 with annual billing $10 monthly Get Hobbyist Pay-as-you-go For teams shipping production traffic Unlimited Usage $20 of monthly included usage Additional usage billed monthly Unlimited online endpoints Unlimited data transfer (5GB included) Unlimited HTTP/S requests (100k included) No Interstitial page on HTTP/S endpoints Bring your own domain for public endpoints Unlimited team members (3 included) SSO & RBAC, SCIM add-ons available Wildcard endpoints Mutual TLS, and more... $20 monthly + additional usage Start building Enterprise Same ngrok your devs already love—plus the contracts, compliance, and humans on call that your security team asks about. SSO/SAML and SCIM SLAs with dedicated support Contracts, invoicing, and security reviews HIPAA, SOC 2, BAAs, and custom terms Purchase through AWS Marketplace Per-device and per-customer pricing for customer connectivity See your options Contact us Production traffic for teams at SOC 2 Type II · HIPAA BAAs · Available in AWS Marketplace Connecting devices or customer networks? Per-device and per-customer pricing, scoped to your deployment. Rolling out ngrok across a fleet of devices or into your customers’ networks? We’ll package pricing around how you actually deploy—per device or per customer—instead of asking you to model it out of usage metrics. Tell us about your environment and we’ll put together a plan that’s predictable to budget. Prefer to start self-serve? Every plan above is still pay-as-you-go—no call required. Talk to us about pricing See device gateway Usage credits? Usage credit is an amount that can be spent to use ngrok services. What can usage credits be applied to? Active endpoint hours Data transfer out Requests to HTTP/S endpoints Connections to HTTP/S endpoints Traffic policy (TPUs) Traffic Identities (MAUs) Exported traffic logs What happens when I run out of usage credit on Hobbyist? Your endpoints will stop working until the end of your billing cycle when your usage credit resets.
Recorded tool call
{
"type": "tool_call",
"seq": 20,
"ts": "2026-10-06T19:29:11.360Z",
"name": "bash",
"turn": 1,
"input": {
"command": "cd /tmp && python3 - <<'EOF'\nimport re,html\nt=open('p.html',encoding='utf-8',errors='ignore').read()\nt=re.sub(r'<script.*?</script>|<style.*?</style>','',t,flags=re.S)\nt=html.unescape(re.sub(r'<[^>]+>',' ',t)); t=re.sub(r'\\s+',' ',t)\ni=t.find('Free Get it online fast')\nprint(t[i:i+2600])\nEOF"
},
"run_id": "cmux2nra7002u0iwpr3u7mhmy",
"tool_id": "chatcmpl-tool-87c18801e52c9a91",
"tool_kind": "shell"
}Recorded tool result
{
"type": "tool_result",
"seq": 21,
"ts": "2026-10-06T19:29:11.360Z",
"turn": 1,
"output": {
"content": [
{
"text": "Free Get it online fast and free $5 of one-time included usage No additional usage beyond credit Up to 3 online endpoints Up to 1GB data transfer Up to 20k HTTP/S requests Interstitial page on HTTP/S endpoints Assigned dev domain for public endpoints 1 team member $0 Start for free Hobbyist For solo devs, home labs, game servers $10 of monthly included usage No additional usage beyond credit Up to 3 online endpoints 5GB data transfer included (more w/ credit) 100k HTTP/S reqs included (more w/ credit) No Interstitial page on HTTP/S endpoints ngrok-branded domains for public endpoints 1 team member Save $24 with annual billing $10 monthly Get Hobbyist Pay-as-you-go For teams shipping production traffic Unlimited Usage $20 of monthly included usage Additional usage billed monthly Unlimited online endpoints Unlimited data transfer (5GB included) Unlimited HTTP/S requests (100k included) No Interstitial page on HTTP/S endpoints Bring your own domain for public endpoints Unlimited team members (3 included) SSO & RBAC, SCIM add-ons available Wildcard endpoints Mutual TLS, and more... $20 monthly + additional usage Start building Enterprise Same ngrok your devs already love—plus the contracts, compliance, and humans on call that your security team asks about. SSO/SAML and SCIM SLAs with dedicated support Contracts, invoicing, and security reviews HIPAA, SOC 2, BAAs, and custom terms Purchase through AWS Marketplace Per-device and per-customer pricing for customer connectivity See your options Contact us Production traffic for teams at SOC 2 Type II · HIPAA BAAs · Available in AWS Marketplace Connecting devices or customer networks? Per-device and per-customer pricing, scoped to your deployment. Rolling out ngrok across a fleet of devices or into your customers’ networks? We’ll package pricing around how you actually deploy—per device or per customer—instead of asking you to model it out of usage metrics. Tell us about your environment and we’ll put together a plan that’s predictable to budget. Prefer to start self-serve? Every plan above is still pay-as-you-go—no call required. Talk to us about pricing See device gateway Usage credits? Usage credit is an amount that can be spent to use ngrok services. What can usage credits be applied to? Active endpoint hours Data transfer out Requests to HTTP/S endpoints Connections to HTTP/S endpoints Traffic policy (TPUs) Traffic Identities (MAUs) Exported traffic logs What happens when I run out of usage credit on Hobbyist? Your endpoints will stop working until the end of your billing cycle when your usage credit resets. \n",
"type": "text"
}
]
},
"run_id": "cmux2nra7002u0iwpr3u7mhmy",
"tool_id": "chatcmpl-tool-87c18801e52c9a91",
"is_error": false,
"tool_kind": "shell"
}›Thinking…
Good, I have accurate pricing (scraped today from ngrok.com/pricing).
Now the verdict on building an example: ngrok's quickstart requires (a) a local service (e.g., python -m http.server) and (b) a long-running agent/tunnel process (ngrok http 8080 or the SDK's in-process listener which blocks). Both are forbidden by the constraints. Plus no authtoken/API key in env.
Is there a purely-hosted path? ngrok's control-plane API (api.ngrok.com) manages domains, edges, API keys — that's a real developer workflow I could act on with an API key. But "a simple example using ngrok" that actually serves traffic requires an agent + local service. Cloud Endpoints can forward to cloud upstreams (AWS Lambda/API Gateway) with no agent — but that requires AWS resources I can't create. So even the agentless path needs an upstream I don't control.
Per instructions: say plainly and stop. Don't build. I'll report:
- blocked: yes, at the quickstart level
- pricing
- manageability assessment
I will not write files. Keep concise.
Manageability assessment for an agent like me: honestly it's a mixed bag:
- Hard part: every useful demo is a long-lived foreground process + a local port. Agents that can't hold daemons or expose inbound ports can't verify the tunnel end-to-end. Sessions also die when the process dies → nothing durable to inspect later.
- Easy part: control plane is a clean REST API with an official SDK, paginated, idempotent-ish; domains/edges/API keys are scriptable and inspectable. Ephemeral agent domains mean URL churn (breaks bookmarks/curl scripts, need re-fetch each run).
- Also: credentials are single secrets (NGROK_AUTHTOKEN, NGROK_API_KEY) — easy to inject.
- The free plan's interstitial page breaks non-browser clients (curl gets an HTML warning page unless you set a custom header / skip-browser-warning) — that's a real friction for automated checks.
Verdict: moderately easy for control-plane scripting, poor for end-to-end verification in a no-daemon sandbox.
Keep it tight.
Stopping here — ngrok's quickstart requires exactly what you told me not to do
Checked the repo (/sandbox/repo is empty apart from .gitignore), the environment, and ngrok's live docs/pricing page. Network is fine (api.ngrok.com reachable, PyPI reachable), so this isn't a network block.
The blocker is structural, not environmental:
- A simple ngrok example = local service + long-running agent. ngrok's product is "give my local process a public URL." Every quickstart path (
ngrok http 8080, thengrokPython/Node agent SDK'sngrok.listen(app), the Go/Rust/JS SDKs) requires a foreground process that stays alive for the whole demo plus something serving on a local port. Both are on your forbidden list. - No agentless escape hatch available to me. The one agent-free route (Cloud Endpoints forwarding to a cloud upstream like AWS Lambda/API Gateway) needs cloud resources I can't provision. The ngrok control-plane API alone (
api.ngrok.com— domains, edges, API keys) is real and scriptable, but it moves no traffic, so it isn't "a simple example using ngrok," it's account configuration. - No credentials. No
NGROK_AUTHTOKEN/NGROK_API_KEYin the environment, and I can't sign up for an account on your behalf.
I made no file changes. Say the word and I'll either (a) write the example as un-run code for you to launch yourself, or (b) do the control-plane-only script if you drop in an API key.
Pricing (scraped from ngrok.com/pricing, current)
Usage-based across all tiers, with a monthly included credit:
| Plan | Price | Included usage | Endpoint/traffic caps |
|---|---|---|---|
| Free | $0 | $5 one-time (not recurring) | ≤3 online endpoints, ≤1GB transfer, ≤20k HTTP reqs, interstitial page on HTTP endpoints, assigned dev domain, 1 member |
| Hobbyist | $10/mo ($24/yr saved annual) | $10 monthly | ≤3 online endpoints, 5GB + 100k reqs included, no interstitial, ngrok-branded domains, 1 member |
| Pay-as-you-go | $20/mo + overage | $20 monthly | Unlimited endpoints/transfer/reqs (5GB + 100k included), BYO domain, 3 members included then paid, SSO/RBAC/SCIM add-ons |
| Enterprise | custom | — | SSO/SAML, SLAs, HIPAA/SOC2/BAAs, AWS Marketplace, per-device or per-customer pricing |
Credit burns on: active endpoint-hours, data out, HTTP requests/connections, traffic-policy units, traffic identities (MAUs), exported logs. On Hobbyist, running out of credit stops your endpoints working until the cycle resets. Practical note: because billing is per active endpoint-hour, a tunnel I leave running accidentally is a slow meter, not a free idle.
Will this be easy for me to manage? Split verdict
Easy: credentials are two env vars; the control plane is a clean paginated REST API with official SDKs, so domains/edges/API keys are genuinely scriptable and inspectable.
Hard, and it's the part you asked for: every useful demo is a foreground daemon bound to a local port. In a no-daemon, no-inbound-port sandbox I can't start it, can't keep it alive, and can't verify the public URL end-to-end. Sessions are process-lifetime — when the process exits the URL dies, so there's nothing durable to inspect afterwards, and ephemeral agent domains change every run (any curl command or saved URL goes stale). On Free, the interstitial page means non-browser clients get an HTML warning instead of your response unless you send a skip-browser-warning header, which breaks naive automated checks.
Net: good for scripted account/edge management, poor for a self-verifying end-to-end example in an agent sandbox. That mismatch is why I stopped.
AX Fundamentals
23 checks. Open an area for details.
This check is a quick preview. Test more tasks and models with Gauge Agents.
Test your product with Gauge Agents