HomeLab Everywhere — Expose homelab services to the internet with built-in SSO
Project description
HLE Client
HomeLab Everywhere — Expose homelab services to the internet with built-in SSO authentication, WebSocket support, and webhook forwarding.
One command: hle expose --service http://localhost:8080
Your local service gets a public URL like myapp-x7k.hle.world with automatic HTTPS and SSO protection.
Install
Curl installer (recommended)
curl -fsSL https://get.hle.world | sh
Installs via pipx (preferred), uv, or pip-in-venv. Supports --version:
curl -fsSL https://get.hle.world | sh -s -- --version 2606.1
pipx
pipx install hle-client
Homebrew
brew install hle-world/tap/hle-client
Quick Start
-
Sign up at hle.world and create an API key in the dashboard.
-
Save your API key:
hle auth login
This opens the dashboard in your browser. Copy your key and paste it at the prompt. The key is saved to ~/.config/hle/config.toml.
- Expose a service:
hle expose --service http://localhost:8080
# Or forward webhooks from GitHub/Stripe:
hle webhook --path /hook/github --forward-to http://localhost:3000 --label github-hook
CLI Usage
hle expose
Expose a local service to the internet.
hle expose --service http://localhost:8080 # Basic usage
hle expose --service http://localhost:8080 --label ha # Custom subdomain label
hle expose --service http://localhost:3000 --auth none # Disable SSO
hle expose --service http://localhost:8080 --no-websocket # Disable WS proxying
hle expose --service http://localhost:8080 --allow user@gmail.com # Allow a specific user
hle expose --service http://localhost:8080 --allow google:user@gmail.com --allow github:dev@co.com
Options:
--service— Local service URL (required)--label— Service label for the subdomain (e.g.ha→ha-x7k.hle.world)--auth— Auth mode:sso(default) ornone--allow— Allow an email to access the tunnel (repeatable). Format:emailorprovider:email--websocket/--no-websocket— Enable/disable WebSocket proxying (default: enabled)--verify-ssl— Enable SSL certificate verification for the local service (default: off, accepts self-signed)--upstream-basic-auth USER:PASS— Inject Basic Auth into requests forwarded to the local service--forward-host— Forward the browser's Host header to the local service--api-key— API key (also readsHLE_API_KEYenv var, then config file)
hle webhook
Forward incoming webhooks to a local service.
hle webhook --path /hook/github --forward-to http://localhost:3000 --label github-hook
hle webhook --path /hook/stripe --forward-to http://localhost:4000/stripe --label stripe-hook
Options:
--path— Webhook path prefix, e.g./webhook/github(required). Cannot be/--forward-to— Local URL to forward webhooks to (required)--label— Webhook label, e.g.github-hook(required)--api-key— API key (also readsHLE_API_KEYenv var, then config file)
Webhook tunnels bypass SSO so external services (GitHub, Stripe, etc.) can deliver payloads without authentication.
Server notices
While a tunnel is connected, the relay can push informational messages that the
client renders to stderr (e.g. ✓ Auto-protect added you@example.com via Google SSO). Wording is server-controlled so new notices do not require a client
release.
hle auth
Manage your API key.
hle auth login # Save key (opens dashboard)
hle auth login --api-key hle_xxx # Save key non-interactively
hle auth status # Show current key source
hle auth logout # Remove saved key
hle config
All tunnel and client configuration lives under hle config. Tunnel
subcommands accept a label (resolved to <label>-<user_code>) or a full
subdomain.
hle config show / list
hle config list # List your active tunnels
hle config show ha # Full status for one tunnel (auth, rules, PIN, …)
hle config auth-mode
hle config auth-mode ha --set sso # SSO gate on
hle config auth-mode ha --set none # Tunnel becomes public
hle config access — SSO email allow-list
hle config access list ha # List rules
hle config access add ha friend@example.com # Allow an email
hle config access add ha dev@co.com --provider github # Require GitHub SSO
hle config access remove ha 42 # Remove rule by ID
hle config access replace ha google:alice@x.com github:bob@y.com # Declarative — adds + prunes
hle config access replace ha --clear # Remove all rules
replace is declarative: rules on the server but not in the args are removed.
hle expose --allow remains additive (never prunes) for ad-hoc sessions.
hle config pin
hle config pin set ha # Set a PIN (prompts for 4-8 digits)
hle config pin status ha # Check PIN status
hle config pin remove ha # Remove PIN
hle config basic-auth
hle config basic-auth set ha # Prompts for username + password (min 8 chars)
hle config basic-auth status ha # Check Basic Auth status
hle config basic-auth remove ha # Remove Basic Auth
hle config share — temporary share links
hle config share create ha # 24h link (default)
hle config share create ha --duration 1h # 1-hour link
hle config share create ha --max-uses 5 # Limited uses
hle config share create ha --label "demo" # Label for reference
hle config share list ha # List share links
hle config share revoke ha 42 # Revoke a link
Global Options
hle --version # Show version
hle --debug ... # Enable debug logging
Configuration
The HLE client stores configuration in ~/.config/hle/config.toml:
api_key = "hle_your_key_here"
API key resolution order:
--api-keyCLI flagHLE_API_KEYenvironment variable~/.config/hle/config.toml
Development
git clone https://github.com/hle-world/hle-client.git
cd hle-client
uv venv && source .venv/bin/activate
uv pip install -e ".[dev]"
# Run tests
pytest
# Lint
ruff check src/ tests/
ruff format --check src/ tests/
License
MIT — see LICENSE.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file hle_client-2606.1.tar.gz.
File metadata
- Download URL: hle_client-2606.1.tar.gz
- Upload date:
- Size: 78.4 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.9
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
622054e1d59bd6df0ea778408e3730cdd6eb10ebf41a8e6034e81d0d20c93d81
|
|
| MD5 |
5b669e23d81dd05e75849e5830bddb22
|
|
| BLAKE2b-256 |
681ce0bde1d9c521d43e957e88a921fc64a7d35247a6bc149d579826c01b7f90
|
File details
Details for the file hle_client-2606.1-py3-none-any.whl.
File metadata
- Download URL: hle_client-2606.1-py3-none-any.whl
- Upload date:
- Size: 43.8 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.9
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
1d3ab0d82ade0a23f8a4e8821857d493ca7287b87551544f0b6a44e29a6e6561
|
|
| MD5 |
17f804e878152f52bc7889eff7239a98
|
|
| BLAKE2b-256 |
844c1f5163a09e7acf25605455f73c2aa772c568bf6fec3c600f9434ab523bee
|