A config-driven TCP proxy that intercepts connections and routes them through authenticated CoreLink sessions. No TUN/TAP, no root required.
See It In Action
Your tools. Your workflow. CoreLink underneath.
The client agent runs on high ports -- no root, no TUN/TAP, no VPN client.
Download the CoreLink client agent for your platform. It runs as a userspace binary -- no elevated permissions, no kernel modules, no VPN configuration.
Define your targets in a simple JSON config. Each target maps an alias to a local port. The agent generates a hosts file entry so your tools use the alias directly.
Use psql, ssh, or any native client as normal. The proxy intercepts the connection, provisions JIT credentials with a configurable TTL, and routes through an authenticated CoreLink session.
The proxy runs on high ports -- no root, no kernel changes, no TUN/TAP devices.
Native Tools
TCP Proxy
High-port listener, no root required, session caching with TTL
JIT Credentials
TTL-scoped credentials provisioned per connection, session recorded
Any Protocol
Deploy the CoreLink client agent and get transparent, JIT-brokered access to every target -- using the tools you already use.