All Use Cases
PAM

Connect to Any Target Without Changing Your Workflow

A config-driven TCP proxy that intercepts connections and routes them through authenticated CoreLink sessions. No TUN/TAP, no root required.

Watch the Transparent Proxy

Your tools. Your workflow. CoreLink underneath.

Three steps. Zero workflow changes.

The client agent runs on high ports -- no root, no TUN/TAP, no VPN client.

Install Agent

Download the CoreLink client agent for your platform. It runs as a userspace binary -- no elevated permissions, no kernel modules, no VPN configuration.

Configure Targets

Define your targets in a simple JSON config. Each target maps an alias to a local port. The agent generates a hosts file entry so your tools use the alias directly.

Connect Transparently

Use psql, ssh, or any native client as normal. The proxy intercepts the connection, provisions JIT credentials with a configurable TTL, and routes through an authenticated CoreLink session.

Transparent to Your Tools. Enforced by the Platform.

The proxy runs on high ports -- no root, no kernel changes, no TUN/TAP devices.

Your Client

Native Tools

psql ssh mysql rdp
Use your existing native tools unchanged. The proxy intercepts at the loopback interface -- no configuration changes to your client.

Client Agent

TCP Proxy

High-port listener, no root required, session caching with TTL

Listens on configured high ports. Caches sessions so reconnects within the TTL reuse the same JIT credentials without a round trip.

Platform

JIT Credentials

TTL-scoped credentials provisioned per connection, session recorded

JIT credentials are provisioned with a configurable TTL. All session activity is recorded and auditable.

Target

Any Protocol

SSH RDP Postgres MySQL
SSH, RDP, PostgreSQL, and MySQL targets are supported. The proxy handles protocol-specific credential injection transparently.
Client agent runs on
Linux
macOS
Windows

Ready to connect without changing your workflow?

Deploy the CoreLink client agent and get transparent, JIT-brokered access to every target -- using the tools you already use.