Local-first transport
The raw MCP service binds to loopback. Remote clients reach it through a supported authenticated connection path instead of turning the local workspace gateway into a public host listener.
- ngrok
- Cloudflare Tunnel
- Direct HTTPS
- Optional OpenAI Secure MCP Tunnel
Capability-oriented tools
RepoTunnel does not expose an unrestricted host API. File, Git, command, browser, desktop, phone, team, continuity, and video operations each retain their own validation and permission rules.
- Workspace IDs instead of absolute roots
- Bounded reads and outputs
- Remote MCP cannot self-approve local Review actions
- Phone access escalation remains user-controlled
OAuth
Public MCP access uses RepoTunnel's OAuth boundary where applicable, including dynamic-client registration and PKCE-compatible flows. Authorization state lives outside project repositories and can be revoked without deleting approved projects.
Verify the complete route
Start the local gateway, choose a supported connection path and authorize the intended AI client. Then list approved projects and request a bounded read of a non-sensitive file.
This validates transport, authentication, tool discovery and workspace access together. Repeat discovery after a schema change when the client caches the available tools.