Far away.Addressed locally.

Kepos makes services on another machine feel local—without a public IP, account, or virtual subnet.

GET THE RIGHT BUILD All three downloads stay available.

  1. 01No public IP.
  2. 02No account.
  3. 03No virtual subnet.

01 / THE PRODUCT

Open services.
Copy local addresses.

Web services open in place. TCP services expose a local address.

Kepos for Mac showing a connected publisher and its remote services
Kepos for Android showing seven available remote services

02 / PRIVATE TOPOLOGY

One publisher.
Only trusted peers.

The publisher accepts public keys from its local allowlist.

Trust forms a private topology Many trusted peers connect independently to one publisher. No peer-to-peer mesh exists between them. PUBLISHER TRUSTED_PEER_01 TRUSTED_PEER_02 TRUSTED_PEER_03 TRUSTED_PEER_04 ONE PUBLISHER / MANY TRUSTED PEERS

03 / WHY KEPOS

Services,
not a subnet.

Mesh VPNs connect devices. Kepos exposes only selected services.

01 / KEEP

Keep mature apps.

Navidrome, Jellyfin, Forgejo, SSH, and similar services keep their existing clients and workflows.

02 / CHANGE

Change service distribution.

Kepos makes selected access channels direct, authenticated, and P2P instead of exposing a public port.

03 / PRESERVE

Preserve the client.

Browsers, media clients, Git tools, and SSH still use ordinary local URLs or ports.

KEPOS / HOLESAIL

Different shapes of direct access.

Holesail documents a direct encrypted port tunnel with a connection key or QR flow and TCP plus UDP support. Kepos is for a persistent publisher/subscriber relationship with named services, device identities, and per-service authorization. Read the cited comparison

04 / HOW IT WORKS

Direct, authenticated,
and service-scoped.

Kepos opens a clear route through a mountain A subscriber and publisher sit on opposite sides. An encrypted route passes through a tunnel cut into the mountain. PUBLIC EXPOSURE SUBSCRIBER PUBLISHER DIRECT PEER-TO-PEER NO PUBLIC ORIGIN
01

Discover

HyperDHT finds the publisher and attempts NAT traversal.

02

Authenticate

The publisher accepts the subscriber only when its public key is allowed.

03

Open

One encrypted connection carries separate channels for the allowed services.

05 / TECHNICAL LINEAGE

Built on open
peer-to-peer tools.

01 / NETWORK

HyperDHT

Peer discovery, NAT traversal, and encrypted streams.

02 / CHANNELS

Protomux

Independent service channels over one connection.

03 / RUNTIME

Bare

A portable JavaScript runtime for Android and desktop hosts.

Kepos is independent and is not affiliated with or endorsed by Holepunch.

06 / OPEN SOURCE

Read the code.
Build it yourself.

Start with the public guide, then use the repository docs for contributor and architecture detail.