Pricing
One public IPv4 address, routed to hardware you already own, from $10 a month. Below is what each plan includes, what it does not, and the things we cannot promise yet — because you will meet all three either way, and it is cheaper for both of us if you meet them now.
The plans
One dedicated, globally routable IPv4 address from our own 23.187.152.0/24, announced by BGP from AS396500 and routed to a machine you already own. An IPv6 /56 comes with it — that is 256 subnets, not a single address, so every container or VM behind your machine can hold its own.
Inbound traffic reaches you at that address. It works from behind NAT or CGNAT with no port forwarding, because your machine dials outbound to us and we route the address down that tunnel.
- Linux, WSL, macOS on Apple Silicon, Windows, or a phone — one installer each, same address whichever you use
- SSH open by default; everything else closed until you open it
- Port rules enforced at our edge, so unwanted traffic is dropped before it reaches your machine
- Machines on the same account can reach each other over the mesh without opening anything publicly
Everything above, and your outbound traffic leaves as that same address instead of your ISP's. This is the plan for the case where a vendor has to allowlist the address you call them from, not just the one they call you on.
You choose the city you exit from — US Central (Chicago) or US East (Newark) — or leave it on anycast and exit through whichever is nearest.
You can start on the $10 plan and upgrade later from the dashboard; the difference is prorated, so nothing is wasted by starting small.
For people who already hold an ASN and their own address space. We carry your prefix and originate it, so you do not need a BGP-capable VPS or a BIRD configuration of your own. Linux and WSL2 only, because BIRD does not run natively on Windows or macOS.
Email support@minakilabs.com with your ASN and we will talk.
The other services
The plans above are the network product: a public IPv4 address on a machine you own. We also run three other services on the same network, priced separately and billed separately. Nothing above bundles them, and nothing below requires the network product.
We also run other services on the same network, priced and billed separately. Nothing above bundles them, and none of them requires the network product: each can be bought on its own. TunnelNet VPN can be bought self-serve: sign in at tunnelnet.io and open its section. New orders for TunnelNet Cloak, TunnelNet Mail, TunnelNet Monitoring and TunnelNet Alerting are paused right now; existing customers are unaffected.
Mail — $5/month
Send from your own domain through our relay, signed. We can show that a message was sent and that the receiving provider accepted it; where it lands after that is not observable from the sending side, so we do not claim it. Details.
Not taking new orders right now. New orders for TunnelNet Mail are paused; existing customers are unaffected. Questions: support@minakilabs.com.
Alerting — $12/month
Email and API alerts with hard spend caps, because the failure mode of an alerting system is not silence, it is a bill. SMS is not live yet — US carrier registration is pending, and we do not bill for what cannot deliver. Details.
Not taking new orders right now. New orders for TunnelNet Alerting are paused; existing customers are unaffected. Questions: support@minakilabs.com.
Monitoring — $10/month
HTTPS, TCP and heartbeat checks run from outside our own network, with a third outcome besides up and down: a probe that cannot prove its traffic left our network is recorded as not measured, never as a green. Details.
Not taking new orders right now. New orders for TunnelNet Monitoring are paused; existing customers are unaffected. Questions: support@minakilabs.com.
TunnelNet Cloak — $10/month
No longer sold to new customers. If you already have TunnelNet Cloak, nothing changes for you. Questions: support@minakilabs.com.
TunnelNet VPN — $30/month
Buy TunnelNet VPN. Or pay with Bitcoin, prepaid 1, 3, 6, 12 months at a time (it does not renew by itself).
How billing works
Each machine is a seat at $10 per month. You press Add a machine on the dashboard, it adds a seat and issues a single-use enrolment token, and you run the installer on that machine. Repeat as often as you like.
Payment is through Stripe and we never see or store your card details. Subscriptions renew monthly until you cancel, and you can cancel at any time from your account — service then continues to the end of the period you have already paid for.
Two things worth knowing before they surprise you. If you remove a machine mid-cycle, you have already paid for that cycle, and the dashboard says so before you click rather than after. And if a payment fails we will retry for a period before suspending, rather than cutting you off on the first decline.
Upgrades between plans are prorated: moving from $10 to $20 mid-month costs you the difference rather than a fresh month.
What we do not do
This section exists because we would rather lose the sale than have the argument later.
The base plan is inbound only. Traffic arriving at your address is routed to you; your own outbound traffic still leaves through your ISP. If you need outbound to carry your address too, that is the $20 plan, and there is no way to get it on the $10 one.
Outbound port 25 is blocked. You cannot run a mail server on a TunnelNet address today. This is our own rule rather than a limitation of our providers, and it is there because a single spam run from our range would poison the address block for every other customer on it. We would like to sell this properly one day; we are not going to sell it before we can do it safely.
Failover takes about 25 seconds, and one kind of failure is not covered at all. We run hubs in two cities and announce your address from both. Measured on 2026-09-16, on our own fleet, from a vantage outside our network: when a hub fails completely and withdraws its routes, a tunnel that is carrying traffic is reachable again 25 seconds later. Your machine re-handshakes at about 16 seconds of that and internet routing catches up by 25. An idle tunnel took 37 seconds to notice, and failing back when the hub returned took about 50. If a hub stays up and keeps announcing but stops forwarding traffic, nothing fails over and it needs us to intervene — we are building a health-gated route withdrawal to close that case, and until it ships this is what the product does. If your service cannot absorb interruptions of this order, you want something with a load balancer in front of it.
We publish our measured availability, and no SLA. Not a slogan — the actual number, taken every 30 seconds from a machine outside our network, on our uptime page, with every incident listed, including the four we caused ourselves. The published record begins 2026-09-10. There is no SLA; the uptime page says when we will consider one, and why.
What this is for. TunnelNet IP and Full give a machine you own a dedicated address the internet can reach — to host something, or to have one stable IP that a bank, a payment processor or a corporate firewall can put on its allowlist. The address is permanently, deliberately yours; that is exactly what makes it useful to an allowlist. If what you want is privacy and a choice of the city your traffic comes out of, that is TunnelNet VPN.
We are not an ISP and we do not sell internet access. You bring the connection and the hardware; we bring the address.
Before you buy, check you need this
There is a real chance a free tool fits your case better, and we would rather you found that out here than after a month of paying us.
If your service is HTTP and a hostname on your own domain is what people will type, Cloudflare Tunnel is free and better than us at that job — your certificate, DDoS absorption, and an identity layer we do not offer.
If the machines that need to reach your server are your own, a private mesh exposes nothing to the internet at all and is free at personal scale. That is a stronger security position than any public address, ours included.
If your address changes but the internet can already reach you, dynamic DNS solves that for nothing, and so might a phone call to your ISP.
If you are prototyping and need a URL for an afternoon, ngrok is faster than anything else including us.
Buy an address when something on the other side needs an address rather than a name: a vendor allowlist, a corporate firewall, reverse DNS, a protocol that is not HTTP, or a game server whose players connect directly. That is the case we are built for, and if you are stuck behind CGNAT, this explains why nothing else you have tried worked.
Getting started
Create an account, add a machine, and copy the enrolment token. On the machine, run one command — on Linux that is curl -fsSL https://tunnelnet.io/install.sh | sudo bash -s -- <your-token>, with an equivalent for macOS and Windows. Enrolment takes about a minute: the installer generates a WireGuard key, asks us for addresses, writes the tunnel configuration and brings it up, then waits for both hubs to add your device.
After that, sudo tnet status tells you whether the tunnel is up and how much has crossed it, and sudo tnet ports allow tcp 443 opens a port. If you uninstall, use the uninstaller rather than deleting the config by hand — it releases the address back to the pool.
Create an account, or read the documentation first. Questions go to support@minakilabs.com and we reply within one business day on the consumer plans, or within 8 working hours on Business.