Home › Config generator

Build your proxy config

Tell it where your service lives, then copy a ready-to-run command or manifest. The proxy terminates TLS for your *.gotls.de hosts and asks goTLS's signer for each handshake signature. Your traffic and your keys stay put.

Where the proxy forwards plaintext after terminating TLS (your ROUTE_0_UPSTREAM).

Use :443 so the URL needs no port. Ports below 1024 need a binding capability. The config below adds it automatically.

Which TLS server names this route terminates.

The IP your proxy listens on. Used to build the magic URL to open.

Advanced

The keyless signer host:port. Leave as-is unless you run your own.


      

Start the proxy first, then open your service over HTTPS. The certificate is trusted, so browsers, curl and webhooks all connect with no warning. And the private key never touches your machine.