1cattunnel
v0.3.4
Published
1Cat Tunnel client with bundled Windows/Linux amd64 binaries
Readme
1cattunnel
Global npm wrapper for the 1Cat Tunnel client.
Version 0.3.4 connects to dx.1catai.com:50001 by default, uses TLS 1.3, masks first-run credential input with stars, embeds the project private CA, persists the dedicated per-node credential after first enrollment, and ships a Garble-protected Linux client plus protected npm scripts. The Windows client remains a Defender-compatible stripped Go binary.
Install
npm install -g 1cattunnelRun
1cattunnelThe package bundles Windows/Linux amd64 client binaries. It does not include the enrollment password.
On first run it creates a writable user config and the Go client wizard asks for either:
- a WebUI bootstrap token; or
- the enrollment password from the administrator.
The enrollment password is saved only until the first successful connection. It is then replaced by the dedicated node token. On Windows, choose Manual custom ports in the wizard to expose one or more custom TCP/UDP local ports.
Config path:
- Windows:
%APPDATA%\\1cat-tunnel\\client-windows.json - Linux:
~/.config/1cat-tunnel/client-linux.json
Linux clients also expose a loopback-only API for submitting blocked IPs to the server:
curl -u admin:YOUR_ADMIN_PASSWORD \
-H "Content-Type: application/json" \
-d '{"ip":"203.0.113.10","reason":"scan"}' \
http://127.0.0.1:51888/api/block-ipThe server validates the same WebUI administrator username/password before adding the IP to the persistent blocklist.
Use a custom config if needed:
1cattunnel -config ./client-linux.json