| Component | Runs where | Role |
|---|---|---|
| TunnelSats package | Its own StartOS container | Actions (Buy, Renew, Reset Bandwidth, Import, Export, Configure, Connect Wallet), background sync daemon, web dashboard |
| Lightning node package (LND, Core Lightning, Eclair) | Its own StartOS container | Pays invoices through its Pay Invoice action; runs the WireGuard tunnel wg0 and its routing when the clearnet-vpn task is accepted |
| TunnelSats public API v1 | https://tunnelsats.com/api/public/v1 | Servers, orders, payment status, config claim, status sync, inbound ping test |
| NWC wallet (optional) | Your wallet, over Nostr relays | Pays renewal invoices automatically when Connect Wallet is set up |
wgPublicKey. Orders created with wgPublicKey are provisioned for that key only; the server never generates or stores a private key for them, and /claim returns the tunnel parameters with fullConfig: null. The package assembles the .conf locally and rejects a claim whose peer key differs from its own.wg0, listens for inbound peers on the tunnel address and announces <server>:<vpnPort>. Policy routing (table 51820) sends clearnet peer traffic through wg0 while it is up; Tor traffic keeps using the container bridge.wg0.https://tunnelsats.com/api/public/v1. Purchase endpoints need no authentication.| Endpoint | When | Data sent |
|---|---|---|
GET /servers | Buy action opens; dashboard region cards (cached 60 s, retried after 15 s on failure) | Nothing node-specific |
POST /subscription/create (docs) | Buy Subscription | serverId, duration, wgPublicKey |
GET /subscription/{paymentHash} (docs) | Settlement polling for Buy / Renew / Reset | Payment hash |
POST /subscription/claim (docs) | After a Buy settles | paymentHash, wgPublicKey (optional referral code) |
POST /subscription/renew | Renew Subscription, NWC auto-renew | serverId, duration, wgPublicKey |
POST /subscription/bandwidth-reset (guide) | Reset Bandwidth (usage at 70% or more) | wgPublicKey, serverId |
POST /subscription/status | Background sync | wgPublicKey; receives expiry, bandwidth used, monthly limit, paid reset count |
POST /ping/test | Only when the user presses Check inbound reachability (max 2 per 60 s) | Node public key, server address and port from the config |
.onion); then it goes through the StartOS Tor SOCKS5 proxy and fails if Tor is unreachable..conf in a masked, copyable field.lookup_invoice) whether it is already settled before paying. After 3 failed attempts (or insufficient budget/balance) automatic retries stop for that period and the user pays through a Pay Invoice task.| Trigger | What the user sees |
|---|---|
| Expiry in 7 days or less | StartOS notification; Renew Subscription task (important) only if NWC auto-renew is not active |
| Expiry in 3 days or less | Notification; task raised or updated only if NWC auto-renew is not active |
| Expired | Renew Subscription task + notification (also with NWC connected); the server disables the tunnel until renewed |
| No subscription for the configured key | Import Subscription task + notification |
| NWC auto-renew succeeded | Notification with amount paid and new expiry |
| NWC fallback | Pay Invoice task on the node (+ Connect Wallet task if the budget is short) + notification |
0.21.3-beta:10, Core Lightning 26.6.8:3 or Eclair 0.14.3:3 (or newer). While the tunnel is configured, those builds keep blackhole default metric 4294967295 in table 51820 for IPv4 and IPv6, so if wg0 goes down, is removed or loses its server, clearnet traffic is dropped instead of using the home connection. QA verified no leak window at boot and none when the endpoint's DNS fails at start (the node daemon waits for the tunnel). Verify on the node: wg show wg0, ip rule (lookup 51820), ip route show table 51820 (default dev wg0 plus the blackhole route), ip -6 route show table 51820 (blackhole route), curl -4 -s https://ifconfig.me (TunnelSats IPv4).AllowedIPs include ::/0 (TunnelSats configs do) and block it otherwise. Allow IPv6 Endpoint only lets TunnelSats hand the node an IPv6 server endpoint to announce.