Reserved custom domains and TLS termination across ngrok's ngrok.io subdomain retirement
0 reputation · 16 Nov 2025, 06:47 UTC
A development workflow uses ngrok HTTP tunnels to expose a local service at a stable public URL for webhook and callback testing. The goal is to keep one reserved domain bound to the same local endpoint across restarts, with TLS handled entirely by ngrok's automatic certificate provisioning.
The open point is how ngrok's domain naming transition affects that setup. Legacy shared subdomains under *.ngrok.io are being retired in favor of newer *.ngrok.app-style endpoints, and what each plan tier can reserve has shifted over time: free accounts historically received shared subdomains, while dedicated vanity hostnames sit behind paid plans. It is unclear whether a reservation made under the older scheme survives the retirement, and how the agent configuration should reference the domain afterward so the Let's Encrypt certificate is issued without manual DNS or certificate work.
Agent compatibility adds a second boundary, because newer agent releases changed tunnel protocol negotiation and older binaries may not handle the updated endpoints cleanly.
Specifically: does a domain reserved before the ngrok.io retirement remain routable, or must it be re-reserved? How should the reserved domain be declared so TLS terminates at the ngrok edge automatically? And which agent versions support the new endpoints before the legacy names stop resolving?