DocumentationNetwork & HTTPS

Network & HTTPS

Test your application on another device on the same network. Dwell mirrors local routes to the LAN; check reachability and certificate trust on the actual client.

When do I need LAN?

Use LAN for previews on a phone, tablet or another development machine. You need a working Dwell project, Docker and a trusted shared network.

  • .localhost is local to your machine; managed application routes are offered to other devices as .local.
  • Dwell creates no internet tunnel or public hosting address.
  • LAN sharing has no authentication of its own. Reachable devices can access shared routes.

Open the application on LAN

Enable sharing from the project directory and open the printed .local address on the second device. A displayed QR code can help open it; it does not replace checking on the client.

Share the application on LANbash
dwell up --lan

For example, http://my-project.localhost/api becomes http://my-project.local/api. The URL path is preserved; subdomains are mirrored too. Names are advertised through mDNS. Custom domains with other suffixes cannot be mirrored automatically.

The setting persists: a later dwell up may share again. To disable LAN sharing persistently for this project, use:

Disable LAN sharingbash
dwell up --no-lan

dwell down stops the project but retains the saved LAN setting. Check current status with dwell ps instead of assuming an earlier URL is still shared.

Share tools deliberately

Mailpit and phpMyAdmin stay local by default. Share them deliberately only when those services are enabled and all reachable devices are trusted.

Share the application and tools on LANbash
dwell up --lan --lan-tools

This also exposes tool routes such as http://tools.my-project.local/mp/ and /pma/. They can make emails or database access reachable. To keep tools local again while continuing to share the application:

Withdraw tool sharingbash
dwell up --lan --no-lan-tools

Choose the right interface

Dwell selects a suitable private IPv4 address. Multiple networks or VPNs may make the choice ambiguous. Explicitly select the interface or IPv4 address on your shared network in that case.

Select the LAN address explicitlybash
dwell up --lan --lan-interface 192.168.1.42

Replace 192.168.1.42 with your machine’s actual LAN IPv4 address. All running projects on the shared LAN gateway must agree on an explicitly selected interface. LAN HTTP uses port 80; optional HTTPS uses port 443.

Optional HTTPS

HTTPS is optional and depends on available mkcert, certificate generation and free gateway ports. Install mkcert using its official instructions and start Dwell again; it attempts to prepare matching local certificates. Check the output before using HTTPS.

Official mkcert instructions ↗

The second device must trust the certificate issuer. Installing trust on your development machine does not automatically extend it to your phone. Transfer only the public CA certificate for this trust, never the private CA key. Follow mkcert’s client instructions.

Locally, the gateway redirects HTTP to its HTTPS port when HTTPS is active; normal project links and access still show HTTP addresses. On LAN, HTTP remains available without automatic redirection. Use the printed HTTPS address there when HTTPS is active. If LAN HTTPS fails, Dwell can fall back to HTTP; check the protocol you are using.

When LAN is unreachable

Local startup and LAN reachability are separate. Check the reported LAN status first:

Inspect local and LAN statusbash
dwell ps

  • Host and client must share a reachable network; check the selected IPv4 address and interface.
  • The client needs mDNS support for .local. A name conflict can withdraw the affected project from sharing.
  • Check firewall rules for mDNS (UDP 5353), HTTP (TCP 80) and HTTPS (TCP 443) when applicable.
  • VPN routes and Wi-Fi client isolation can separate devices; test on the relevant shared network.
  • If only HTTPS is affected, check client certificate trust and whether the printed HTTPS address is active.

LAN is best effort: up can succeed locally even when mDNS, client resolution or the LAN gateway fails. Dwell reports LAN failures separately. A working local application does not prove reachability on the second device.

Security & limits

Use sharing deliberately on a trusted local network. HTTPS encrypts transport but adds no Dwell LAN authentication. You own any application login. Tool sharing broadens what is reachable; explicitly disable tools and LAN again as needed.

Next steps

The routing guide explains the underlying URLs. The product page covers the LAN concept and its uses.

Technical reference