For software vendors with customer-managed deployments
Reach the service you cannot get to—with the customer's approval.
Thirp lets a support engineer connect to a named private service in a customer environment. The customer grants a bounded window, can end it immediately, and keeps an audit of who connected. No inbound port on the customer's network required. No copy of the application payload in Thirp.
Request a pilot See how it works
-
A named Service
Publish
criticalservice.api, not the subnet. Knowing the name is not permission. -
A real approval
A customer Approver says yes, no, or stop. Stop ends the live connection.
-
A durable record
Record who, which Service, when, and how long—not the session payloads.
The scene you already know
The ticket is real. The deployment is behind the customer's firewall. A VPN into the whole site is a non-starter, and screen sharing does not let the engineer use the tools that can diagnose the real service. You do not need the customer's network. You need one service, for a bounded time, with the customer holding the switch.
Example: a transaction service behind two DMZs
You ship software that talks to a transaction process on an application server in the customer's data center—sometimes a database listener on the same host, two DMZs in from the internet. Overnight the batch window slips. Your engineer needs the admin or query port on that one process. Not a desktop. Not the subnet.
Their rule is: submit a firewall ticket. You file it. They ask for your ingress address. You do not have a stable one, or you do and it still waits for tomorrow's change window. The ticket comes back "use the VPN," which is a non-starter because it will not route to that DMZ, or it comes back approved a day later for a jump host you cannot use with the tools that can actually see the service.
The Service is up. You still cannot get to it. Thirp can.
Four steps
- Enroll
thirp-agentin the customer Environment; it connects outbound. - Publish the named Service the vendor may support.
- Request access; the customer Approver grants a bounded window.
- Connect with the Thirp CLI; expiry or revocation closes the connection.
Design partners
Thirp is inviting a small number of vendors who already support software or appliances in customer-controlled environments. Admission is selective. A request is a conversation, not a signup and not a purchase.