Ultra-low latency
Anycast routing sends every client to its nearest relay for sub-40ms median hops — critical for teleop and live conversation.
Nothing proprietary to install. If your app accepts ICE servers it works with zTurn, and it will still work with whatever you move to next.
Anycast routing sends every client to its nearest relay for sub-40ms median hops — critical for teleop and live conversation.
Live capacity across 8 regions on 4 continents, with more coming. Pick exactly where you need relays — from the US to the Middle East and APAC.
TLS/DTLS everywhere, time-limited credentials, and full RFC 5766/8656 compliance. Your media never sits in the clear.
Pay only for the TB you relay. Volume discounts kick in automatically — from $10/TB down to $5/TB (or less) for large workloads.
Standard STUN/TURN URIs work with any WebRTC stack — libwebrtc, Pion, aiortc, Janus, mediasoup, LiveKit, and more.
Live dashboards for bandwidth, session counts, and per-region health — so you always know what's happening.
If your users connect from networks you don't control, some share of their sessions needs a relay. That share is the part that fails silently without one.
| STUN | stun:relay.ngturn.io:3478 — free public address discovery. |
|---|---|
| TURN over UDP | turn:relay.ngturn.io:3478 — the fastest relay path when UDP is allowed. |
| TURN over TCP | turn:relay.ngturn.io:80?transport=tcp — for networks that block UDP outright. |
| TURN over TLS | turns:relay.ngturn.io:443?transport=tcp — indistinguishable from HTTPS to a proxy. |
| TCP relay allocations | RFC 6062, for TCP connections between peers. |
| IPv4 and IPv6 | Relays listen on both where the location supports it. |
| Static credentials | A username and password for local testing. Rotate them whenever you like. |
|---|---|
| Time-limited credentials | Your backend signs short-lived usernames with a shared secret, so a leak expires by itself. |
| Media stays encrypted | WebRTC encrypts with DTLS-SRTP before a packet reaches a relay. We forward ciphertext. |
| Private address protection | Relays refuse to forward to private and link-local ranges, which is what turns an open relay into an SSRF hole. |
| Per-account limits | Traffic caps and instant credential revocation if a secret leaks. |
| Nearest-relay routing | One hostname resolves to the closest open location for each client. |
|---|---|
| Pinned regions | Use a regional hostname when data has to stay in one region. |
| Usage reporting | Relayed traffic by day and month, per credential. |
| Status and incidents | Location status and incident updates by email. |
The whole service on one card. Standard TURN, so it works with browsers, libwebrtc, Pion, mediasoup, LiveKit, Janus and Jitsi without an SDK.
| Protocols | STUN and TURN (RFC 8656) over UDP, TCP and TLS |
|---|---|
| Ports | 3478 for UDP and TCP, 80 for TCP, 443 for TLS through strict firewalls |
| Credentials | Static pair for tests; time-limited credentials from a shared secret for production |
| Routing | One hostname that resolves to the nearest open relay |
| Usage | Relayed traffic by day and month, per credential |
| Billing | Per TB of relayed traffic per month; STUN is free and never counts |
| First month | 30 days free, starting the day your credentials arrive, after a card check |
| Cancelling | One click in your account, any time |
Rates start at $10 per TB and fall with volume.Work out yours →
Pick your monthly TB and the rate is on screen before you give us anything.