Skip to content

How it works

When you install the Dataplicity agent on a Linux device, it establishes and maintains an outbound connection to Dataplicity. That connection supports more than Remote Shell: on qualified releases, your product application can publish selected values through an agent-local broker for OEM and customer product pages.

When you connect to remote shell or reach a web service through a Wormhole URL, traffic is routed between the browser and device through Dataplicity.

Outbound connections

The agent initiates the Dataplicity connection from the device. The Dataplicity access path does not require an inbound internet route to Remote Shell, RDP, or a device-hosted web service. This means:

  • No port forwarding on customer routers
  • No inbound firewall exception for Dataplicity access
  • Restricted networks can allowlist the documented outbound destinations
  • Portable devices reconnect automatically when they move between networks

Traffic is routed over encrypted WebSocket connections. Availability still depends on the device's network path, DNS, time configuration, and permitted outbound traffic.

Components

ComponentRole
AgentSoftware installed on each Linux device. Maintains the outbound connection, device identity, and remote access. On installs that include the optional supervisor, it also runs Class Software and the local stream broker.
IoT RouterDataplicity service that routes connections between your browser and devices.
DashboardWeb interface for device list, remote shell, fleet management, logs, and monitors.
Device ClassProduct definition for compatible software, streams, actions, settings, and customer layout.
Customer PortalBranded, customer-separated application for assigned products and locations.
Local brokerLoopback boundary through which a compatible product process publishes class streams without a cloud API key.
WormholePersistent outbound tunnel to a web service running on the device.
File retrievalResilient transfer for support artifacts.

What this means in practice

You can access devices when the agent has a viable, authorised route to Dataplicity. NAT and dynamic public addressing do not require a per-device inbound rule because the agent connects outward.

The OEM workspace and Customer Portal use different authorisation boundaries. A portal user does not gain OEM Remote Shell, fleet-wide logs, or software rollout access.

Dataplicity hosts these SaaS surfaces and the device-operating connection. You keep the hardware, Linux, product application, local safety behaviour, customer contract, billing, and physical service lifecycle. See Customer lifecycle and automation for the complete boundary.