VPN & Proxy
Every request a script makes leaves from Ocalt’s own address. OUTBOUND sends a script’s traffic out through an exit you bring instead: your own VPN, or your own proxy. Ocalt does not hand out exits; it connects your script to yours, and only for as long as the script says so.
Your Own VPN
OUTBOUND VIA VPN takes a WireGuard config as text - the same file any WireGuard app imports, with an [Interface] holding your PrivateKey and Address, and a [Peer] holding the server’s PublicKey and Endpoint. Keep it in your namespace and read it, or build it in the script.
FILE READ "/root/vpn/home.conf" SET ?wg
AFTER OUTBOUND VIA VPN ?wg
AFTER FETCH "https://api.ipify.org" SET ?there
AFTER EMIT "seen as: " & ?there
AFTER OUTBOUND DIRECT
AFTER FETCH "https://api.ipify.org" SET ?here
AFTER EMIT " | and now: " & ?here
The tunnel runs for this script alone; no other script, and no other account, can use it. Before OUTBOUND VIA VPN returns, the tunnel has already carried a real request, so a script that gets past it knows its traffic is leaving through the VPN. It ends at OUTBOUND DIRECT, at OUTBOUND VIA PROXY, or when the script ends, and your private key is never left on disk. Configs exported by providers are accepted as they come: lines a WireGuard client does not use, such as Table, PostUp or comments, are ignored.
OUTBOUND VIA VPN raises an error you can catch, and the script keeps leaving from wherever it left before. Nothing goes out unprotected by surprise.FILE READ "/root/vpn/home.conf" SET ?wg
AFTER OUTBOUND VIA VPN ?wg OR CATCH ERROR SET ?err
AFTER EMIT "no VPN: " & ?err("message")
OUTBOUND sets execution state, the way HEADER does for the response. It takes effect from that statement onward and applies to every outbound call the script makes - FETCH, CURL, browser sessions, webhooks. Those verbs are unchanged: they read the state rather than taking an argument. OUTBOUND DIRECT puts it back.
PROXY written on the statement itself always wins over OUTBOUND. A script that names a proxy on the line in front of you means it, and ambient state should never quietly override something written explicitly.Your Own Proxy
OUTBOUND VIA PROXY takes any proxy you can reach - a proxy service, a scraping provider, a machine of your own somewhere else. Ocalt carries none of that traffic; it only points your requests at it.
OUTBOUND VIA PROXY "socks5h://user:pass@demo:demo@example.ocalt.com:3128"
AFTER FETCH "https://api.ipify.org" SET ?r
AFTER EMIT ?r
The scheme is required: socks5://, socks5h://, http:// or https://. Prefer socks5h, which asks the proxy to resolve the hostname rather than resolving it here.
What an Exit Cannot Reach
An exit carries your traffic to the internet. It is not a way into Ocalt: a proxy on a private or loopback address is refused, as is Ocalt’s own address, and private addresses stay out of reach through an exit exactly as they are for a script. An exit has no more reach than the account behind it.
Full Verb Reference
| Verb | Description |
|---|---|
OUTBOUND VIA VPN ?config | Every outbound call from here on leaves through your own WireGuard VPN; raises an error if the tunnel does not carry traffic |
OUTBOUND VIA PROXY "url" | Every outbound call from here on leaves through your own proxy |
OUTBOUND DIRECT | Back to leaving from Ocalt itself; ends a VPN |