VPN & Proxy

Every request a script makes leaves from Ocalt’s own address. OUTBOUND sends a script’s traffic out through an exit you bring instead: your own VPN, or your own proxy. Ocalt does not hand out exits; it connects your script to yours, and only for as long as the script says so.

Your Own VPN

OUTBOUND VIA VPN takes a WireGuard config as text - the same file any WireGuard app imports, with an [Interface] holding your PrivateKey and Address, and a [Peer] holding the server’s PublicKey and Endpoint. Keep it in your namespace and read it, or build it in the script.

Through Your VPN, and Back Again
FILE READ "/root/vpn/home.conf" SET ?wg
AFTER OUTBOUND VIA VPN ?wg
AFTER FETCH "https://api.ipify.org" SET ?there
AFTER EMIT "seen as: " & ?there
AFTER OUTBOUND DIRECT
AFTER FETCH "https://api.ipify.org" SET ?here
AFTER EMIT " | and now: " & ?here

The tunnel runs for this script alone; no other script, and no other account, can use it. Before OUTBOUND VIA VPN returns, the tunnel has already carried a real request, so a script that gets past it knows its traffic is leaving through the VPN. It ends at OUTBOUND DIRECT, at OUTBOUND VIA PROXY, or when the script ends, and your private key is never left on disk. Configs exported by providers are accepted as they come: lines a WireGuard client does not use, such as Table, PostUp or comments, are ignored.

If the tunnel does not come up - a wrong key, an endpoint that cannot be reached, a provider that refuses the handshake - OUTBOUND VIA VPN raises an error you can catch, and the script keeps leaving from wherever it left before. Nothing goes out unprotected by surprise.
When the VPN Does Not Connect
FILE READ "/root/vpn/home.conf" SET ?wg
AFTER OUTBOUND VIA VPN ?wg OR CATCH ERROR SET ?err
AFTER EMIT "no VPN: " & ?err("message")

OUTBOUND sets execution state, the way HEADER does for the response. It takes effect from that statement onward and applies to every outbound call the script makes - FETCH, CURL, browser sessions, webhooks. Those verbs are unchanged: they read the state rather than taking an argument. OUTBOUND DIRECT puts it back.

A PROXY written on the statement itself always wins over OUTBOUND. A script that names a proxy on the line in front of you means it, and ambient state should never quietly override something written explicitly.

Your Own Proxy

OUTBOUND VIA PROXY takes any proxy you can reach - a proxy service, a scraping provider, a machine of your own somewhere else. Ocalt carries none of that traffic; it only points your requests at it.

Your Own Proxy
OUTBOUND VIA PROXY "socks5h://user:pass@demo:demo@example.ocalt.com:3128"
AFTER FETCH "https://api.ipify.org" SET ?r
AFTER EMIT ?r

The scheme is required: socks5://, socks5h://, http:// or https://. Prefer socks5h, which asks the proxy to resolve the hostname rather than resolving it here.

What an Exit Cannot Reach

An exit carries your traffic to the internet. It is not a way into Ocalt: a proxy on a private or loopback address is refused, as is Ocalt’s own address, and private addresses stay out of reach through an exit exactly as they are for a script. An exit has no more reach than the account behind it.

Full Verb Reference

Verb Description
OUTBOUND VIA VPN ?configEvery outbound call from here on leaves through your own WireGuard VPN; raises an error if the tunnel does not carry traffic
OUTBOUND VIA PROXY "url"Every outbound call from here on leaves through your own proxy
OUTBOUND DIRECTBack to leaving from Ocalt itself; ends a VPN