System operational

Your traffic exits via
Starlink residential IP

KosmosBridge routes your WireGuard tunnel through a satellite uplink — giving operators a clean, non-datacenter residential exit that bypasses CGNAT without touching a VPN provider.

Get operator access Stripe billing · $0.02/MB · no minimums
packet-path — live routing topology
# Operator traffic flows through three hops to Starlink egress
 
ingress endpoint 62.238.105.232:51820 # Hetzner VPS, Helsinki
protocol transport WireGuard UDP
tunnel back-link wg-back-a 10.200.0.1 → 10.200.0.2
egress-host device Raspberry Pi 5 (craigpi)
exit-medium uplink Starlink residential
exit-ip observed 98.97.x.x # dynamic · non-datacenter · ARIN residential
 
# Full path
Operator ──UDP──► Hetzner wg-operators ──wg-back-a──► craigpi ──► Starlink → internet
 
operator-subnet 10.50.0.0/24 # isolated per-operator assignment
billing rx+tx bytes → Stripe metered → $0.02/MB
98.97.x.x
Starlink residential exit IP
$0.02
Per megabyte transferred
UDP 51820
WireGuard ingress port
60s
Billing poll interval
Helsinki
Relay location (Hetzner)
Monthly
Billing cycle via Stripe
01

Get an API key

Complete Stripe checkout. You receive an API key tied to your billing account. No ongoing subscription — you pay per MB consumed.

02

Generate a WireGuard keypair

Run wg genkey | tee privkey | wg pubkey > pubkey on your system. Keep the private key local — only your public key leaves your machine.

03

Call POST /provision

POST your public key with your API key as the bearer token. The API returns a complete wg-quick config file. No back-and-forth.

04

Bring the tunnel up

Run wg-quick up client.conf. Traffic exits via Starlink. Verify with curl ipinfo.io/ip — you should see a residential 98.97.x.x address.

$0.02
per megabyte · rx + tx combined
  • No monthly minimum
  • No setup fee
  • Metered billing via Stripe — invoiced monthly
  • Usage counter survives tunnel restarts
  • One config per API key
  • Revoke anytime via API
Get started
Ingress endpoint 62.238.105.232:51820 (UDP)
Protocol WireGuard (kernel module or userspace)
Operator subnet 10.50.0.0/24 — isolated assignment per operator
Exit IP range 98.97.0.0/16 (Starlink, dynamic, ARIN residential)
Back-tunnel wg-back-a, persistent keepalive 25s, Hetzner → craigpi
Billing unit Bytes (rx + tx), converted to MB, reported to Stripe every 60s
Meter event agora_transport_mb · price_1U3So2HI4Bbp4yAzPP6mjWcO
Provisioning API POST https://transport.eclesia.app/provision
Auth Authorization: Bearer <api-key>
Config format wg-quick compatible INI — bring up with wg-quick up client.conf

Ready to route via Starlink?

Complete Stripe checkout to receive your API key. Takes under two minutes from checkout to tunnel up.

Get operator access — $0.02/MB