Relay left public checkout on 2026-09-29: it only ever connected the Pulse Mobile app, which retires on 31 March 2027, and existing Relay subscribers now carry Pro entitlements. The app still sold it. Every Community install saw a "Get alerts on your phone ... Available with Relay and Pro plans" upgrade panel on Alerts destinations, the plan screen offered a Relay card with "Remote web access via Relay", and the settings section was called Remote Access although Relay never reached the web UI. The Alerts push panel now renders only on instances that have the relay feature, with no upsell. The settings section, nav, header and locale catalogs say Pulse Mobile and carry the retirement date. Community sees only the Pro comparison card and Relay-tier licenses see none; gated mobile features name Pro as their minimum plan. The relay feature is labelled "Pulse Relay (Mobile Connection)" in the catalog, plan copy no longer claims remote web access, the backend pairing diagnostics point at Settings > Pulse Mobile, and the user docs, including PRIVACY.md, state that Relay does not provide remote web UI access.
5.6 KiB
Relay / Pulse Mobile
Pulse Mobile is being retired on 31 March 2027. Paired phones keep working until then. Relay is no longer sold as a plan; existing Relay subscribers have Pro features at their current price. For alerts on your phone afterwards, add an ntfy, Gotify, or Pushover destination under Alerts, and reach the Pulse web UI away from home through your own VPN or tunnel.
Pulse Relay is the end-to-end encrypted connection between a Pulse instance and paired Pulse Mobile devices. It lets the app reach your server without exposing it to the public internet. It does not provide remote access to the Pulse web UI.
Supported Pulse Mobile clients pair from Settings → Pulse Mobile using a QR code or deep link and connect through Pulse Relay over an end-to-end encrypted channel.
How It Works
┌──────────┐ ┌──────────────┐ ┌──────────┐
│ Pulse │◄──E2E──►│ Relay │◄──WSS──►│ Pulse │
│ Mobile │ ECDH │ Server │ │ Server │
└──────────┘ └──────────────┘ └──────────┘
- Your Pulse server maintains a persistent WebSocket connection to the relay server.
- A mobile client connects to the relay server and authenticates.
- An ECDH key exchange creates a per-channel encryption key.
- Tunneled remote-access traffic is encrypted end-to-end — the relay server never sees plaintext data.
Quick Start
- Go to Settings → Pulse Mobile.
- Toggle relay On.
- Use the QR Code or Deep Link to pair a supported Pulse Mobile client.
- Your paired mobile client connects through relay.
Requirements
- Relay, Pro, legacy Pro+, or Cloud license — relay is gated by the
relayfeature key. - Outbound WebSocket — Pulse must be able to reach
relay.pulserelay.pro(port 443). - No inbound ports — you do not need to open any ports on your firewall.
Security
Relay was designed with a zero-trust model:
| Property | Detail |
|---|---|
| Encryption | End-to-end ECDH key exchange per channel |
| Plaintext | Relay server never sees your monitoring data |
| Authentication | Per-session mobile authentication |
| Back-pressure | Data limiters prevent channel flooding |
| License-gated | Requires an active Relay-or-higher license |
| Configurable | Can be enabled/disabled at any time via Settings |
| Audit | Relay connection events are logged to the audit trail |
Configuration
UI
Settings → Pulse Mobile — toggle on/off, view QR code, and manage relay pairing sessions.
Environment Variables
For headless / container deployments, two env vars override the persisted
relay.enc values at load time. Unset leaves the file value untouched.
| Variable | Description | Default |
|---|---|---|
PULSE_RELAY_ENABLED |
Enable/disable relay (true/false/yes/no/1/0). Unrecognized values are ignored. |
(unset) |
PULSE_RELAY_SERVER |
Override relay server URL. Must be ws:// or wss://. Invalid values are logged and ignored. |
wss://relay.pulserelay.pro/ws/instance |
Env vars take precedence over the file at load. Saving from the UI after an env override is active persists the env-effective state to disk, so clearing the env var alone will not revert the change — disable in the UI too.
Storage
Relay configuration is stored encrypted in relay.enc in the Pulse data directory.
API Reference
| Method | Endpoint | Scope | Description |
|---|---|---|---|
GET |
/api/settings/relay |
settings:read |
Get relay status and config |
PUT |
/api/settings/relay |
settings:write |
Update relay settings |
POST |
/api/onboarding/qr |
settings:read |
Generate mobile onboarding QR code |
POST |
/api/onboarding/deep-link |
settings:read |
Generate mobile deep link |
Pulse Mobile Pairing
iOS / Android
- Pulse Mobile is in early access. Relay and Pro customers get install links from the authenticated download page.
- Open Pulse Mobile and tap Connect to Server.
- Scan the QR code from Settings → Pulse Mobile in your Pulse web UI.
- The app connects via the relay for push notifications and secure Open Pulse handoff.
Multiple Servers
Pulse Mobile can pair with multiple Pulse instances. Each pairing has its own encrypted channel.
Troubleshooting
Relay showing "Disconnected"
- Confirm your Relay, Pro, grandfathered Pro+, or Cloud license is active (Settings → Plans & Billing).
- Verify the Pulse server can reach the relay server:
curl -s https://relay.pulserelay.pro/healthz - Check Pulse logs for relay errors:
journalctl -u pulse | grep -i relay # or docker logs pulse | grep -i relay
Pulse Mobile can't connect
- Verify relay is enabled in Settings → Pulse Mobile.
- Confirm your mobile account has beta access.
- Re-scan the QR code — sessions can expire.
- Ensure your mobile device has internet access.
Open Pulse handoff not loading
- Check the relay connection status in Settings → Pulse Mobile.
- Look for WebSocket reconnection messages in Pulse logs.
- Restart Pulse Mobile.
See Also
- Configuration Guide — environment variables
- Security — relay security details
- Plans & Entitlements — feature availability by plan