Straw is a small, self-hosted HTTP/HTTPS egress proxy. Your application sends a request to Control, Control assigns it over NATS to an Egress worker, and the worker makes the outbound request.
flowchart LR
App["Application"] -->|REST or forward-proxy request| Control
Control -->|assignment over NATS| Egress["Egress worker"]
Egress -->|outbound HTTP/HTTPS| Dest["Destination"]
Dest -->|response| Egress
Egress -->|response frames| Control
Control -->|HTTP response, JSON, receipt, or tunnel bytes| App
One deployment is one trust boundary. Straw has no tenants, accounts, RBAC, billing, quotas, or analytics database. NATS is the only required backing service; optional JetStream, Redis, and object-storage profiles provide durable runtime configuration, multi-Control coordination, and large-body receipts respectively.
Requirements: Git, Docker with Compose v2, make, Bash, and curl.
git clone https://github.com/beremaran/straw-oss.git
cd straw-oss
make devThen send a request:
curl -sS \
-H 'Content-Type: application/json' \
-d '{"method":"GET","url":"https://example.com"}' \
http://localhost:8080/api/v1/requestsOr use Control as an HTTP/HTTPS forward proxy:
curl --proxy http://localhost:8080 https://example.comThe CLI and tagged SDKs expose the same per-request routing hints. For example:
straw request --url https://example.com --route-country AU --route-tag residential --sticky-session-id checkout-42The local stack contains exactly NATS, Control, and one Egress worker. It needs no credentials or provisioning.
- separate the application-facing API from the network that performs egress;
- scale outbound workers independently;
- preserve ordered and duplicate headers;
- bound request bodies, response bodies, and deadlines;
- apply the same routing rules, pool constraints, sticky-session behavior, and destination policy from REST, forward-proxy, and CONNECT ingress;
- optionally move large request and response bodies through verified expiring receipts;
- select any of 79 pinned
tls-clientv1.15.1 TLS/HTTP/2 fingerprint profiles without a runtime dependency ontls-clientorfhttp; - operate with Prometheus metrics, health endpoints, and JSON logs;
- deploy without an application database.
- Full documentation
- Quickstart
- Install a release
- Architecture
- Request API
- HTTP and HTTPS proxy ingress
- Configuration
- Deployment patterns
- Runtime administration
- Highly available Control
- Object storage and receipts
- Security
- Compatibility and supported versions
- Public components and provenance
- Support
- Governance
- Contributing
make check
make production-deploy-check
make docs-websiteSee CONTRIBUTING.md for setup and contribution conventions. The supported development stack is in
deploy/local; deploy/production is a security-conscious example to adapt to your environment.
Straw is pre-1.0. The REST request API and HTTP/HTTPS proxy ingress are the primary supported surfaces; custom-worker protocol packages are more likely to change between minor releases. See ROADMAP.md and CHANGELOG.md.
MIT © 2026 Berke Arslan. Adapted third-party profile data is covered by THIRD_PARTY_NOTICES.md.