Threadway

Changelog

What has changed in the service. The client carries its own version, which threadway --version prints and the download page lists alongside its checksum.

Usage, billing and reporting

August 2026

  • Engagement reports. Any engagement can be exported as a single self-contained HTML file: the tunnels opened, every callback with its time and source address, and the scope you recorded. Nothing is loaded from the network, so it still opens as an email attachment later. Print it to PDF from your browser.
  • Usage against your plan. The billing page shows how much of each limit you are using, and suggests a larger plan only when one would actually give you room.
  • Clearer limits. Hitting a plan limit now tells you which limit, what your plan allows, and where to change it, instead of stopping at the refusal.
  • Cancelling keeps the period you paid for. Your plan stays active until the end of the period you have already paid for, then reverts.

Plans and pages

August 2026

  • Plan details on the home and pricing pages are read from the live plans, so the prices and limits shown are the ones actually charged and enforced.
  • Fixed plan limits being displayed as "unlimited" where the value meant the opposite.
  • Threadway is a hosted service. References to running it yourself have been removed from the site, and the terms and privacy policy updated to match.

Out-of-band capture

Earlier

  • DNS, HTTP, SMTP and LDAP interactions recorded against your account, with interactsh-compatible endpoints so the interactsh client and Nuclei work unchanged.
  • Engagements group tunnels and capture endpoints for one job.
  • Request inspector with replay and HAR export.
This page lists user-visible changes only. Security fixes are described here once deployed; if you believe you have found one, please read Security before posting about it.
Terms of Service · Privacy Policy · Acceptable Use · Report abuse