# How to Access ReClip from an External Network: Flask Host Binding Guide

> Learn how to access ReClip from an external network by setting the HOST environment variable to 0.0.0.0. This Flask host binding guide ensures external access to your ReClip instance.

- Repository: [Avery Gan/reclip](https://github.com/averygan/reclip)
- Tags: how-to-guide
- Published: 2026-09-05

---

**To access ReClip from an external network, set the `HOST` environment variable to `0.0.0.0` before starting the Flask server, ensuring port 8899 is open in your firewall.**

The `averygan/reclip` repository runs a Flask web application that defaults to localhost-only access for security. By default, the server binds to `127.0.0.1`, which prevents remote machines from reaching the service. Understanding how to modify this binding configuration is essential for deploying ReClip in networked environments or Docker containers.

## Understanding ReClip's Default Network Binding

In [`app.py`](https://github.com/averygan/reclip/blob/main/app.py), the Flask application reads its host configuration from environment variables with a secure default. The specific lines that control network accessibility are:

```python
host = os.environ.get("HOST", "127.0.0.1")

```

This implementation at **app.py#L9-L10** means that without explicit configuration, the server only accepts connections from the local machine. The `PORT` variable similarly defaults to `8899` but can be overridden to match your network requirements.

Binding to `127.0.0.1` (localhost) is a security feature that prevents accidental exposure during development. To make ReClip accessible from other devices on your network or the internet, you must override this default by setting `HOST=0.0.0.0`, which instructs Flask to listen on all available network interfaces.

## Method 1: Exposing ReClip via Environment Variables (Local Python)

When running ReClip directly with Python, you can expose it externally by exporting the correct environment variables before executing the startup script.

### Configuration Steps

1. Export the `HOST` variable set to `0.0.0.0` to enable all interfaces
2. Optionally specify a custom `PORT` (default is 8899)
3. Run the [`reclip.sh`](https://github.com/averygan/reclip/blob/main/reclip.sh) convenience script to start the server

```bash

# Example 1 – Run locally and expose to the network

export HOST=0.0.0.0          # bind to all interfaces

export PORT=8899            # optional, defaults to 8899

./reclip.sh                 # starts the Flask app

# Access from another machine:

#   http://<your-host-ip>:8899

```

The [`reclip.sh`](https://github.com/averygan/reclip/blob/main/reclip.sh) script automatically picks up these environment variables and launches the application with the specified binding configuration. Ensure the chosen port is not blocked by your operating system's firewall before attempting external connections.

## Method 2: Docker Deployment with External Access

Containerized deployments require both the Docker port mapping and the Flask host configuration to work together for external accessibility.

### Docker Run Command

Use the `-p` flag to map the container port to your host, and the `-e` flags to set the internal host binding:

```bash

# Example 2 – Docker run with explicit host binding

docker run -d \
  -p 8899:8899 \
  -e HOST=0.0.0.0 \
  -e PORT=8899 \
  averygan/reclip

# Visit http://<docker-host-ip>:8899 from any device on the same network

```

The `-p 8899:8899` mapping exposes the container's port to the host machine, while `HOST=0.0.0.0` ensures Flask listens on the container's external interface rather than just localhost within the container.

### Docker Compose Configuration

When using [`docker-compose.yml`](https://github.com/averygan/reclip/blob/main/docker-compose.yml), add the `HOST` environment variable to ensure external reachability:

```yaml

# Example 3 – docker-compose.yml snippet (add or verify)

services:
  reclip:
    build: .
    ports:
      - "8899:8899"
    environment:
      - HOST=0.0.0.0   # makes Flask listen on all interfaces

      - PORT=8899

```

After updating the configuration, run `docker compose up -d` to start the service. Docker automatically forwards the mapped port, and the `HOST` environment variable ensures the Flask instance accepts connections from outside the container.

## Network Security Considerations

Exposing ReClip to external networks requires attention to security infrastructure beyond the application configuration.

**Firewall and Security Groups** – Open port 8899 (or your custom port) on your host operating system, cloud provider security groups, or network router. Without this step, connection attempts will be blocked before reaching the Flask application.

**NAT and Port Forwarding** – When the host machine sits behind a residential or corporate router, configure port forwarding to direct external traffic on port 8899 to the internal IP address of your ReClip host.

**TLS and Reverse Proxies** – For production environments, avoid exposing Flask directly to the internet. Instead, deploy a reverse proxy such as **nginx**, **Caddy**, or **Traefik** in front of ReClip. This architecture provides HTTPS encryption, load balancing, and optional authentication mechanisms that the default Flask development server does not include.

## Summary

- **Default security**: ReClip binds to `127.0.0.1` via the `HOST` environment variable in [`app.py`](https://github.com/averygan/reclip/blob/main/app.py) to prevent unauthorized remote access during development
- **External access**: Set `HOST=0.0.0.0` to enable listening on all network interfaces before starting the server
- **Script support**: The [`reclip.sh`](https://github.com/averygan/reclip/blob/main/reclip.sh) startup script automatically uses exported environment variables for configuration
- **Docker requirements**: Both port mapping (`-p 8899:8899`) and host binding (`-e HOST=0.0.0.0`) are necessary for containerized external access
- **Production hardening**: Use a reverse proxy with TLS termination rather than direct external exposure of the Flask development server

## Frequently Asked Questions

### Why does ReClip default to localhost only?

ReClip defaults to `127.0.0.1` as a security measure implemented in [`app.py`](https://github.com/averygan/reclip/blob/main/app.py) to prevent accidental exposure of the development server to untrusted networks. This default requires explicit action (setting `HOST=0.0.0.0`) to enable external access, ensuring administrators consciously choose to open the service.

### What port does ReClip use by default?

ReClip uses port **8899** by default. This can be modified by setting the `PORT` environment variable to any available port number before starting the application. Both the [`reclip.sh`](https://github.com/averygan/reclip/blob/main/reclip.sh) script and Docker configurations respect this variable when present.

### Is it safe to expose ReClip directly to the internet?

Exposing ReClip directly to the internet is **not recommended for production use**. The underlying Flask development server is not optimized for production traffic and lacks built-in security features like HTTPS. Instead, place a reverse proxy (nginx, Caddy, or Traefik) in front of ReClip to handle TLS encryption, connection pooling, and access control.

### How do I check if the port is accessible externally?

Test external accessibility using `telnet` or `curl` from a remote machine: `telnet <your-server-ip> 8899`. If the connection times out, verify that the `HOST` environment variable is set to `0.0.0.0`, check local firewall rules with `sudo iptables -L` or `ufw status`, and confirm any router port forwarding rules are active.