Install the client with the one-line installer (the server is curl -fsSL https://seikan.okonomi.cloud/server/install.sh | sudo bash on your public host — see the install guide):

# 0. install the client (no root needed)
curl -fsSL https://seikan.okonomi.cloud/client/install.sh | bash

# 1. enrol this machine (saved to ~/.config/seikan/config.json).
#    Prints a confirmation code and waits; an administrator approves it in the
#    admin UI -> Requests, checking the code matches. Nothing to copy by hand.
seikan init --server admin.example.com
#    (already been handed a client key? use it instead:
#     seikan init --server admin.example.com --api-key sk_...)

# 2. expose local :3000 on an HTTPS domain (DNS for app.example.com must point at the server)
seikan add app.example.com 3000
seikan start
#    -> https://app.example.com is now live, served by a background service that
#       survives logout and restarts on failure

# 3. or expose a local TCP service on an auto-assigned public port
seikan add --tcp 5432 --name postgres
#    -> added to the running service straight away; no restart to do yourself

# 4. or relay a local service privately to just one other client — no public
#    port at all, e.g. reaching a database from another box without exposing it
seikan add --peer --name pgdb 5432
#    -> prints a one-time token + a `seikan forward` command; hand that to
#       whatever should reach it (see the client reference for the full flow)

Check on it, and take it away again:

seikan list             # every tunnel with its public endpoint, online and cert status
seikan status           # is the background service running?
seikan logs -f          # follow what it's doing
seikan remove app.example.com   # stop serving it and delete the frontend

For a one-off tunnel you don't want to keep, skip add/start entirely and run seikan serve app.example.com 3000 — one tunnel in the foreground, gone when you Ctrl-C.