docker container port shows exactly which host address and port Docker published for a container, with no guesswork. You will also query one private port and protocol when you need a precise answer. The command is read-only: it does not start, stop, restart or reconfigure a container. Allow about five minutes if you already know the container name.
You need the Docker CLI and access to the Docker daemon. The examples were checked with Docker CE CLI 5:29.8.1-1~ubuntu.24.04~noble, which reports client version 29.8.1. Exact host ports will differ on other machines.
Start with the normal container list. The PORTS column gives you a useful overview and the NAMES column gives you a value to pass to the next command:
$ docker ps --format 'table {{.Names}}\t{{.Ports}}'
NAMES PORTS
web 127.0.0.1:29630->8080/tcp
Replace web with the name or ID of your container. A container ID, an unambiguous ID prefix or a name can identify the container. If it is stopped, add -a to docker ps so that it appears in the list.
Checkpoint: you should have one exact container identifier and should know whether the mapping you want is TCP, UDP or another supported protocol. Do not infer a host port from the container's application configuration; the Docker publish rule is the authoritative mapping for this question.
Pass the container identifier without a private port:
$ docker container port web
8080/tcp -> 127.0.0.1:29630
The left side is the container's private port and protocol. The right side is the address and port on the Docker host. In this example, connect to 127.0.0.1:29630 from the host, while the application inside the container listens on port 8080.
There may be several lines. A published range can produce multiple entries, and a container can have separate TCP and UDP mappings for the same port number. Read the protocol suffix rather than treating a number on its own as a complete endpoint.
Add the private port and, when there could be more than one protocol, spell out the protocol:
$ docker container port web 8080/tcp
127.0.0.1:29630
This focused form prints only the public-facing address and port. It is useful in a script or when a container has several mappings. A bare number is accepted as shorthand for the normal protocol selection:
$ docker container port web 8080
127.0.0.1:29630
Use PRIVATE_PORT/PROTO in operational checks anyway. It makes the intended mapping visible during review and avoids querying the wrong entry when both protocols are present.
The address in the result is significant. 127.0.0.1 means the host loopback interface, so a client on another machine cannot reach that published endpoint directly. An address of 0.0.0.0 means Docker published it on all IPv4 interfaces. The command reports the binding; it does not make a private binding public or alter firewall rules.
When creating a container, an explicit publish rule such as -p 127.0.0.1:8080:80 keeps the host side local. Omitting the host address, for example -p 8080:80, normally binds on all interfaces. That is a configuration decision made by docker run or Compose, not by docker container port.
Security checkpoint: Before exposing a service beyond the host, confirm the application authentication, host firewall policy and intended network boundary. Docker's reported port is an exposure detail, not proof that the service is safe to publish.
A valid container can have no published ports. It may still show an internal or exposed port in other Docker output, but that does not create a host endpoint for this command to return. Querying a protocol that was not published produces an error:
$ docker container port web 8080/udp
no public port '8080/udp' published for web
That message means the container was found but the requested private port and protocol has no public mapping. Check the full list without the filter, then inspect the container's configuration if necessary:
$ docker container port web
8080/tcp -> 127.0.0.1:29630
$ docker inspect --format '{{json .NetworkSettings.Ports}}' web
{"8080/tcp":[{"HostIp":"127.0.0.1","HostPort":"29630"}]}
If Docker instead says it cannot find the container, repeat docker ps -a and check spelling, project prefixes and the active Docker context. If the CLI cannot contact the daemon, this read-only command cannot inspect anything. Diagnose the daemon or context rather than adding sudo automatically. Elevated privileges are only appropriate when your host's Docker access policy requires them, and they should be applied to the smallest command that needs them.
Capture the command's output and status if a deployment check needs to confirm a mapping:
mapping=$(docker container port web 8080/tcp) || {
status=$?
printf 'No usable Docker mapping (status %s)\n' "$status" >&2
exit "$status"
}
printf 'Container endpoint: %s\n' "$mapping"
Do not parse the output as if it were always a single fixed string unless your container definition guarantees one mapping. For a human check, the full listing is clearer. For automation, use the exact private port and protocol, and treat a non-zero status as a failed prerequisite.
docker ps or docker ps -a.docker container port CONTAINER showed the complete published list.