I do the same thing but with SSH. I like using SSH as the proxy because it supports other protocols besides HTTP and people generally already have SSH keys, and I don't have to manage another daemon just to provide authentication with yet another set of public/private keys.
Just have your service listing on 127.0.0.1 and have SSH listening on 0.0.0.0 and proxy in!