A name for each app
Web apps, folders, single files and TCP ports each get their own private address.
Open them from your own devices. Share one with a person or a link, until a date you pick.
brew install --cask anydoor7/tap/tslinkPrivate visits need Tailscale on the viewer’s device. Get Tailscale
Independent project, not made or endorsed by Tailscale.
photos.<tailnet>.ts.net
media.<tailnet>.ts.net
home.<tailnet>.ts.net
Your devices
Phone, tablet and laptop
You decide who gets access
Your apps, on your own devices
Keep your apps running on your computer or server. Open them from your phone, tablet or another computer on your tailnet.
Web apps, folders, single files and TCP ports each get their own private address.
A private portal lists the apps each visitor can open, with their health.
Health checks and alerts, with bounded local access history that includes denied requests.
App recipes
Your app keeps its own login. Recipes guide proxy settings; they do not install apps or add authentication to apps that have none.
What’s new
Release notes ·
Project note ·
Project note ·
Choose how they visit
Reach your apps from your own devices over your tailnet. Each app has its own address.
Recipient needs: Tailscale and permission on your tailnet.
Private visits need Tailscale on the viewer’s device. Get Tailscale
Tailnet policy still applies. Without people or allow rules, other permitted tailnet callers can also connect.
Make a private shareGrant a Tailscale login access to selected HTTP or file apps, with a deadline you can change.
Recipient needs: Tailscale, sign-in and, when necessary, a per-app device invite.
Private visits need Tailscale on the viewer’s device. Get Tailscale
Checks apply to HTTP and file requests. Raw TCP and open public Funnel are not person-scoped.
Share with a personSend a finite guest link to one HTTP app. Add a PIN and revoke the link when the visit is over.
Recipient needs: Browser only, with the link and its PIN if set.
Links and PINs can be forwarded. They do not prove who is visiting. Requires public Funnel on the host.
Create a guest linkHow it works
Start with Immich already running on port 2283. Open your private address first, then share when you need to.
Register the app, then get its live URL. TSLink starts the background gateway when needed.
tslink share 2283 --name photos
tslink url photos --waitFirst time? Open the printed Tailscale authorization URL and finish approval before running the second command. If share returns a different name, use it.
Let that person reach photos for seven days, alongside your tailnet policy. Your app keeps its own login.
tslink people add alice@example.com --apps photos --for 7dUse their actual Tailscale login in place of alice@example.com. They need sign-in and network permission; outsiders may also need a per-app invite.
For a short visit without Tailscale, create a three-day link and enter a PIN at the hidden prompt.
tslink guest create photos --for 3d --pin --public --print-link--public enables Funnel with a mandatory guest gate; --print-link reveals the link. Send the PIN separately. Check status and doctor before sharing.
Remove a person’s managed grants without stopping the app. Their next request is denied.
tslink people remove alice@example.comFor a guest, run tslink guest revoke with its grant ID. Downloads cannot be recalled; accepted private streams may continue.
Guest revocation guideFits alongside Tailscale
Serve is enough for one app on your own devices. TSLink puts app addresses, deadlines and access changes in one workflow.
| Job | Tailscale alone | TSLink |
|---|---|---|
| One web app on your phone | Tailscale alonetailscale serve 3000 is enough | TSLinktslink share 3000 |
| Several apps, separate names | Tailscale aloneServices setup, or separate nodes | TSLinkOne share/add per app; enroll each node |
| One person, one app, seven days | Tailscale alonePolicy rules, then a JIT tool or manual removal | TSLinktslink people add alice@example.com --apps photos --for 7d (HTTP/files) |
| Browser link, three days | Tailscale alonePublic Funnel; add a gate and scheduled shutdown | TSLinktslink guest create photos --for 3d --public --print-link (HTTP only) |
Private recipients need Tailscale. Guest links are public, forwardable bearer links.
Read the full guideCLI + MCP
Let an agent give its localhost app a private address, report the exact URL and remove it when done. Reduced roles can inspect apps and manage grants for the apps you name.
Set up your agent{"mcpServers":{"tslink":{"command":"tslink","args":["mcp"]}}}Know the boundaries
01
Named access stops at the next request. It cannot recall delivered data or stop already accepted private streams. Guest revocation also cancels tracked guest streams.
02
People grants apply to HTTP and file apps. Raw TCP relies on tailnet policy and backend login. Browser guest links can be forwarded.
03
TSLink manages access on one host. It does not install apps, isolate host processes or combine multiple hosts. Tailscale supplies transport and HTTPS.
Start with one app
macOS, Linux or Windows. Your apps stay where they are; TSLink manages how people reach them.
You need a Tailscale account, MagicDNS and HTTPS. Devices opening private apps need the Tailscale app. Guest links and public web access need Funnel permission; visitors need only a browser.
brew install --cask anydoor7/tap/tslinkRelease files include checksums and attestations. The installation guide covers verification.
Start small
Install TSLink. Open an app on your own devices. Share when you want to.
Useful? Star TSLink to find it again. For release notifications, Watch → Custom → Releases.