Private addresses for your apps, on your Tailscale network.

Open them from your own devices. Share one with a person or a link, until a date you pick.

Install TSLink with Homebrew
brew install --cask anydoor7/tap/tslink
macOS · LinuxOther platforms

Private visits need Tailscale on the viewer’s device. Get Tailscale

Independent project, not made or endorsed by Tailscale.

One private address per app
Your photosImmich

photos.<tailnet>.ts.net

Your mediaJellyfin

media.<tailnet>.ts.net

Your homeHome Assistant

home.<tailnet>.ts.net

Your devices

Phone, tablet and laptop

You decide who gets access

The people you choose Until your deadline
Example addresses. After enrollment, use the exact URL returned by TSLink.

Your apps, on your own devices

Your apps, wherever you open them.

Keep your apps running on your computer or server. Open them from your phone, tablet or another computer on your tailnet.

A name for each app

Web apps, folders, single files and TCP ports each get their own private address.

Open your first app

App recipes

Familiar apps. Less setup guesswork.

Explore app recipes

Your app keeps its own login. Recipes guide proxy settings; they do not install apps or add authentication to apps that have none.

What’s new

Releases and notes.

All updates

Choose how they visit

Three ways to reach an app.

Just you

Reach your apps from your own devices over your tailnet. Each app has its own address.

Recipient needs: Tailscale and permission on your tailnet.

Private visits need Tailscale on the viewer’s device. Get Tailscale

Tailnet policy still applies. Without people or allow rules, other permitted tailnet callers can also connect.

Make a private share

Named people

Grant a Tailscale login access to selected HTTP or file apps, with a deadline you can change.

Recipient needs: Tailscale, sign-in and, when necessary, a per-app device invite.

Private visits need Tailscale on the viewer’s device. Get Tailscale

Checks apply to HTTP and file requests. Raw TCP and open public Funnel are not person-scoped.

Share with a person

Browser guest

Send a finite guest link to one HTTP app. Add a PIN and revoke the link when the visit is over.

Recipient needs: Browser only, with the link and its PIN if set.

Links and PINs can be forwarded. They do not prove who is visiting. Requires public Funnel on the host.

Create a guest link
HTML report with a deadline

How it works

Share when you want to. Choose an end date.

Follow the quick start

Start with Immich already running on port 2283. Open your private address first, then share when you need to.

  1. 1

    Give your app a private address

    Register the app, then get its live URL. TSLink starts the background gateway when needed.

    tslink share 2283 --name photos
    tslink url photos --wait

    First time? Open the printed Tailscale authorization URL and finish approval before running the second command. If share returns a different name, use it.

  2. 2

    Choose a person and a deadline

    Let that person reach photos for seven days, alongside your tailnet policy. Your app keeps its own login.

    tslink people add alice@example.com --apps photos --for 7d

    Use their actual Tailscale login in place of alice@example.com. They need sign-in and network permission; outsiders may also need a per-app invite.

  3. 3

    Or send a browser guest link

    For a short visit without Tailscale, create a three-day link and enter a PIN at the hidden prompt.

    tslink guest create photos --for 3d --pin --public --print-link

    --public enables Funnel with a mandatory guest gate; --print-link reveals the link. Send the PIN separately. Check status and doctor before sharing.

  4. 4

    Take access back

    Remove a person’s managed grants without stopping the app. Their next request is denied.

    tslink people remove alice@example.com

    For a guest, run tslink guest revoke with its grant ID. Downloads cannot be recalled; accepted private streams may continue.

    Guest revocation guide

Fits alongside Tailscale

When do you need TSLink?

Serve is enough for one app on your own devices. TSLink puts app addresses, deadlines and access changes in one workflow.

JobTailscale aloneTSLink
One web app on your phoneTailscale alonetailscale serve 3000 is enoughTSLinktslink share 3000
Several apps, separate namesTailscale aloneServices setup, or separate nodesTSLinkOne share/add per app; enroll each node
One person, one app, seven daysTailscale alonePolicy rules, then a JIT tool or manual removalTSLinktslink people add alice@example.com --apps photos --for 7d (HTTP/files)
Browser link, three daysTailscale alonePublic Funnel; add a gate and scheduled shutdownTSLinktslink guest create photos --for 3d --public --print-link (HTTP only)

Private recipients need Tailscale. Guest links are public, forwardable bearer links.

Read the full guide

CLI + MCP

Let your agent manage it.

Let an agent give its localhost app a private address, report the exact URL and remove it when done. Reduced roles can inspect apps and manage grants for the apps you name.

Set up your agent
{"mcpServers":{"tslink":{"command":"tslink","args":["mcp"]}}}
Four roles, explicit limits
viewer, app-operator, people-manager, owner. Bind supported roles to apps and maximum durations. Local owner is the default; scopes do not sandbox the agent’s shell or filesystem.
44 tools for owner sessions
Reduced roles see fewer tools. Read live tools/list for the session’s authoritative tool set; guest and public mutations remain owner-only.
needs_login is a handoff to a human
Open the enrollment URL, complete approval, then retrieve the live app URL and test access. An enrollment prompt is not a working share.

Know the boundaries

Clear controls. Honest limits.

Read the architecture

01

Revocation has a boundary

Named access stops at the next request. It cannot recall delivered data or stop already accepted private streams. Guest revocation also cancels tracked guest streams.

02

Choose the right access model

People grants apply to HTTP and file apps. Raw TCP relies on tailnet policy and backend login. Browser guest links can be forwarded.

03

Your apps, on your host

TSLink manages access on one host. It does not install apps, isolate host processes or combine multiple hosts. Tailscale supplies transport and HTTPS.

Start with one app

Install on the computer that runs your apps.

macOS, Linux or Windows. Your apps stay where they are; TSLink manages how people reach them.

You need a Tailscale account, MagicDNS and HTTPS. Devices opening private apps need the Tailscale app. Guest links and public web access need Funnel permission; visitors need only a browser.

Install TSLink with Homebrew
brew install --cask anydoor7/tap/tslink
macOS · LinuxOther platforms

Release files include checksums and attestations. The installation guide covers verification.

A few useful answers

Before you start.

Read the full FAQ

Start small

Start with one private address.

Install TSLink. Open an app on your own devices. Share when you want to.

Useful? Star TSLink to find it again. For release notifications, Watch → Custom → Releases.