2026/03/10

Private Local Services for Coding Agents

Share an existing app or generated file, hand back an exact URL or needs_login step, and choose the right TSLink CLI or MCP interface.

An agent may finish a web preview or report while the person who needs it is on another device. A port number on the agent's machine is not a usable handoff. TSLink can share that existing local service through the person's tailnet and return structured state.

Install TSLink v0.1.1.

Share a preview or file

bash
tslink share 3000 --name preview --json
tslink share ./report.html --name report --json

A result may contain the live URL. On first enrollment it may instead contain data.status: needs_login and data.auth_url. The agent should hand that authorization URL to the person, wait for approval, then run tslink url preview --wait or tslink url report --wait. The human should open the final private URL from another tailnet device. No stored API token or OAuth client is required for this default path.

Choose the correct automation interface

  • CLI JSON: use --json for one command and read its versioned result.
  • Historical local JSON API: Earlier development builds had a JSON-over-stdio top-level command. It has been retired; use current CLI JSON or MCP for new workflows.
  • TSLink as an MCP control server: tslink mcp connects a local MCP client over stdio. An opt-in tailnet-only HTTP control plane is documented separately and grants powerful management access. See MCP server setup.
  • Host a third-party HTTP MCP server: register that server as a TSLink proxy service. This exposes the other server to selected tailnet callers; it does not turn it into TSLink's control interface. See MCP hosting.

Each service has a distinct tailnet node, but that does not isolate its process or replace application authorization. For proxy/file HTTP services, --allow can narrow Tailscale identities. Raw TCP uses tailnet policy and backend authentication. Avoid publishing auth URLs, private hostnames, tool inputs, or file paths in public agent logs.