Private Local Services for Coding Agents
Share an existing app or generated file, hand back an exact URL or needs_login step, and choose the right TSLink CLI or MCP interface.
An agent may finish a web preview or report while the person who needs it is on another device. A port number on the agent's machine is not a usable handoff. TSLink can share that existing local service through the person's tailnet and return structured state.
Share a preview or file
tslink share 3000 --name preview --json
tslink share ./report.html --name report --jsonA result may contain the live URL. On first enrollment it may instead contain data.status: needs_login and data.auth_url. The agent should hand that authorization URL to the person, wait for approval, then run tslink url preview --wait or tslink url report --wait. The human should open the final private URL from another tailnet device. No stored API token or OAuth client is required for this default path.
Choose the correct automation interface
- CLI JSON: use
--jsonfor one command and read its versioned result. - Historical local JSON API: Earlier development builds had a JSON-over-stdio top-level command. It has been retired; use current CLI JSON or MCP for new workflows.
- TSLink as an MCP control server:
tslink mcpconnects a local MCP client over stdio. An opt-in tailnet-only HTTP control plane is documented separately and grants powerful management access. See MCP server setup. - Host a third-party HTTP MCP server: register that server as a TSLink proxy service. This exposes the other server to selected tailnet callers; it does not turn it into TSLink's control interface. See MCP hosting.
Each service has a distinct tailnet node, but that does not isolate its process or replace application authorization. For proxy/file HTTP services, --allow can narrow Tailscale identities. Raw TCP uses tailnet policy and backend authentication. Avoid publishing auth URLs, private hostnames, tool inputs, or file paths in public agent logs.
More Posts
Introducing TSLink: Share Local Services by Name
A Go CLI for sharing an existing app or file on your private tailnet, then managing named services with CLI JSON and MCP.
Share Your First Local Service with TSLink
Install TSLink, share an existing app or file, approve the node if prompted, and retrieve its private URL.
Who Can Open a Shared Local Service?
A practical access-boundary guide for a privately shared TSLink service: tailnet policy, optional HTTP --allow, raw TCP, and public Funnel.