Share Your First Local Service with TSLink
Install TSLink, share an existing app or file, approve the node if prompted, and retrieve its private URL.
Share an existing app
Start an app on localhost:3000, then run:
tslink share 3000 --name preview --jsonThe first run needs no stored Tailscale API token or OAuth client. TSLink may return data.status: needs_login and data.auth_url for a new node. A person should open that URL and approve the node. The command does not make the app public.
After approval, retrieve the live address:
tslink url preview --waitOpen the returned address on another device signed into the same tailnet and permitted by its policy. The exact hostname comes from TSLink's output; do not assume a placeholder address is live.
Share a generated file
tslink share ./report.html --name report --jsonThis works well for an agent handing a built report to a person. If the result needs approval, the agent should pass data.auth_url to the person and resume with tslink url report --wait. For local MCP clients, see MCP server setup; to host someone else's HTTP MCP server, see MCP hosting.
Keep a service registered
For a named proxy, use tslink add app-preview --proxy localhost:3000 --json. By default, add saves the service and ensures the background gateway is running. If it returns data.status: needs_login, open data.auth_url and approve the new node, then retrieve the live address with tslink url app-preview --wait. Use tslink status --json to inspect readiness. A stored credential via tslink login is optional for tagged, durable multi-service setups. Quick Start explains that branch and the service lifecycle.
More Posts
Introducing TSLink: Share Local Services by Name
A Go CLI for sharing an existing app or file on your private tailnet, then managing named services with CLI JSON and MCP.
Private Local Services for Coding Agents
Share an existing app or generated file, hand back an exact URL or needs_login step, and choose the right TSLink CLI or MCP interface.
Who Can Open a Shared Local Service?
A practical access-boundary guide for a privately shared TSLink service: tailnet policy, optional HTTP --allow, raw TCP, and public Funnel.