2026/05/25

Host an HTTP MCP Server on Your Private Tailnet

A concrete TSLink proxy path for a third-party HTTP MCP server, with tailnet access, backend authentication, and Funnel boundaries.

A third-party HTTP MCP server may be useful from more than one device. Before sharing it, check what its tools can read or change. TSLink can make that existing HTTP endpoint reachable on a private Tailscale tailnet as a proxy service.

Install TSLink v0.1.1.

Register the server you already run

Suppose the HTTP MCP server listens on localhost:8080:

bash
tslink add mcp-tools --proxy localhost:8080 --json
tslink url mcp-tools --wait

By default, add saves the named service and ensures the background gateway is running. If its JSON result reports data.status: needs_login, open data.auth_url and approve the new tsnet node before running url --wait to retrieve its live address. Use tslink status --json to inspect readiness. If you want TSLink to reject HTTP callers whose Tailscale identity does not match your policy, configure --allow for the proxy service. Without it or a people policy, callers allowed by tailnet policy can reach the proxy. People expiry and deny records still apply.

The tailnet leg uses Tailscale/WireGuard, and proxy HTTP uses a Tailscale HTTPS listener. The hop to the local backend may be plaintext. The separate node identity is a network boundary, not a process sandbox; the MCP server still needs appropriate application authorization for its tools.

Keep the interfaces separate

This setup hosts another HTTP MCP server behind TSLink. It does not connect your MCP client to TSLink's own service-management tools. For that, run local tslink mcp over stdio as described in MCP control server setup. The optional remote control plane from tslink serve --mcp is tailnet-only and has high management privilege; follow its explicit access configuration before enabling it.

Public Funnel exposure is a separate decision and requires both --funnel and --public. TSLink's tailnet identity filter does not protect public Funnel requests. Keep privileged MCP tools private unless you have designed application-layer authentication and review for a public endpoint. MCP hosting guide covers configuration and limitations.