Introduction
Access and manage apps on your PC or cloud host; keep them private or share them on your terms.
Scenario guides: Use your coding agent's web UI from your phone · Share one HTML report privately, with an end date · Share an app, not your whole machine.
TSLink gives each app on your computer or server its own private Tailscale address. Grant named people access until a deadline, send a browser guest link to someone who does not use Tailscale, and revoke either one with a command. You can manage access through the CLI or an AI agent limited to its assigned role. Tailscale supplies transport and HTTPS; TSLink manages apps on each host.
TSLink v0.1.1: install with Homebrew, an archive or a package.
Choose a first workflow
- When do you need TSLink?: compare Tailscale alone and TSLink by the job, setup and limits.
- First private share: open a local app or file from your phone.
- Share with a person and a deadline: grant seven days, invite an outsider or revoke access.
- Access local AI: connect a permitted device to an existing model API.
- Agent/MCP setup: let an agent inspect and manage shares through role-dependent tools (44 for owner).
- Browser guest links: offer one HTTP app for a finite visit.
- Private portal, requests and QR: one home address per host.
- Flexible durations: choose deadlines and explicit renewals.
- Access history: inspect retained access and changes.
- MCP roles: delegate app operations within scope.
- Choose a sharing tool: compare TSLink, Serve, official Services and public tunnels.
share and add ensure the gateway runs by default. Fresh nodes may return a browser enrollment URL (needs_login); finish enrollment and any device approval, then retrieve the exact address with tslink url <name> --wait. Stored credentials are optional for ordinary private sharing.
Available now
| Capability | Scope |
|---|---|
| Proxy, file and raw TCP services | Separate embedded nodes and one local registry; the host needs no separate Tailscale daemon |
| People and deadlines | Private proxy/file HTTP only; verified Tailscale logins, per-request expiry and revocation |
| Invitation bundles | Optional single-use device invite per app; user-owned API token required to create invites |
| Public Funnel | Proxy only, explicit --funnel --public; new shares default to 24-hour exposure |
| App recipes and detection | Preview/apply routes for self-hosted apps; applications remain separately installed and configured |
| Health and alerts | Backend observations, key-expiry warnings and opt-in owner notifications |
| Request limits | HTTP body size and read/idle windows, not requests-per-second middleware |
| CLI and MCP | Versioned CLI JSON, local stdio MCP, opt-in tailnet-only remote MCP with mcp.allow |
| Lifecycle | Hot reload and platform supervision; Windows Task Scheduler uses a built-in crash supervisor |
Access boundaries
Tailscale policy controls network reachability. TSLink adds private HTTP/file people checks and optional --allow rules. Unknown callers on a person-scoped app need an active grant or explicit legacy allow rule; known people's grants override legacy allow rules. Raw TCP depends on tailnet policy and backend authentication. Open Funnel has no TSLink visitor identity gate; browser guest links add a mandatory bearer gate on a separate explicit public workflow.
Revocation blocks new requests; existing streams may finish and downloaded data cannot be recalled. Distinct nodes do not isolate backend processes or the host. Tailnet transport is encrypted; a local backend hop may be plaintext. Your application keeps responsibility for its own authentication.
Multi-host inventory, middleware, admin REST/dashboard, cluster sync, custom-domain ACME and Prometheus remain planned. The private portal, requests, QR onboarding, guest links, flexible durations, scoped MCP and bounded history are shipped. TSLink does not install apps, isolate host processes or create a VPC.
Next: Task recipes · Health and request limits · Command reference.
Source: TSLink README.