TSLinkTSLink Docs

Introduction

Access and manage apps on your PC or cloud host; keep them private or share them on your terms.

View as Markdown

Scenario guides: Use your coding agent's web UI from your phone · Share one HTML report privately, with an end date · Share an app, not your whole machine.

TSLink gives each app on your computer or server its own private Tailscale address. Grant named people access until a deadline, send a browser guest link to someone who does not use Tailscale, and revoke either one with a command. You can manage access through the CLI or an AI agent limited to its assigned role. Tailscale supplies transport and HTTPS; TSLink manages apps on each host.

TSLink v0.1.1: install with Homebrew, an archive or a package.

Choose a first workflow

share and add ensure the gateway runs by default. Fresh nodes may return a browser enrollment URL (needs_login); finish enrollment and any device approval, then retrieve the exact address with tslink url <name> --wait. Stored credentials are optional for ordinary private sharing.

Available now

CapabilityScope
Proxy, file and raw TCP servicesSeparate embedded nodes and one local registry; the host needs no separate Tailscale daemon
People and deadlinesPrivate proxy/file HTTP only; verified Tailscale logins, per-request expiry and revocation
Invitation bundlesOptional single-use device invite per app; user-owned API token required to create invites
Public FunnelProxy only, explicit --funnel --public; new shares default to 24-hour exposure
App recipes and detectionPreview/apply routes for self-hosted apps; applications remain separately installed and configured
Health and alertsBackend observations, key-expiry warnings and opt-in owner notifications
Request limitsHTTP body size and read/idle windows, not requests-per-second middleware
CLI and MCPVersioned CLI JSON, local stdio MCP, opt-in tailnet-only remote MCP with mcp.allow
LifecycleHot reload and platform supervision; Windows Task Scheduler uses a built-in crash supervisor

Access boundaries

Tailscale policy controls network reachability. TSLink adds private HTTP/file people checks and optional --allow rules. Unknown callers on a person-scoped app need an active grant or explicit legacy allow rule; known people's grants override legacy allow rules. Raw TCP depends on tailnet policy and backend authentication. Open Funnel has no TSLink visitor identity gate; browser guest links add a mandatory bearer gate on a separate explicit public workflow.

Revocation blocks new requests; existing streams may finish and downloaded data cannot be recalled. Distinct nodes do not isolate backend processes or the host. Tailnet transport is encrypted; a local backend hop may be plaintext. Your application keeps responsibility for its own authentication.

Multi-host inventory, middleware, admin REST/dashboard, cluster sync, custom-domain ACME and Prometheus remain planned. The private portal, requests, QR onboarding, guest links, flexible durations, scoped MCP and bounded history are shipped. TSLink does not install apps, isolate host processes or create a VPC.

Next: Task recipes · Health and request limits · Command reference.

Source: TSLink README.

Table of Contents