---
title: "Use your coding agent's web UI from your phone"
description: "Open a coding-agent UI or dev server on your phone through TSLink. Set up private access, verify the URL, and remove the share when done."
url: "https://tslink.md/docs/agent-ui-phone"
locale: "en"
product_version: "0.1.1"
source: "https://github.com/anydoor7/tslink/blob/v0.1.1/docs/agent-quickstart.md"
---

> Documentation index: https://tslink.md/llms.txt · Installed binary is authoritative: `tslink manifest`.

Share a running dev server by port, or just `report.html` with `tslink share ./report.html`; open from a permitted Tailscale phone, then remove the share. For the file workflow, see [share one HTML report](https://tslink.md/docs/private-html-report.md).

## Before you start

[Install TSLink](https://tslink.md/docs/installation.md) on the publishing machine. Have an HTTP UI or dev server already running on an address the daemon can reach; the publishing machine needs no separate Tailscale app. Enable MagicDNS and HTTPS, and permit the connection in tailnet policy. See [first private share](https://tslink.md/docs/quickstart.md), [Tailscale HTTPS setup](https://tailscale.com/docs/how-to/set-up-https-certificates) and [access controls](https://tailscale.com/docs/features/access-control/acls).

Any agent UI or dev server that serves HTTP on a port the daemon can reach fits this workflow, such as an OpenCode, Vite or Next.js dev server. TSLink forwards requests to it; it does not start, configure or sign in to the app.

## Publish the agent's running port

Use the port the app actually chose. For port 3000:

```bash
tslink share localhost:3000 --name agent-ui --json
```

Capture `data.name` from the response: the requested name can receive a suffix. Use that actual name in every later command. Sharing can install/start TSLink's background service; it does not start the dev server. See [app management](https://tslink.md/docs/services.md) and [daemon lifecycle](https://tslink.md/docs/daemon.md).

An agent can use CLI `--json` or MCP `share` and `unshare`. MCP registration/removal requires `owner`, including remote MCP; `app-operator`, `people-manager` and `viewer` cannot create or delete shares. Local stdio MCP is owner by default. CLI access uses the launching OS user's authority rather than an MCP role. See [MCP setup](https://tslink.md/docs/mcp-server.md) and [MCP roles](https://tslink.md/docs/mcp-scopes.md).

## Finish enrollment and copy the exact URL

If `status` is `needs_login`, give the returned `auth_url` to the owner. This is a successful pending handoff, not a working app URL. A person completes enrollment and any device approval. Then replace `<returned-name>` below with the saved actual name:

```bash
tslink url <returned-name> --wait --json
tslink status --urls --name <returned-name> --json
```

Use the exact returned endpoint; require a real response from the phone before calling the preview ready. See [enrollment and URL retrieval](https://tslink.md/docs/quickstart.md) and [Tailscale tsnet authentication](https://tailscale.com/docs/features/tsnet).

## Open it on your phone

The phone needs a browser and Tailscale installed, connected and signed in. It does not need TSLink. `tslink share` adds no per-person check: any device your tailnet policy lets reach the new node can open the UI. To limit it to your own login, register it with `tslink add agent-ui --proxy localhost:3000 --allow you@example.com` instead, or pass `allow` to the MCP `share` tool. A recipient outside your tailnet also accepts the app-node invitation. See [people sharing](https://tslink.md/docs/people-sharing.md), [Tailscale for iOS](https://tailscale.com/docs/install/ios), [Android](https://tailscale.com/docs/install/android) and [device sharing](https://tailscale.com/docs/features/sharing).

## Check login, live updates, and host settings

Keep the UI's own authentication and tool permissions. TSLink proxies the app's functions; it does not authorize another MCP server's tools. See [MCP hosting](https://tslink.md/docs/mcp-hosting.md) and [access boundaries](https://tslink.md/docs/architecture.md).

TSLink's HTTP proxy forwards WebSocket upgrades, and its upload timeout does not cut off streamed responses such as server-sent events, so hot reload and live agent output can reach the phone. By default `share` rewrites the Host header to the local target and leaves the browser's Origin unchanged. If the app checks Origin, or checks allowed hosts when you use `--preserve-host`, allow the exact URL from `tslink url`. Open the app from that URL on the phone and confirm login, live updates and layout before you rely on it. See [reverse proxy](https://tslink.md/docs/architecture.md#reverse-proxy), [app recipes and WebSockets](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/apps.md) and [request limits and streams](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/sharing.md).

## Remove the preview

Remove only the returned name:

```bash
tslink remove <returned-name> --json
```

The MCP equivalent is `unshare`. Removal deletes registration; the daemon reconciles and closes its node. Remote device deletion depends on credentials and ownership proof. It does not stop the agent/backend, uninstall the daemon or recall downloads. Stop the dev server separately if desired and inspect the cleanup result. See [app removal](https://tslink.md/docs/services.md) and [MCP roles](https://tslink.md/docs/mcp-scopes.md).

Official Tailscale sources linked above: accessed **2026-10-07**. Product behavior: TSLink v0.1.1.
