TSLink, Tailscale Serve, Services and Public Tunnels
Choose a sharing workflow for one service, several local apps, stable multi-host services or a public URL.
TSLink fits when you run several apps on one computer and want private per-app addresses, named-person deadlines for HTTP/files, and CLI or MCP lifecycle management. Tailscale Serve and Services already offer service publishing; choose by the workflow you need.
The choices below are workflow judgments based on official documentation, not performance benchmarks. Serve and Services addressing checked on October 7, 2026.
| Tool | A useful starting point when… | What to account for |
|---|---|---|
| TSLink | One person runs multiple local apps and wants to manage people, deadlines, invitations and recipes | Apps stay on the publishing host. Recipients need Tailscale for private access. Source install requires Go; browser guest links and MCP scopes are shipped, with explicit public/private boundaries. |
| Tailscale Serve | You already run the Tailscale client and want to share a local service, file or TCP forwarder | Serve supports multiple ports on a device hostname; TSLink's per-app embedded nodes are a different operating model. |
| Tailscale Services | You administer named resources across hosts and want the address to survive host moves or redundant hosts | Services already has stable named services, traffic steering, access controls and host approval. Follow its admin and service-host setup. |
| ngrok | You need a public localhost endpoint for a webhook, demo or external client | Configure endpoint policy and authentication for the audience. Public tunneling does not mean authentication is unavailable. |
| Cloudflare Tunnel | You want outbound connections from your origin to Cloudflare's network | Decide separately which apps are public and which need Access policies. Account, domain and connector setup differ from tailnet enrollment. |
For the task-by-task setup and limits, read When do you need TSLink? Tailscale alone vs TSLink.
TSLink versus Tailscale Serve
Serve is enough when device-hostname routes on one or more ports meet your needs. Reuse the Tailscale client you already operate. TSLink embeds a node for each app and keeps their registrations together. Its added workflow includes app recipes, health observations, named people with deadlines, invitation bundles and CLI JSON/MCP operations.
TSLink supplies the sharing lifecycle. You still install, configure and run the backend application, retain its own authentication, and keep the publishing computer available. See share with a person and health checks.
TSLink versus official Tailscale Services
Official Services already decouples service names from hosting devices. For example, its documented command form is tailscale serve --service=svc:web-server --https=443 localhost:3000, after the service and host approvals are configured.
TSLink's distinction is the local multi-app, per-person lifecycle workflow. It does not provide Services' multi-host routing or high availability, and independent TSLink computers do not form a synchronized cluster. Both depend on Tailscale policy and suitable application security.
Private sharing or a public tunnel?
For a teammate or family member with a Tailscale account, private people sharing can constrain new HTTP/file requests to their login and deadline. Outsiders accept one Tailscale app invitation per app; a bundle reduces owner commands, not recipient accepts.
For a finite browser visit, TSLink offers single-app guest links with a mandatory gate and optional PIN over public Funnel. The link/PIN can be forwarded and does not identify a person. Open Funnel remains a separate explicit publication; keep application authentication. People revocation cannot recall downloads or end already accepted private streams; guest revoke/expiry cancels tracked guest streams.
Read MCP roles for bounded delegation and portal for a private per-host directory. Multi-host inventory remains planned. TSLink is an independent project, not an official Tailscale product.
Next: Installation · Local AI · Agent/MCP setup.
Sources: official documentation linked above, and TSLink comparison.