File Sharing
How to expose directories for file sharing over your tailnet
Overview
TSLink can serve any local directory over HTTPS on your Tailscale network. This is useful for sharing documents, build artifacts, media files, or any collection of files with teammates or your own devices.
Sharing a Directory
Use tslink add with the --dir flag:
tslink add <name> --dir <path>Examples:
# Share a documents folder
tslink add docs --dir ~/Documents/shared
# Share build output
tslink add builds --dir /var/www/builds
# Share a project's public assets
tslink add assets --dir ~/projects/my-app/publicAccessing Shared Files
add ensures the gateway is running. Complete any enrollment handoff, then run tslink url docs --wait and open its exact URL from a device allowed by your tailnet policy:
https://docs.<your-tailnet>.ts.netTSLink serves a file listing page at the root URL. You can navigate directories and download files directly through your browser.
URL Path
Files are served at the root URL of the file service:
https://docs.<your-tailnet>.ts.net/Use separate service names when you need separate shared directories.
Use Cases
Team File Sharing
Share project resources with your team without uploading to cloud storage:
tslink add team-resources --dir ~/team/resources
tslink url team-resources --waitAfter enrollment and URL readiness, permitted tailnet team members can browse and download files.
Development Artifacts
Share build artifacts or test reports with colleagues:
tslink add test-reports --dir ./coverage
tslink add builds --dir ./distMedia Library
Make a local media library accessible across your devices:
tslink add media --dir /Volumes/External/mediaAccess your files from your phone, tablet, or any other device on your tailnet.
Temporary Sharing
Need to share files quickly? Add a directory, share the link, then remove it when done:
# Start sharing
tslink add temp --dir ~/Desktop/send-these
# When done
tslink remove tempRestricted Sharing
Limit file access to specific users or tagged devices. The --allow flag supports both email addresses and ACL tags, and you can specify multiple values:
# Single user
tslink add confidential --dir ~/Documents/private --allow user@company.com
# Multiple identities
tslink add confidential --dir ~/Documents/private --allow user@company.com,tag:admin
# Combine with tags for ACL-based access
tslink add team-docs --dir ~/team/docs --allow tag:engineering --tags tag:internalOnly the specified identities will be able to access the shared directory. Unauthorized requests receive a 403 Forbidden response.
Ephemeral Sharing
Use --ephemeral to request an ephemeral node. Control-plane cleanup follows inactivity; stopping the gateway is not proof that the remote device is gone. The local registry entry remains until removed. This is useful for one-off file transfers or short-lived sharing sessions:
# Request temporary node lifetime; verify remote cleanup separately
tslink add temp-share --dir ~/Desktop/handoff --ephemeral
# Combine ephemeral with access control for secure one-time sharing
tslink add handoff --dir ~/Desktop/deliverables --ephemeral --allow colleague@company.comMultiple Directories
You can share multiple directories as separate services, each with its own hostname and access controls:
tslink add public-docs --dir ~/Documents/public
tslink add team-files --dir ~/team/shared --allow tag:engineering
tslink add build-output --dir ./dist --ephemeralImportant Notes
- The directory path must exist on the machine running TSLink.
- Paths inside, equal to, or containing TSLink's config directory are refused with
path_exposes_config_dirto protect credentials and node keys. - Files are served read-only — remote users can download but not upload or modify files.
- The directory is served over HTTPS on the tailnet listener with automatic TLS certificates, and the tailnet transport to the file service is WireGuard-encrypted (file reads happen locally on the host).
- All access is restricted to authenticated devices on your Tailscale network by default — files are never exposed to the public internet. Funnel is proxy-only and requires
--funnel --public. - Use
--allowto restrict access to specific identities for sensitive directories, enforcing least-privilege access. - Subdirectories are served recursively.
- Funnel (
--funnel --public) is not available for file services — it is only supported for proxy services and is explicit public exposure.
People and deadlines
File services also support people grants with deadlines. Give only the intended private file app to a verified Tailscale login; outsiders need an accepted app-device invitation. Revocation stops new requests, not completed downloads or accepted streams. File services cannot use public Funnel.