---
title: "File Sharing"
description: "How to expose directories for file sharing over your tailnet"
url: "https://tslink.md/docs/file-sharing"
locale: "en"
product_version: "0.1.1"
source: "https://github.com/anydoor7/tslink/blob/v0.1.1/docs/getting-started.md"
---

> Documentation index: https://tslink.md/llms.txt · Installed binary is authoritative: `tslink manifest`.

## Overview

TSLink can serve any local directory over HTTPS on your Tailscale network. This is useful for sharing documents, build artifacts, media files, or any collection of files with teammates or your own devices.

## Sharing a Directory

Use `tslink add` with the `--dir` flag:

```bash
tslink add <name> --dir <path>
```

**Examples:**

```bash
# Share a documents folder
tslink add docs --dir ~/Documents/shared

# Share build output
tslink add builds --dir /var/www/builds

# Share a project's public assets
tslink add assets --dir ~/projects/my-app/public
```

## Accessing Shared Files

`add` ensures the gateway is running. Complete any enrollment handoff, then run `tslink url docs --wait` and open its exact URL from a device allowed by your tailnet policy:

```
https://docs.<your-tailnet>.ts.net
```

TSLink serves a file listing page at the root URL. You can navigate directories and download files directly through your browser.

## URL Path

Files are served at the root URL of the file service:

```
https://docs.<your-tailnet>.ts.net/
```

Use separate service names when you need separate shared directories.

## Use Cases

### Team File Sharing

Share project resources with your team without uploading to cloud storage:

```bash
tslink add team-resources --dir ~/team/resources
tslink url team-resources --wait
```

After enrollment and URL readiness, permitted tailnet team members can browse and download files.

### Development Artifacts

Share build artifacts or test reports with colleagues:

```bash
tslink add test-reports --dir ./coverage
tslink add builds --dir ./dist
```

### Media Library

Make a local media library accessible across your devices:

```bash
tslink add media --dir /Volumes/External/media
```

Access your files from your phone, tablet, or any other device on your tailnet.

### Temporary Sharing

Need to share files quickly? Add a directory, share the link, then remove it when done:

```bash
# Start sharing
tslink add temp --dir ~/Desktop/send-these

# When done
tslink remove temp
```

### Restricted Sharing

Limit file access to specific users or tagged devices. The `--allow` flag supports both email addresses and ACL tags, and you can specify multiple values:

```bash
# Single user
tslink add confidential --dir ~/Documents/private --allow user@company.com

# Multiple identities
tslink add confidential --dir ~/Documents/private --allow user@company.com,tag:admin

# Combine with tags for ACL-based access
tslink add team-docs --dir ~/team/docs --allow tag:engineering --tags tag:internal
```

Only the specified identities will be able to access the shared directory. Unauthorized requests receive a `403 Forbidden` response.

### Ephemeral Sharing

Use `--ephemeral` to request an ephemeral node. Control-plane cleanup follows inactivity; stopping the gateway is not proof that the remote device is gone. The local registry entry remains until removed. This is useful for one-off file transfers or short-lived sharing sessions:

```bash
# Request temporary node lifetime; verify remote cleanup separately
tslink add temp-share --dir ~/Desktop/handoff --ephemeral

# Combine ephemeral with access control for secure one-time sharing
tslink add handoff --dir ~/Desktop/deliverables --ephemeral --allow colleague@company.com
```

### Multiple Directories

You can share multiple directories as separate services, each with its own hostname and access controls:

```bash
tslink add public-docs --dir ~/Documents/public
tslink add team-files --dir ~/team/shared --allow tag:engineering
tslink add build-output --dir ./dist --ephemeral
```

## Important Notes

* The directory path must exist on the machine running TSLink.
* Paths inside, equal to, or containing TSLink's config directory are refused with `path_exposes_config_dir` to protect credentials and node keys.
* Files are served **read-only** — remote users can download but not upload or modify files.
* The directory is served over HTTPS on the tailnet listener with automatic TLS certificates, and the tailnet transport to the file service is WireGuard-encrypted (file reads happen locally on the host).
* All access is restricted to authenticated devices on your Tailscale network by default — files are never exposed to the public internet. Funnel is proxy-only and requires `--funnel --public`.
* Use `--allow` to restrict access to specific identities for sensitive directories, enforcing least-privilege access.
* Subdirectories are served recursively.
* Funnel (`--funnel --public`) is not available for file services — it is only supported for proxy services and is explicit public exposure.

## People and deadlines

File services also support [people grants](https://tslink.md/docs/people-sharing.md) with deadlines. Give only the intended private file app to a verified Tailscale login; outsiders need an accepted app-device invitation. Revocation stops new requests, not completed downloads or accepted streams. File services cannot use public Funnel.
