Browser Guest Links
Open one HTTP proxy app for a finite browser visit, with a mandatory guest gate and optional PIN.
Scenario guides: Share one HTML report privately, with an end date.
Guest links let someone open one HTTP proxy app in a browser without installing Tailscale or creating an account. The owner needs a running, enrolled node, Tailscale HTTPS and Funnel permission. This is explicitly public HTTPS through Funnel, protected by a mandatory guest gate.
Create and send a link
Bring the private app online first and verify its exact URL:
tslink add photos --proxy localhost:3000
tslink url photos --wait
tslink guest create photos --for 3d --label "Family visit" --public --print-link --json--for is required. --public acknowledges the public edge when first enabling the gate. Creation saves configuration; the daemon watcher applies it. Check status and doctor for actual Funnel availability. It does not install a daemon or enroll a node.
--print-link explicitly reveals the bearer URL once. Without it, link is null; list/show cannot recover the token. An exact current URL is required before disclosure and mutation. Store or send the link privately. Add --pin to read a 6–64 digit PIN from hidden terminal input or stdin, then send that PIN separately. Never put it in shell arguments. MCP guest_create accepts a secret pin; avoid logging its request.
The recipient opens the link, enters the PIN if configured, and continues to the app. The finite lifetime has a 1h minimum and a default 7d maximum; the owner can configure that maximum. never is refused. See durations.
Inspect and revoke
tslink guest list --json
tslink guest show <id> --json
tslink guest revoke <id> --json
tslink access log --app photos --since 24h --jsonRevoke is permanent for that ID; issue a new grant to renew. Each public request checks the grant. Revoke and expiry cancel tracked guest streams, including SSE/WebSocket, though a bounded request authorized before the revoke commit may finish. Counters are local estimates and a crash may lose unflushed usage. Access history is bounded and can have gaps.
Choose the right audience
A link or PIN can be forwarded. A label is an owner's note, not proof of the visitor's identity. Public guests receive no Tailscale user identity headers. Keep the app's own authentication and authorization where needed; there is no general OIDC sign-in tier.
File services and raw TCP cannot use guest grants. Private traffic to the same gated app still follows independent people/--allow rules; a guest session cannot bypass them. Gated apps are owner/admin inventory in the private portal and cannot receive access requests.
An existing open Funnel must be returned to a private listener before enabling a guest gate. Preserve the full app configuration when replacing it. Guest mode is sticky; ordinary add cannot silently remove it. Follow the TSLink migration guide before changing publication mode.
Related: People sharing · MCP roles · Public Funnel.
Sources: TSLink guest-links.md