---
title: "Browser Guest Links"
description: "Open one HTTP proxy app for a finite browser visit, with a mandatory guest gate and optional PIN."
url: "https://tslink.md/docs/guest-links"
locale: "en"
product_version: "0.1.1"
source: "https://github.com/anydoor7/tslink/blob/v0.1.1/docs/guest-links.md"
---

> Documentation index: https://tslink.md/llms.txt · Installed binary is authoritative: `tslink manifest`.

Scenario guides: [Share one HTML report privately, with an end date](https://tslink.md/docs/private-html-report.md).

Guest links let someone open **one HTTP proxy app** in a browser without installing Tailscale or creating an account. The owner needs a running, enrolled node, Tailscale HTTPS and Funnel permission. This is explicitly public HTTPS through Funnel, protected by a mandatory guest gate.

## Create and send a link

Bring the private app online first and verify its exact URL:

```bash
tslink add photos --proxy localhost:3000
tslink url photos --wait
tslink guest create photos --for 3d --label "Family visit" --public --print-link --json
```

`--for` is required. `--public` acknowledges the public edge when first enabling the gate. Creation saves configuration; the daemon watcher applies it. Check `status` and `doctor` for actual Funnel availability. It does not install a daemon or enroll a node.

`--print-link` explicitly reveals the bearer URL once. Without it, `link` is null; list/show cannot recover the token. An exact current URL is required before disclosure and mutation. Store or send the link privately. Add `--pin` to read a 6–64 digit PIN from hidden terminal input or stdin, then send that PIN separately. Never put it in shell arguments. MCP `guest_create` accepts a secret `pin`; avoid logging its request.

The recipient opens the link, enters the PIN if configured, and continues to the app. The finite lifetime has a 1h minimum and a default 7d maximum; the owner can configure that maximum. `never` is refused. See [durations](https://tslink.md/docs/durations.md).

## Inspect and revoke

```bash
tslink guest list --json
tslink guest show <id> --json
tslink guest revoke <id> --json
tslink access log --app photos --since 24h --json
```

Revoke is permanent for that ID; issue a new grant to renew. Each public request checks the grant. Revoke and expiry cancel tracked guest streams, including SSE/WebSocket, though a bounded request authorized before the revoke commit may finish. Counters are local estimates and a crash may lose unflushed usage. [Access history](https://tslink.md/docs/access-history.md) is bounded and can have gaps.

## Choose the right audience

A link or PIN can be forwarded. A label is an owner's note, **not proof of the visitor's identity**. Public guests receive no Tailscale user identity headers. Keep the app's own authentication and authorization where needed; there is no general OIDC sign-in tier.

File services and raw TCP cannot use guest grants. Private traffic to the same gated app still follows independent people/`--allow` rules; a guest session cannot bypass them. Gated apps are owner/admin inventory in the [private portal](https://tslink.md/docs/portal-requests.md) and cannot receive access requests.

An existing open Funnel must be returned to a private listener before enabling a guest gate. Preserve the full app configuration when replacing it. Guest mode is sticky; ordinary `add` cannot silently remove it. Follow the TSLink migration guide before changing publication mode.

Related: [People sharing](https://tslink.md/docs/people-sharing.md) · [MCP roles](https://tslink.md/docs/mcp-scopes.md) · [Public Funnel](https://tslink.md/docs/services.md#tailscale-funnel).

Sources: [TSLink guest-links.md](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/guest-links.md)
