---
title: "Introduction"
description: "Access and manage apps on your PC or cloud host; keep them private or share them on your terms."
url: "https://tslink.md/docs"
locale: "en"
product_version: "0.1.1"
source: "https://github.com/anydoor7/tslink/blob/v0.1.1/README.md"
---

> Documentation index: https://tslink.md/llms.txt · Installed binary is authoritative: `tslink manifest`.

Scenario guides: [Use your coding agent's web UI from your phone](https://tslink.md/docs/agent-ui-phone.md) · [Share one HTML report privately, with an end date](https://tslink.md/docs/private-html-report.md) · [Share an app, not your whole machine](https://tslink.md/docs/share-one-app.md).

TSLink gives each app on your computer or server its own private Tailscale address. Grant named people access until a deadline, send a browser guest link to someone who does not use Tailscale, and revoke either one with a command. You can manage access through the CLI or an AI agent limited to its assigned role. Tailscale supplies transport and HTTPS; TSLink manages apps on each host.

[TSLink v0.1.1: install with Homebrew, an archive or a package](https://tslink.md/docs/installation.md).

## Choose a first workflow

* [When do you need TSLink?](https://tslink.md/docs/when-to-use-tslink.md): compare Tailscale alone and TSLink by the job, setup and limits.
* [First private share](https://tslink.md/docs/quickstart.md): open a local app or file from your phone.
* [Share with a person and a deadline](https://tslink.md/docs/people-sharing.md): grant seven days, invite an outsider or revoke access.
* [Access local AI](https://tslink.md/docs/local-ai.md): connect a permitted device to an existing model API.
* [Agent/MCP setup](https://tslink.md/docs/mcp-server.md): let an agent inspect and manage shares through role-dependent tools (44 for owner).
* [Browser guest links](https://tslink.md/docs/guest-links.md): offer one HTTP app for a finite visit.
* [Private portal, requests and QR](https://tslink.md/docs/portal-requests.md): one home address per host.
* [Flexible durations](https://tslink.md/docs/durations.md): choose deadlines and explicit renewals.
* [Access history](https://tslink.md/docs/access-history.md): inspect retained access and changes.
* [MCP roles](https://tslink.md/docs/mcp-scopes.md): delegate app operations within scope.
* [Choose a sharing tool](https://tslink.md/docs/comparisons.md): compare TSLink, Serve, official Services and public tunnels.

`share` and `add` ensure the gateway runs by default. Fresh nodes may return a browser enrollment URL (`needs_login`); finish enrollment and any device approval, then retrieve the exact address with `tslink url <name> --wait`. Stored credentials are optional for ordinary private sharing.

## Available now

| Capability                       | Scope                                                                                              |
| -------------------------------- | -------------------------------------------------------------------------------------------------- |
| Proxy, file and raw TCP services | Separate embedded nodes and one local registry; the host needs no separate Tailscale daemon        |
| People and deadlines             | Private proxy/file HTTP only; verified Tailscale logins, per-request expiry and revocation         |
| Invitation bundles               | Optional single-use device invite per app; user-owned API token required to create invites         |
| Public Funnel                    | Proxy only, explicit --funnel --public; new shares default to 24-hour exposure                     |
| App recipes and detection        | Preview/apply routes for self-hosted apps; applications remain separately installed and configured |
| Health and alerts                | Backend observations, key-expiry warnings and opt-in owner notifications                           |
| Request limits                   | HTTP body size and read/idle windows, not requests-per-second middleware                           |
| CLI and MCP                      | Versioned CLI JSON, local stdio MCP, opt-in tailnet-only remote MCP with mcp.allow                 |
| Lifecycle                        | Hot reload and platform supervision; Windows Task Scheduler uses a built-in crash supervisor       |

## Access boundaries

Tailscale policy controls network reachability. TSLink adds private HTTP/file people checks and optional `--allow` rules. Unknown callers on a person-scoped app need an active grant or explicit legacy allow rule; known people's grants override legacy allow rules. Raw TCP depends on tailnet policy and backend authentication. Open Funnel has no TSLink visitor identity gate; browser guest links add a mandatory bearer gate on a separate explicit public workflow.

Revocation blocks new requests; existing streams may finish and downloaded data cannot be recalled. Distinct nodes do not isolate backend processes or the host. Tailnet transport is encrypted; a local backend hop may be plaintext. Your application keeps responsibility for its own authentication.

Multi-host inventory, middleware, admin REST/dashboard, cluster sync, custom-domain ACME and Prometheus remain [planned](https://tslink.md/docs/experimental-roadmap.md). The private portal, requests, QR onboarding, guest links, flexible durations, scoped MCP and bounded history are shipped. TSLink does not install apps, isolate host processes or create a VPC.

Next: [Task recipes](https://tslink.md/docs/use-cases.md) · [Health and request limits](https://tslink.md/docs/health-and-alerts.md) · [Command reference](https://tslink.md/docs/commands.md).

Source: [TSLink README](https://github.com/anydoor7/tslink/blob/v0.1.1/README.md).
