TSLinkTSLink Docs

MCP Roles, App Scopes and Receipts

Delegate bounded MCP operations while keeping app access and the agent’s OS permissions separate.

View as Markdown

Local tslink mcp defaults to owner authority. Reduce the session when delegating:

bash
tslink mcp --scope viewer --apps photos
tslink mcp --scope app-operator --apps photos --max-duration 8h
tslink mcp --scope people-manager --apps finance --max-duration 2h
tslink mcp --scope viewer --inventory

These limits govern TSLink MCP operations. They do not sandbox the agent's shell/filesystem; another process running as owner can launch an owner session. Configure those capabilities separately. Inventory permission does not grant permission to open an app.

RoleAvailable operationsBoundary
viewerRead inventory, health, URLs, people and explicit-app access history; static recipe/template catalogsExplicit apps, or explicit inventory for all app inventory
app-operatorViewer plus app_restart, people_grant, people_revoke, person extendListed apps; positive maximum grant duration
people-managerViewer plus one-app grants/revokes/extensions and request toolsListed apps and finite limits; request authority has additional owner checks
ownerAll 44 shipped tools, including guest/public mutations and mcp_auditNo app/duration restrictions; binding expiry can still apply

Current viewer sessions expose 12 tools; people-manager sessions expose 18. Use live tools/list for your session; tool visibility depends on role. Operator/manager local max_duration defaults to 24h. Reduced sessions cannot widen their scope through arguments or create unknown people.

people_grant changes one pre-existing person's private HTTP/file app grant; people_revoke affects one app. They preserve other grants and cannot undo a whole-person revocation. TCP and ungated public Funnel are unsupported; private people checks remain valid on a guest-gated app. New people records need owner authority (mcp_person_owner_required). Protected portal owner/admin records cannot be changed by reduced roles.

app_restart queues a restart of the TSLink gateway node, preserves enrolled identity and does not restart the backend app or prove completion. Poll status/health; reduced operators cannot restart an existing public Funnel app.

Remote binding

Keep your own owner login and add the exact delegate login in config.json:

json
{"mcp":{"enabled":true,"allow":["you@example.com"],"bindings":[{"principal":"family@example.com","role":"viewer","apps":["photos"]}]}}

Restart the daemon after editing. Connect from a permitted tailnet device to the actual remote MCP URL. Legacy mcp.allow entries retain owner authority; remove a login there before assigning it a reduced binding. Duplicate principals and invalid/unknown bindings fail closed. Explicit logins take precedence; multiple matching tag principals deny access. Owner tags grant broad authority to devices carrying them.

Operator/manager remote bindings need positive max_duration. Use an actual issued_at with relative for, or expires_at RFC3339, to limit the binding itself; these forms are exclusive. Restart does not extend the binding. New grants obey audience policy, max_duration and remaining binding lifetime. Expiry denies new calls and cancels admitted remote requests, without rolling back committed effects.

Remote request listing/approval/denial additionally requires the current untagged, unrevoked human portal owner. An unrelated manager or portal admin cannot approve. Owner local CLI/stdio supplies trusted host recovery; reduced local scopes still limit role, app and duration. Guest tools, portal management, original whole-person mutations, global logs/invites and owner receipt tools remain owner-only. The global /events stream is owner-only; reduced roles poll tools.

Audit and denials

Recognized mutations record bounded intent/completion receipts. No raw arguments, targets, credentials or bearer links enter the journal. Missing completion means unknown outcome; history can have drops and crash gaps. Read access history before using receipts as evidence. Scope denials use mcp_scope_denied; hidden tools behave as unknown tools.

Related: Full MCP reference · Portal and requests · Durations.

Sources: TSLink mcp-scopes.md · TSLink remote-mcp.md · TSLink agent-quickstart.md

Table of Contents