Share an App with a Person and a Deadline
Share a self-hosted app privately for seven days, invite someone outside your tailnet, and revoke access.
Scenario guides: Share one HTML report privately, with an end date.
TSLink can grant one person access to selected private HTTP apps or files until a deadline. The recipient uses their actual Tailscale login; an outsider accepts an invitation for each app. The application stays on your computer and keeps its own login.
Recipients can install Tailscale from the official downloads: iPhone/iPad, Android, Mac, or all platforms.
1. Register and enroll your app
Install TSLink, then install and start your application separately. For a running Jellyfin server, preview its recipe before applying it:
tslink apps share jellyfin --allow you@example.com
tslink apps share jellyfin --allow you@example.com --yes
tslink url jellyfin --waitReplace you@example.com with your own Tailscale login. Check the recipe's app-side settings and use the actual host port if it differs from the default. Keep Jellyfin login enabled. Recipes register the route; they do not install or configure the app. Complete any browser enrollment or admin device approval before opening the exact returned URL.
2. Give a tailnet member seven days
tslink people add alice@example.com --apps jellyfin --for 7d
tslink people list --jsonUse Alice's actual Tailscale login, which may differ from her contact email. No stored API credential is needed for these local grants. The daemon must run a compatible version, and tailnet policy must permit reaching the app.
The first people grant makes this app person-scoped: unlisted callers need an active grant or an explicit legacy --allow rule. The owner rule above keeps your own access. For a known untagged person, their grants override legacy allow rules: expiry or loss of an app denies new requests. Tagged machines cannot use a person's grant.
To shorten the same person's app set and lifetime:
tslink people update alice@example.com --apps jellyfin --for 1hAn update with only --apps preserves deadlines on retained apps and gives newly added apps a 24h deadline. Supply --for to set the lifetime for every selected app. --apps all selects currently registered private HTTP/file apps only; future apps are not included.
3. Invite someone outside your tailnet
For a new person outside the tailnet:
tslink people add bob@example.com --apps jellyfin --for 7d --invite --print-linksCreating invitations needs a stored user-owned Tailscale API access token; OAuth client tokens cannot create device invites. Store it through the stdin login path, keeping it out of arguments and public logs.
Send the generated message yourself. TSLink requests links rather than sending an email. Bob installs Tailscale, signs in with the named account, accepts each app's link, and keeps Tailscale connected. Several apps mean several accepts. Holding the link does not authorize a different login.
Invitation links are bearer capabilities. --print-links explicitly reveals them; otherwise URLs stay hidden. The registry records IDs and states, never invitation URLs or tokens.
A bundle can partially fail while local grants remain saved. Inspect complete, per-app code and state. Resume unfinished work with tslink people update bob@example.com --invite; completed operations reuse their IDs. An unknown POST outcome needs owner-verified reconciliation, not a blind retry. See the TSLink people guide for recovery.
4. End access early
tslink people remove alice@example.comRemoval saves local denial first, then attempts cleanup of recorded pending invitations. Without a token, local denial still works and cleanup can remain incomplete. Accepted Tailscale device shares may need separate network management.
Expiry and removal block new private HTTP/file requests, including new WebSocket upgrades. Accepted streams and WebSocket connections can finish; downloaded data cannot be recalled. TCP and public Funnel cannot be person-scoped. Removing a person also keeps a deny record across private HTTP/file apps; it does not revoke tailnet membership.
Can someone use only a browser?
Private people sharing requires Tailscale. Browser guest links now offer one HTTP proxy app with a finite deadline and optional PIN through explicitly public Funnel and a mandatory guest gate. Links/PINs can be forwarded and do not prove identity. Open Funnel is a separate publication with no TSLink visitor identity gate; new public exposure defaults to 24h and refuses never.
Related: Local AI · Agent/MCP setup · Choose a sharing tool.
Sources: TSLink sharing boundaries, people guide.
A home address, QR and renewals
Enable the private per-host portal, then use people add/update --qr or --qr-png <existing-directory/file.png> for the exact address. Tailscale installation, correct login, device shares and policy permission remain prerequisites. One QR does not install apps or approve access; outsiders need the portal node shared separately from app nodes.
New people grants default to 24h. Flexible durations support relative/absolute deadlines, minimum 1h. Invitation history uses guest policy with a default 7d maximum; member permanent grants require --for never --ack-never. Use tslink extend jellyfin --person alice@example.com --for 36h for one app; expired grants require --regrant. Open Funnel/TCP cannot be person-scoped; guest-gated apps retain people rules on the private listener. Inspect access history for retained requests and lifecycle receipts.