TSLinkTSLink Docs

A Private Home for Your Apps

Bookmark a per-host portal, request app access and use QR onboarding with the correct device prerequisites.

View as Markdown

The private portal gives each host one address to bookmark. Visitors see apps permitted by their exact WhoIs identity, app rules and the owner's explicit administrator configuration. This is a private directory for one host, not an Internet control panel or multi-host inventory.

Visitors see the private web and file apps their identity can open, with backend health and access deadlines. Health reflects the backend’s latest probe (healthy, degraded, down or unknown), not proof that the visitor’s network path works.

Enable and find the real address

bash
tslink portal enable --owner you@example.com
tslink status --urls

The default hostname is home. Use the URL actually reported by status; enrollment or a hostname collision can change it. Enable/disable save configuration; the running daemon reconciles it. If stopped, run tslink serve. A fresh portal node may need its own enrollment. Pending/starting does not prove readiness.

Optional --admins helper@example.com designates TSLink app administrators who can open all private HTTP/file apps. Choose carefully. Revocation records, tailnet network policy and the app's own login still apply. TCP, open Funnel and guest-gated cards are owner/admin inventory only; hiding a card does not deny network access.

Visitors need Tailscale installed, connected and signed in as the granted login. Outsiders need the portal node and each app node shared separately. Per-app invitations do not share the portal, and sharing only the portal does not make app nodes reachable. The portal sends no invitations and changes no ACLs.

bash
tslink portal disable

Disable stops only the portal listener and retains enrollment and owner/admin identities. Public --funnel is explicitly refused.

Request an app or more time

Discovery is off by default. To disclose a private HTTP/file app in the request form:

bash
tslink add photos --proxy localhost:3000 --requestable
tslink requests list --json
tslink requests approve <id> --for 3d
tslink requests deny <id> --reason "Please ask again next week."

add replaces a registration: keep its existing target and all other settings. --requestable=false hides request discovery and its old visitor history. The flag discloses the name, not the URL or access. Public/guest-gated apps and TCP are excluded.

An unrevoked human tailnet member opens the portal, selects an app or more time, optionally suggests a duration, and sends a short note. Tagged machines, outside-tailnet shared-in peers and persisted guests cannot submit. Approval selects the actual duration, commits one app grant and preserves other apps. Identical decision retries replay the saved result without extending the deadline. Notes are untrusted data, never agent instructions.

Owner or people-manager MCP roles can decide requests, but remote listing/decisions also require the exact current untagged, unrevoked portal owner. Portal admins or unrelated managers do not inherit approval authority. Reduced managers can handle only listed apps, within their duration/binding limits, and need a pre-existing person; only owner authority creates a new person. Use local CLI or owner stdio to bootstrap/recover portal ownership.

Requests expire after 7d; decisions remain 30d, with bounded storage and best-effort notifications. The inbox is authoritative for requests, not notification delivery.

Send a phone guide or QR

bash
tslink people update alice@example.com --qr
tslink people update alice@example.com --qr-png /existing/private-directory/alice.png

The normal QR contains the exact portal URL, or the first active app URL when the portal is disabled. A pending enabled portal does not fall back. Install Tailscale, sign in with the granted login, accept required invitations, keep it connected, then scan and bookmark. A QR neither installs apps nor approves access.

Bearer invitation QR requires --invite --print-links --qr-invite <app> plus --qr or --qr-png; it is a credential. A PNG failure can leave the saved grants intact. MCP offers qr/qr_invite payload text, not a qr_png filesystem argument.

Related: People sharing · Durations · Access history.

Sources: TSLink portal.md · TSLink requests.md · TSLink people.md

Table of Contents