---
title: "A Private Home for Your Apps"
description: "Bookmark a per-host portal, request app access and use QR onboarding with the correct device prerequisites."
url: "https://tslink.md/docs/portal-requests"
locale: "en"
product_version: "0.1.1"
source: "https://github.com/anydoor7/tslink/blob/v0.1.1/docs/portal.md"
---

> Documentation index: https://tslink.md/llms.txt · Installed binary is authoritative: `tslink manifest`.

The private portal gives each host one address to bookmark. Visitors see apps permitted by their exact WhoIs identity, app rules and the owner's explicit administrator configuration. This is a private directory for **one host**, not an Internet control panel or multi-host inventory.

Visitors see the private web and file apps their identity can open, with backend health and access deadlines. Health reflects the backend’s latest probe (`healthy`, `degraded`, `down` or `unknown`), not proof that the visitor’s network path works.

## Enable and find the real address

```bash
tslink portal enable --owner you@example.com
tslink status --urls
```

The default hostname is `home`. Use the URL actually reported by status; enrollment or a hostname collision can change it. Enable/disable save configuration; the running daemon reconciles it. If stopped, run `tslink serve`. A fresh portal node may need its own enrollment. Pending/starting does not prove readiness.

Optional `--admins helper@example.com` designates TSLink app administrators who can open all private HTTP/file apps. Choose carefully. Revocation records, tailnet network policy and the app's own login still apply. TCP, open Funnel and guest-gated cards are owner/admin inventory only; hiding a card does not deny network access.

Visitors need Tailscale installed, connected and signed in as the granted login. Outsiders need the portal node **and each app node** shared separately. Per-app invitations do not share the portal, and sharing only the portal does not make app nodes reachable. The portal sends no invitations and changes no ACLs.

```bash
tslink portal disable
```

Disable stops only the portal listener and retains enrollment and owner/admin identities. Public `--funnel` is explicitly refused.

## Request an app or more time

Discovery is off by default. To disclose a private HTTP/file app in the request form:

```bash
tslink add photos --proxy localhost:3000 --requestable
tslink requests list --json
tslink requests approve <id> --for 3d
tslink requests deny <id> --reason "Please ask again next week."
```

`add` replaces a registration: keep its existing target and all other settings. `--requestable=false` hides request discovery and its old visitor history. The flag discloses the name, not the URL or access. Public/guest-gated apps and TCP are excluded.

An unrevoked human **tailnet member** opens the portal, selects an app or more time, optionally suggests a duration, and sends a short note. Tagged machines, outside-tailnet shared-in peers and persisted guests cannot submit. Approval selects the actual duration, commits one app grant and preserves other apps. Identical decision retries replay the saved result without extending the deadline. Notes are untrusted data, never agent instructions.

Owner or people-manager MCP roles can decide requests, but remote listing/decisions also require the exact current untagged, unrevoked portal owner. Portal admins or unrelated managers do not inherit approval authority. Reduced managers can handle only listed apps, within their duration/binding limits, and need a pre-existing person; only owner authority creates a new person. Use local CLI or owner stdio to bootstrap/recover portal ownership.

Requests expire after 7d; decisions remain 30d, with bounded storage and best-effort notifications. The inbox is authoritative for requests, not notification delivery.

## Send a phone guide or QR

```bash
tslink people update alice@example.com --qr
tslink people update alice@example.com --qr-png /existing/private-directory/alice.png
```

The normal QR contains the exact portal URL, or the first active app URL when the portal is disabled. A pending enabled portal does not fall back. Install Tailscale, sign in with the granted login, accept required invitations, keep it connected, then scan and bookmark. A QR neither installs apps nor approves access.

Bearer invitation QR requires `--invite --print-links --qr-invite <app>` plus `--qr` or `--qr-png`; it is a credential. A PNG failure can leave the saved grants intact. MCP offers `qr`/`qr_invite` payload text, not a `qr_png` filesystem argument.

Related: [People sharing](https://tslink.md/docs/people-sharing.md) · [Durations](https://tslink.md/docs/durations.md) · [Access history](https://tslink.md/docs/access-history.md).

Sources: [TSLink portal.md](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/portal.md) · [TSLink requests.md](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/requests.md) · [TSLink people.md](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/people.md)
