Share one HTML report privately, with an end date
Share one HTML report privately with named Tailscale users, with access that expires at a deadline. Learn file limits, revocation, and the separate browser guest-link option.
Choose named private access or a browser guest link
For a named reader with Tailscale, share the file directly and give the person's actual login access until a deadline. Direct single-file shares cannot receive guest links. Browser-only access requires a separate HTTP proxy workflow with an explicitly public, bearer-gated Funnel edge. See people sharing, guest links and Tailscale Funnel.
Publish exactly one file
Prefer a self-contained report:
tslink share ./report.html --name report --json
tslink url <returned-name> --waitSave the actual data.name; names can receive suffixes. If sharing returns needs_login, the owner completes the auth_url enrollment and any device approval before fetching the URL. Only the selected file is addressable: adjacent CSS, images and scripts are not served. The contents remain live rather than a frozen copy. See file sharing and enrollment.
Grant a person access until a deadline
Once the app is enrolled, use the person's actual Tailscale login:
tslink people add alice@example.com --apps <returned-name> --until '2026-10-10T18:00:00Z'Replace the example date with a future deadline at least one hour away. Prefer explicit RFC3339 offsets: dates without offsets use the operator's local time. For an existing active person, use people update, preserving any other desired app grants. See people grants and duration syntax.
Single-file services support people grants. The grant authorizes that person, not the whole tailnet, and its deadline expires the person's access rather than the share itself. Registration persists until removed. The first grant makes the app people-scoped, but existing explicit allow rules and portal owner/admin access can still apply. Configure grants before delivering the address: initial CLI sharing adds no named-reader restriction. See file access, people rules and portal permissions.
Help the recipient open the report
An existing tailnet member's grant needs no stored credential. For an outsider, use people add ... --invite --print-links: automated invites require a user-owned API token, not OAuth. Alternatively, the owner creates the app-node share in Tailscale's console. The recipient installs/signs into Tailscale and accepts that node share; network policy still applies. See people invitations, Tailscale device sharing, iOS, Android and access controls.
Browser-only alternative through a proxy
Direct single-file shares cannot receive guest links. If the recipient needs only a browser, first run a local HTTP server configured to serve only the report, then register its port:
tslink share localhost:8080 --name report-web --json
tslink url <proxy-name> --wait --json
tslink guest create <proxy-name> --for 3d --label 'Report reviewer' --public --print-link --jsonReplace <proxy-name> with this share's actual returned name and finish any enrollment. Bring the proxy online before creating the guest link. A generic directory web server would expose its directory's content: TSLink's single-file restriction does not carry over to an arbitrary proxy backend. See proxy targets and guest-link prerequisites.
This deliberately creates an internet-reachable Funnel edge with a mandatory bearer gate. It is a separate public workflow. Recipients need only a browser; link/PIN possession is not verified identity. Links can be forwarded, and an optional PIN may be required. The owner needs HTTPS/Funnel permission. Guest grants need finite deadlines, minimum 1h, with a default maximum of 7d. Verify actual edge availability after creation. See guest links, Tailscale Funnel and HTTPS setup.
Revoke access and remove the share
For private access:
tslink people remove alice@example.comThis revokes the person across private HTTP/file apps. Use scoped MCP people_revoke for one app if appropriate. Already accepted private downloads, streams and WebSockets may finish, and accepted node shares can remain. See people revocation and MCP roles.
For a guest link:
tslink guest revoke <grant-id> --jsonThe grant ID is data.grant.id in the create result; tslink guest list --json also shows it.
Guest revocation cancels tracked streams, but an already-authorized bounded request may finish. Neither workflow recalls delivered copies. Finally remove the relevant share by its actual name:
tslink remove <returned-name> --jsonStop any separate report server yourself. Removing registration closes the app node after daemon reconciliation; remote device deletion depends on credentials and ownership proof. See guest revocation and app removal.
Official Tailscale sources linked above: accessed 2026-10-07. Product behavior: TSLink v0.1.1.
Agent UI from your phone
Open a coding-agent UI or dev server on your phone through TSLink. Set up private access, verify the URL, and remove the share when done.
Share one app
Share one localhost app over Tailscale through its own TSLink node. See what each node exposes and what changes if the host also runs Tailscale.