TSLinkTSLink Docs

Share one HTML report privately, with an end date

Share one HTML report privately with named Tailscale users, with access that expires at a deadline. Learn file limits, revocation, and the separate browser guest-link option.

View as Markdown

For a named reader with Tailscale, share the file directly and give the person's actual login access until a deadline. Direct single-file shares cannot receive guest links. Browser-only access requires a separate HTTP proxy workflow with an explicitly public, bearer-gated Funnel edge. See people sharing, guest links and Tailscale Funnel.

Publish exactly one file

Prefer a self-contained report:

bash
tslink share ./report.html --name report --json
tslink url <returned-name> --wait

Save the actual data.name; names can receive suffixes. If sharing returns needs_login, the owner completes the auth_url enrollment and any device approval before fetching the URL. Only the selected file is addressable: adjacent CSS, images and scripts are not served. The contents remain live rather than a frozen copy. See file sharing and enrollment.

Grant a person access until a deadline

Once the app is enrolled, use the person's actual Tailscale login:

bash
tslink people add alice@example.com --apps <returned-name> --until '2026-10-10T18:00:00Z'

Replace the example date with a future deadline at least one hour away. Prefer explicit RFC3339 offsets: dates without offsets use the operator's local time. For an existing active person, use people update, preserving any other desired app grants. See people grants and duration syntax.

Single-file services support people grants. The grant authorizes that person, not the whole tailnet, and its deadline expires the person's access rather than the share itself. Registration persists until removed. The first grant makes the app people-scoped, but existing explicit allow rules and portal owner/admin access can still apply. Configure grants before delivering the address: initial CLI sharing adds no named-reader restriction. See file access, people rules and portal permissions.

Help the recipient open the report

An existing tailnet member's grant needs no stored credential. For an outsider, use people add ... --invite --print-links: automated invites require a user-owned API token, not OAuth. Alternatively, the owner creates the app-node share in Tailscale's console. The recipient installs/signs into Tailscale and accepts that node share; network policy still applies. See people invitations, Tailscale device sharing, iOS, Android and access controls.

Browser-only alternative through a proxy

Direct single-file shares cannot receive guest links. If the recipient needs only a browser, first run a local HTTP server configured to serve only the report, then register its port:

bash
tslink share localhost:8080 --name report-web --json
tslink url <proxy-name> --wait --json
tslink guest create <proxy-name> --for 3d --label 'Report reviewer' --public --print-link --json

Replace <proxy-name> with this share's actual returned name and finish any enrollment. Bring the proxy online before creating the guest link. A generic directory web server would expose its directory's content: TSLink's single-file restriction does not carry over to an arbitrary proxy backend. See proxy targets and guest-link prerequisites.

This deliberately creates an internet-reachable Funnel edge with a mandatory bearer gate. It is a separate public workflow. Recipients need only a browser; link/PIN possession is not verified identity. Links can be forwarded, and an optional PIN may be required. The owner needs HTTPS/Funnel permission. Guest grants need finite deadlines, minimum 1h, with a default maximum of 7d. Verify actual edge availability after creation. See guest links, Tailscale Funnel and HTTPS setup.

Revoke access and remove the share

For private access:

bash
tslink people remove alice@example.com

This revokes the person across private HTTP/file apps. Use scoped MCP people_revoke for one app if appropriate. Already accepted private downloads, streams and WebSockets may finish, and accepted node shares can remain. See people revocation and MCP roles.

For a guest link:

bash
tslink guest revoke <grant-id> --json

The grant ID is data.grant.id in the create result; tslink guest list --json also shows it.

Guest revocation cancels tracked streams, but an already-authorized bounded request may finish. Neither workflow recalls delivered copies. Finally remove the relevant share by its actual name:

bash
tslink remove <returned-name> --json

Stop any separate report server yourself. Removing registration closes the app node after daemon reconciliation; remote device deletion depends on credentials and ownership proof. See guest revocation and app removal.

Official Tailscale sources linked above: accessed 2026-10-07. Product behavior: TSLink v0.1.1.

Table of Contents