TSLinkTSLink Docs

When do you need TSLink? Tailscale alone vs TSLink

Use Tailscale Serve for one app. Compare Services, app names, temporary people access and browser links with TSLink, including setup and limits.

View as Markdown

Scenario guides: Share an app, not your whole machine.

Serve is sufficient for one app on your own devices. Consider TSLink when you want several per-app nodes, HTTP/file people deadlines, gated browser links, a portal and backend health in one host's CLI/MCP workflow. Services and Tailscale's JIT options already solve parts of this.

TSLink documentation and source checked on October 9, 2026, against TSLink v0.1.1; Tailscale sources were accessed on the dates listed below. This comparison does not establish recipient onboarding, live-tailnet behavior or performance.

When Tailscale alone is enough

  • You want your own phone to open one web app; Serve already does that. Serve examples
  • Ports or paths under one device name suit your apps, and the existing access policy suits their users. Serve CLI · Grants syntax · policy syntax
  • You already operate Services with tagged hosts and approvals, especially for resources served by several hosts. Tailscale Services

Private visits need Tailscale on the recipient's device and a policy that permits the connection.

One app from your phone: Serve or share

With the app running and Tailscale and HTTPS ready, tailscale serve 3000 is enough. Serve runs in the foreground; use --bg to keep serving after the terminal closes. Serve CLI · Serve examples.

With TSLink, use tslink share 3000. Enroll the fresh app node, complete device approval if required, and retrieve its exact URL. See first private share and app management.

Ordinary Serve uses ports or paths under the device name. Services supplies separate names and suits resources served by several hosts; configure the services, tagged hosts, endpoints, approvals and policy. TSLink runs an embedded node per app in one host's shared daemon, with enrollment for each fresh node.

JobTailscale aloneTSLink
Open one web app from your own phonetailscale serve 3000 is enough once the app, Tailscale and HTTPS are ready; use --bg to keep serving after the terminal closes. Serve CLI · Serve examplestslink share 3000; a fresh app node needs enrollment, then retrieve its exact URL. Sharing
Three apps, each with its own nameOrdinary Serve uses the device name, with different ports or paths. Services supplies separate names: define services, use a tagged host, configure/advertise endpoints, approve or auto-approve the host, and allow access in policy. Separate Tailscale nodes are another option. Serve CLI · Tailscale Services · Docker parametersOne share --name or add per app; TSLink runs one embedded node per app in a shared daemon. Enroll each fresh node; device approval may apply. Architecture · Getting started
Give one person one app for seven daysInvite them into the tailnet or share the host; restrict access to the app's node/port without broader matching grants. Ordinary network rules have no documented expiry field. Use expiring posture attributes, JIT automation, or scheduled rule removal. Invite any user · Device sharing · Grants syntax · policy syntax · JIT overview · expiring posture attributes and Accessbot · ConductorOne/Opal integrationstslink people add alice@example.com --apps photos --for 7d, for enrolled private HTTP/file apps and the actual Tailscale login. Network access must already exist; outsiders need app invitations. People
A browser link without Tailscale, for three daysFunnel publishes an internet endpoint; the documented CLI has no expiry or visitor-authentication flag. Add application authentication or a gate, and arrange shutdown at the deadline. Funnel CLI · Funnel overviewtslink guest create photos --for 3d --public --print-link, for an online HTTP proxy app with Funnel permission. A bearer gate checks expiry; optional --pin; revoke links individually. Guest links
Revoke access, inspect visits and check app healthRemove all matching permissions or the device share; disable Funnel separately. Configuration and network-flow logs exist; use app logging and backend probes for HTTP request history and app health. Grants syntax · policy syntax · Device sharing · Funnel CLI · Funnel overview · Logging overview · Network flow logs · Docker parameterstslink people remove alice@example.com (whole person), tslink guest revoke <id>, tslink access log --app photos; background backend checks and optional command/webhook notifications. Guest history identifies a link, not a person. Access history · Health
Let an AI agent manage thisThe Tailscale CLI and API automate device/service configuration and policy operations; combine them with your chosen deadline, app-log and health workflow. Serve CLI · Tailscale API · JIT overview · expiring posture attributes and Accessbot · ConductorOne/Opal integrationsManagement commands accept --json; tslink mcp uses JSON-RPC, with owner or reduced app-scoped roles. Human enrollment may still be required. Reduced roles cannot create apps/guest links; roles do not restrict the agent's shell. JSON · MCP scopes

See TSLink architecture and the broader comparison with public tunnels.

One person, one app, until a deadline

Tailscale policy can restrict access to an app's node and port, provided broader matching grants do not permit it. Ordinary network rules have no documented direct expiry field; this is a conclusion from the published grants and policy syntax.

Tailscale already supports automatic deadlines through expiring posture attributes (documented for Premium/Enterprise), its Slack Accessbot example, API automation and third-party integrations. Tailscale PAM, currently beta, also documents scoped, time-bound privileged access. These overlap the temporary-access job. JIT overview · Posture expiry and Accessbot · Integrations · PAM.

For enrolled private HTTP/file apps, tslink people add alice@example.com --apps photos --for 7d checks the person's actual Tailscale login. Network access must already exist. Outsiders need app invitations: add --invite --print-links with a stored user-owned API token, or create app shares manually. Each app needs its own recipient acceptance. An emailed device invite can be accepted by a different Tailscale account, but the TSLink grant checks the actual login. Device sharing.

tslink people remove alice@example.com removes the whole person. Expiry or removal denies subsequent HTTP/file requests; accepted streams and network shares may remain. See people sharing and durations.

Funnel publishes an internet endpoint. Its documented CLI has no expiry or visitor-authentication flag; application authentication or a gate remains possible. Arrange shutdown at the deadline. Funnel CLI · Funnel overview.

For an online HTTP proxy app with Funnel permission, tslink guest create photos --for 3d --public --print-link creates a bearer-gated browser link with expiry. Add an optional --pin, or revoke a link individually with tslink guest revoke <id>.

Guest links are public, forwardable bearer links. A PIN does not establish visitor identity. This browser flow does not establish native-client compatibility. Guest revoke or expiry cancels requests and closes streams; an already authorized bounded request may finish. See guest links.

Access history, backend health and the portal

Tailscale offers configuration and network-flow logs; flow logs are documented for Premium/Enterprise. Use application logging for HTTP request history and backend probes for app health. Docker's /healthz checks whether the node has a tailnet IP, not the backend app response. Logging · Network flow logs · Docker parameters.

tslink access log --app photos shows gateway history; guest history identifies a link, not a person. Background backend checks are available, with optional command/webhook notifications that need configuration. The optional private portal lists permitted apps, addresses, health and deadlines. See access history, health and alerts, and the portal.

What an agent can manage through CLI or MCP

Tailscale's CLI and API automate device/service configuration and policy operations; combine them with your chosen deadline, app-log and health workflow. Serve CLI · Tailscale API · JIT.

TSLink management commands accept --json; tslink mcp uses JSON-RPC, with owner or reduced app-scoped roles. Human enrollment may still be required. Reduced roles cannot create apps or guest links, and roles do not restrict the agent's shell. CLI reference · MCP setup · MCP scopes.

Managing TSLink through local MCP is a different task from exposing an app's MCP endpoint. For the latter, follow MCP server hosting and its client requirements.

  • Install apps, isolate workloads, or provide multi-host failover; app nodes share one publishing host and daemon.
  • Replace tailnet policy or app logins. Raw TCP uses tailnet policy and backend authentication; directly reachable backends and other public routes need their own protection.
  • Make guest links private or verify the visitor's identity. They use public HTTPS and can be forwarded, including with a PIN.

People expiry/removal denies subsequent HTTP/file requests; accepted streams and network shares may remain. Guest revoke/expiry cancels requests and closes streams; an already authorized bounded request may finish. Neither can recall delivered data. Access history records gateway events, not a complete audit of every route to the backend.

For app-specific setup, follow the recipes for Jellyfin, Immich, Home Assistant, Ollama, and Open WebUI. Keep the app's own login; browser access does not establish native-player, mobile backup or upload compatibility. See also task recipes and local AI.

Sources and access dates

TSLink boundaries: product comparison. Product links above are pinned to v0.1.1.

Table of Contents