---
title: "When do you need TSLink? Tailscale alone vs TSLink"
description: "Use Tailscale Serve for one app. Compare Services, app names, temporary people access and browser links with TSLink, including setup and limits."
url: "https://tslink.md/docs/when-to-use-tslink"
locale: "en"
product_version: "0.1.1"
source: "https://github.com/anydoor7/tslink/blob/v0.1.1/docs/comparison.md"
---

> Documentation index: https://tslink.md/llms.txt · Installed binary is authoritative: `tslink manifest`.

Scenario guides: [Share an app, not your whole machine](https://tslink.md/docs/share-one-app.md).

Serve is sufficient for one app on your own devices. Consider TSLink when you want several per-app nodes, HTTP/file people deadlines, gated browser links, a portal and backend health in one host's CLI/MCP workflow. Services and Tailscale's JIT options already solve parts of this.

TSLink documentation and source checked on **October 9, 2026**, against TSLink v0.1.1; Tailscale sources were accessed on the dates listed below. This comparison does not establish recipient onboarding, live-tailnet behavior or performance.

## When Tailscale alone is enough

* You want your own phone to open one web app; Serve already does that. [Serve examples](https://tailscale.com/docs/reference/examples/serve)
* Ports or paths under one device name suit your apps, and the existing access policy suits their users. [Serve CLI](https://tailscale.com/docs/reference/tailscale-cli/serve) · [Grants syntax](https://tailscale.com/docs/reference/syntax/grants) · [policy syntax](https://tailscale.com/docs/reference/syntax/policy-file)
* You already operate Services with tagged hosts and approvals, especially for resources served by several hosts. [Tailscale Services](https://tailscale.com/docs/features/tailscale-services)

Private visits need Tailscale on the recipient's device and a policy that permits the connection.

## One app from your phone: Serve or share

With the app running and Tailscale and HTTPS ready, `tailscale serve 3000` is enough. Serve runs in the foreground; use `--bg` to keep serving after the terminal closes. [Serve CLI](https://tailscale.com/docs/reference/tailscale-cli/serve) · [Serve examples](https://tailscale.com/docs/reference/examples/serve).

With TSLink, use `tslink share 3000`. Enroll the fresh app node, complete device approval if required, and retrieve its exact URL. See [first private share](https://tslink.md/docs/quickstart.md) and [app management](https://tslink.md/docs/services.md).

## Several apps: ports, paths, Services or TSLink nodes

Ordinary Serve uses ports or paths under the device name. Services supplies separate names and suits resources served by several hosts; configure the services, tagged hosts, endpoints, approvals and policy. TSLink runs an embedded node per app in one host's shared daemon, with enrollment for each fresh node.

| Job                                                | Tailscale alone                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | TSLink                                                                                                                                                                                                                                                                                                                                                                                                               |
| -------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Open one web app from your own phone               | `tailscale serve 3000` is enough once the app, Tailscale and HTTPS are ready; use `--bg` to keep serving after the terminal closes. [Serve CLI](https://tailscale.com/docs/reference/tailscale-cli/serve) · [Serve examples](https://tailscale.com/docs/reference/examples/serve)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | `tslink share 3000`; a fresh app node needs enrollment, then retrieve its exact URL. [Sharing](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/sharing.md)                                                                                                                                                                                                                                                       |
| Three apps, each with its own name                 | Ordinary Serve uses the device name, with different ports or paths. Services supplies separate names: define services, use a tagged host, configure/advertise endpoints, approve or auto-approve the host, and allow access in policy. Separate Tailscale nodes are another option. [Serve CLI](https://tailscale.com/docs/reference/tailscale-cli/serve) · [Tailscale Services](https://tailscale.com/docs/features/tailscale-services) · [Docker parameters](https://tailscale.com/docs/features/containers/docker/docker-params)                                                                                                                                                                                                                                                                                                                           | One `share --name` or `add` per app; TSLink runs one embedded node per app in a shared daemon. Enroll each fresh node; device approval may apply. [Architecture](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/architecture.md) · [Getting started](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/getting-started.md)                                                                                    |
| Give one person one app for seven days             | Invite them into the tailnet or share the host; restrict access to the app's node/port without broader matching grants. Ordinary network rules have no documented expiry field. Use expiring posture attributes, JIT automation, or scheduled rule removal. [Invite any user](https://tailscale.com/docs/features/sharing/how-to/invite-any-user) · [Device sharing](https://tailscale.com/docs/features/sharing) · [Grants syntax](https://tailscale.com/docs/reference/syntax/grants) · [policy syntax](https://tailscale.com/docs/reference/syntax/policy-file) · [JIT overview](https://tailscale.com/docs/features/access-control/just-in-time-access) · [expiring posture attributes and Accessbot](https://tailscale.com/docs/features/tailscale-accessbot-jit) · [ConductorOne/Opal integrations](https://tailscale.com/docs/integrations/jit-access) | `tslink people add alice@example.com --apps photos --for 7d`, for enrolled private HTTP/file apps and the actual Tailscale login. Network access must already exist; outsiders need app invitations. [People](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/people.md)                                                                                                                                         |
| A browser link without Tailscale, for three days   | Funnel publishes an internet endpoint; the documented CLI has no expiry or visitor-authentication flag. Add application authentication or a gate, and arrange shutdown at the deadline. [Funnel CLI](https://tailscale.com/docs/reference/tailscale-cli/funnel) · [Funnel overview](https://tailscale.com/docs/features/tailscale-funnel)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | `tslink guest create photos --for 3d --public --print-link`, for an online HTTP proxy app with Funnel permission. A bearer gate checks expiry; optional `--pin`; revoke links individually. [Guest links](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/guest-links.md)                                                                                                                                        |
| Revoke access, inspect visits and check app health | Remove all matching permissions or the device share; disable Funnel separately. Configuration and network-flow logs exist; use app logging and backend probes for HTTP request history and app health. [Grants syntax](https://tailscale.com/docs/reference/syntax/grants) · [policy syntax](https://tailscale.com/docs/reference/syntax/policy-file) · [Device sharing](https://tailscale.com/docs/features/sharing) · [Funnel CLI](https://tailscale.com/docs/reference/tailscale-cli/funnel) · [Funnel overview](https://tailscale.com/docs/features/tailscale-funnel) · [Logging overview](https://tailscale.com/docs/features/logging) · [Network flow logs](https://tailscale.com/docs/features/logging/network-flow-logs) · [Docker parameters](https://tailscale.com/docs/features/containers/docker/docker-params)                                   | `tslink people remove alice@example.com` (whole person), `tslink guest revoke <id>`, `tslink access log --app photos`; background backend checks and optional command/webhook notifications. Guest history identifies a link, not a person. [Access history](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/access-log.md) · [Health](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/health-and-alerts.md) |
| Let an AI agent manage this                        | The Tailscale CLI and API automate device/service configuration and policy operations; combine them with your chosen deadline, app-log and health workflow. [Serve CLI](https://tailscale.com/docs/reference/tailscale-cli/serve) · [Tailscale API](https://tailscale.com/docs/reference/tailscale-api) · [JIT overview](https://tailscale.com/docs/features/access-control/just-in-time-access) · [expiring posture attributes and Accessbot](https://tailscale.com/docs/features/tailscale-accessbot-jit) · [ConductorOne/Opal integrations](https://tailscale.com/docs/integrations/jit-access)                                                                                                                                                                                                                                                            | Management commands accept `--json`; `tslink mcp` uses JSON-RPC, with owner or reduced app-scoped roles. Human enrollment may still be required. Reduced roles cannot create apps/guest links; roles do not restrict the agent's shell. [JSON](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/json-automation.md) · [MCP scopes](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/mcp-scopes.md)             |

See [TSLink architecture](https://tslink.md/docs/architecture.md) and the [broader comparison with public tunnels](https://tslink.md/docs/comparisons.md).

## One person, one app, until a deadline

Tailscale policy can restrict access to an app's node and port, provided broader matching grants do not permit it. Ordinary network rules have no documented direct expiry field; this is a conclusion from the published [grants](https://tailscale.com/docs/reference/syntax/grants) and [policy syntax](https://tailscale.com/docs/reference/syntax/policy-file).

Tailscale already supports automatic deadlines through expiring posture attributes (documented for Premium/Enterprise), its Slack Accessbot example, API automation and third-party integrations. Tailscale PAM, currently beta, also documents scoped, time-bound privileged access. These overlap the temporary-access job. [JIT overview](https://tailscale.com/docs/features/access-control/just-in-time-access) · [Posture expiry and Accessbot](https://tailscale.com/docs/features/tailscale-accessbot-jit) · [Integrations](https://tailscale.com/docs/integrations/jit-access) · [PAM](https://tailscale.com/docs/privileged-access-management/what-is-tailscale-pam).

For enrolled private HTTP/file apps, `tslink people add alice@example.com --apps photos --for 7d` checks the person's actual Tailscale login. Network access must already exist. Outsiders need app invitations: add `--invite --print-links` with a stored user-owned API token, or create app shares manually. Each app needs its own recipient acceptance. An emailed device invite can be accepted by a different Tailscale account, but the TSLink grant checks the actual login. [Device sharing](https://tailscale.com/docs/features/sharing).

`tslink people remove alice@example.com` removes the whole person. Expiry or removal denies subsequent HTTP/file requests; accepted streams and network shares may remain. See [people sharing](https://tslink.md/docs/people-sharing.md) and [durations](https://tslink.md/docs/durations.md).

## Browser guests: Funnel and expiring links

Funnel publishes an internet endpoint. Its documented CLI has no expiry or visitor-authentication flag; application authentication or a gate remains possible. Arrange shutdown at the deadline. [Funnel CLI](https://tailscale.com/docs/reference/tailscale-cli/funnel) · [Funnel overview](https://tailscale.com/docs/features/tailscale-funnel).

For an online HTTP proxy app with Funnel permission, `tslink guest create photos --for 3d --public --print-link` creates a bearer-gated browser link with expiry. Add an optional `--pin`, or revoke a link individually with `tslink guest revoke <id>`.

Guest links are public, forwardable bearer links. A PIN does not establish visitor identity. This browser flow does not establish native-client compatibility. Guest revoke or expiry cancels requests and closes streams; an already authorized bounded request may finish. See [guest links](https://tslink.md/docs/guest-links.md).

## Access history, backend health and the portal

Tailscale offers configuration and network-flow logs; flow logs are documented for Premium/Enterprise. Use application logging for HTTP request history and backend probes for app health. Docker's `/healthz` checks whether the node has a tailnet IP, not the backend app response. [Logging](https://tailscale.com/docs/features/logging) · [Network flow logs](https://tailscale.com/docs/features/logging/network-flow-logs) · [Docker parameters](https://tailscale.com/docs/features/containers/docker/docker-params).

`tslink access log --app photos` shows gateway history; guest history identifies a link, not a person. Background backend checks are available, with optional command/webhook notifications that need configuration. The optional private portal lists permitted apps, addresses, health and deadlines. See [access history](https://tslink.md/docs/access-history.md), [health and alerts](https://tslink.md/docs/health-and-alerts.md), and the [portal](https://tslink.md/docs/portal-requests.md).

## What an agent can manage through CLI or MCP

Tailscale's CLI and API automate device/service configuration and policy operations; combine them with your chosen deadline, app-log and health workflow. [Serve CLI](https://tailscale.com/docs/reference/tailscale-cli/serve) · [Tailscale API](https://tailscale.com/docs/reference/tailscale-api) · [JIT](https://tailscale.com/docs/features/access-control/just-in-time-access).

TSLink management commands accept `--json`; `tslink mcp` uses JSON-RPC, with owner or reduced app-scoped roles. Human enrollment may still be required. Reduced roles cannot create apps or guest links, and roles do not restrict the agent's shell. [CLI reference](https://tslink.md/docs/commands.md) · [MCP setup](https://tslink.md/docs/mcp-server.md) · [MCP scopes](https://tslink.md/docs/mcp-scopes.md).

Managing TSLink through local MCP is a different task from exposing an app's MCP endpoint. For the latter, follow [MCP server hosting](https://tslink.md/docs/mcp-hosting.md) and its client requirements.

## What TSLink does not cover

* Install apps, isolate workloads, or provide multi-host failover; app nodes share one publishing host and daemon.
* Replace tailnet policy or app logins. Raw TCP uses tailnet policy and backend authentication; directly reachable backends and other public routes need their own protection.
* Make guest links private or verify the visitor's identity. They use public HTTPS and can be forwarded, including with a PIN.

People expiry/removal denies subsequent HTTP/file requests; accepted streams and network shares may remain. Guest revoke/expiry cancels requests and closes streams; an already authorized bounded request may finish. Neither can recall delivered data. Access history records gateway events, not a complete audit of every route to the backend.

For app-specific setup, follow the recipes for [Jellyfin](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/apps.md#jellyfin), [Immich](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/apps.md#immich), [Home Assistant](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/apps.md#home-assistant), [Ollama](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/apps.md#ollama), and [Open WebUI](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/apps.md#open-webui). Keep the app's own login; browser access does not establish native-player, mobile backup or upload compatibility. See also [task recipes](https://tslink.md/docs/use-cases.md) and [local AI](https://tslink.md/docs/local-ai.md).

### Sources and access dates

* [Serve CLI](https://tailscale.com/docs/reference/tailscale-cli/serve), accessed 2026-10-07.
* [Serve examples](https://tailscale.com/docs/reference/examples/serve), accessed 2026-10-07.
* [Tailscale Services](https://tailscale.com/docs/features/tailscale-services), accessed 2026-10-07.
* [Device sharing](https://tailscale.com/docs/features/sharing), accessed 2026-10-07.
* [Invite any user](https://tailscale.com/docs/features/sharing/how-to/invite-any-user), accessed 2026-10-07.
* [Grants syntax](https://tailscale.com/docs/reference/syntax/grants) and [policy syntax](https://tailscale.com/docs/reference/syntax/policy-file), accessed 2026-10-07. No direct network-rule expiry is a schema-based conclusion; posture expiry and app-defined capabilities remain possible.
* [JIT overview](https://tailscale.com/docs/features/access-control/just-in-time-access), [expiring posture attributes and Accessbot](https://tailscale.com/docs/features/tailscale-accessbot-jit), and [ConductorOne/Opal integrations](https://tailscale.com/docs/integrations/jit-access), accessed 2026-10-07.
* [Tailscale PAM](https://tailscale.com/docs/privileged-access-management/what-is-tailscale-pam), accessed 2026-10-07; beta availability is not a tested onboarding path.
* [Funnel CLI](https://tailscale.com/docs/reference/tailscale-cli/funnel) and [Funnel overview](https://tailscale.com/docs/features/tailscale-funnel), accessed 2026-10-07. The no-flag statement is limited to the published CLI reference; application authentication remains possible.
* [Logging overview](https://tailscale.com/docs/features/logging), accessed 2026-10-07.
* [Network flow logs](https://tailscale.com/docs/features/logging/network-flow-logs), accessed 2026-10-07; documented for Premium/Enterprise.
* [Docker parameters](https://tailscale.com/docs/features/containers/docker/docker-params), accessed 2026-10-07. Docker's `/healthz` checks whether the node has a tailnet IP, not the backend app response.
* [Tailscale API](https://tailscale.com/docs/reference/tailscale-api), accessed 2026-10-07.

TSLink boundaries: [product comparison](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/comparison.md#boundaries-that-matter-more-than-a-feature-score). Product links above are pinned to v0.1.1.
