Private addresses for your apps, on your Tailscale network.
Open them from your own devices. Share one with a person or a link, until a date you pick.
English · 简体中文 · 日本語 · 한국어 · Español · More languages
tslink share 3000 --name notes # a web app → https://notes.<your-tailnet>.ts.net
tslink share ./photos # a folder or a single file
tslink add db --tcp localhost:5432 # any TCP portmacOS hosts require macOS 13 Ventura or later (platform support).
brew install --cask anydoor7/tap/tslinkLinux .deb and .rpm packages and Windows builds are on the latest release. The first time you share an app, TSLink prints a Tailscale sign-in link for it. Getting started
Serve is enough for one app on your own devices. TSLink puts app addresses, deadlines and access changes in one workflow.
| Job | Tailscale alone | TSLink |
|---|---|---|
| One web app on your phone | tailscale serve 3000 is enough |
tslink share 3000 |
| Several apps, separate names | Services setup, or separate nodes | One share/add per app; enroll each node |
| One person, one app, seven days | Policy rules, then a JIT tool or manual removal | tslink people add alice@example.com --apps photos --for 7d (HTTP/files) |
| Browser link, three days | Public Funnel; add a gate and scheduled shutdown | tslink guest create photos --for 3d --public --print-link (HTTP only) |
Private recipients need Tailscale. Guest links are public, forwardable bearer links.
- An address for each app. Web apps, folders, single files and TCP ports each get their own name in your tailnet, so you use names instead of IP addresses.
- Private by default. Nothing is public until you create a guest link or publish through Funnel.
- One app, not the whole machine. Each app you publish gets its own node that forwards to that app only. Without the Tailscale app on the host, TSLink adds no other host ports to your tailnet.
- A home page that lists your apps with their health. Portal
- Health checks and alerts by command or webhook, and an access log that includes denied requests. Health and alerts · Access history
- Recipes for 15 self-hosted apps, including Home Assistant, Jellyfin, Immich and Ollama.
tslink apps detectfinds the ones already running. App recipes
tslink people add alice@example.com --apps notes --for 7d # a tailnet member, for 7 days
tslink guest create notes --for 3d --public --print-link # a browser link, no Tailscale needed
tslink add launch --proxy localhost:4000 --funnel --public --funnel-ttl 1h # anyone, for one hourGuest links and new public URLs expire and work for web apps only; folders, files and TCP ports stay private. People · Guest links · Public access
A dev server an agent starts on localhost is out of reach from your phone. TSLink lets the agent give it a private address, report the exact URL and remove it when done.
{"mcpServers":{"tslink":{"command":"tslink","args":["mcp"]}}}- CLI or MCP. Management commands take
--jsonand return versioned results;tslink mcpoffers app and access operations over MCP. - One file, not the folder. An agent can share just its HTML report with
tslink share ./report.html; other files in that folder stay unreachable. - Limited roles.
viewer,app-operatororpeople-manager, scoped to the apps you name.tslink mcp-auditshows what an agent changed. Roles limit TSLink's tools, not the agent's own shell.
Agent quickstart · MCP scopes · Remote MCP
One background process runs a separate Tailscale node for each app. Tailscale provides the tailnet transport and HTTPS certificates. Private web and file access can be limited by Tailscale identity with --allow and people grants; raw TCP relies on your tailnet policy and the app's own login. Architecture
| Who | Needs |
|---|---|
| You | A Tailscale account with MagicDNS and HTTPS turned on |
| The machine running your apps | TSLink, which embeds Tailscale (on Linux, a systemd user session) |
| Your devices, and people you share with | The Tailscale app |
| Guests | A browser |
Names of HTTPS apps appear in public certificate logs, so pick names you are happy for others to see.
All docs · CLI reference · Compared with Serve, ngrok and Cloudflare · Contributing · Security
Apache 2.0. TSLink is an independent project, not made or endorsed by Tailscale.