Skip to content
Documentation
Docs/Providers

Tailscale

Expose specific apps on your tailnet, or publish with Funnel.

Setup and sharing

New Tunnel → Your Tailnet (or Share ▾ → Private on Your Tailnet in the menu bar) shares a local server on this Mac's Tailscale name, https://<mac>.<tailnet>.ts.net[:port]. Each app gets its own HTTPS port; only the apps you pick are exposed. Private shares can be opened only by devices signed in to your tailnet. Public on the internet (Funnel) is available when Funnel is enabled for this device in the tailnet's access controls, and is limited to ports 443, 8443, and 10000.

Tailscale itself only proxies to 127.0.0.1. When a server isn't reachable there — for example Vite/Node listening only on ::1, or another machine on the LAN — OpenTraffic runs a small loopback TCP relay and points Tailscale at it; WebSockets and hot reload pass through unchanged.

Shares live in the Tailscale daemon, so OpenTraffic records exactly which port and target it applied (tailscale-shares.json in Application Support) and removes only those on Stop, Remove, and Quit, and on the next launch after a crash. It never runs tailscale serve reset and never changes a port that now points elsewhere. Shares created outside OpenTraffic are listed read-only in Settings → Tailscale, which also shows connection, HTTPS-certificate, and Funnel status with links to the admin console.

The first request on a new port can take around 20 seconds while Tailscale issues the HTTPS certificate; the health checks show this as in progress rather than failed.

Next steps

See Protected shares, Everyday sharing, and Troubleshooting.