Skip to main content

Tailscale Private Access

Use this when you want to access Vagaris over Tailscale (or a private LAN/VPN) instead of only localhost.

1. Start Vagaris in private authenticated mode​

pnpm dev --bind tailnet

Recommended behavior:

  • PAPERCLIP_DEPLOYMENT_MODE=authenticated
  • PAPERCLIP_DEPLOYMENT_EXPOSURE=private
  • PAPERCLIP_BIND=tailnet

If you want the old broad private-network behavior instead, use:

pnpm dev --bind lan

Legacy aliases still map to authenticated/private + bind=lan:

pnpm dev --authenticated-private
pnpm dev --tailscale-auth

2. Find your reachable Tailscale address​

From the machine running Vagaris:

tailscale ip -4

You can also use your Tailscale MagicDNS hostname (for example my-macbook.tailnet.ts.net).

3. Open Vagaris from another device​

Use the Tailscale IP or MagicDNS host with the Vagaris port:

http://<tailscale-host-or-ip>:3100

Example:

http://my-macbook.tailnet.ts.net:3100

4. Allow custom private hostnames when needed​

If you access Vagaris with a custom private hostname, add it to the allowlist:

vagaris allowed-hostname my-macbook.tailnet.ts.net

5. Verify the server is reachable​

From a remote Tailscale-connected device:

curl http://<tailscale-host-or-ip>:3100/api/health

Expected result:

{"status":"ok"}

Troubleshooting​

  • Login or redirect errors on a private hostname: add it with vagaris allowed-hostname.
  • App only works on localhost: make sure you started with vagaris run --bind lan or vagaris run --bind tailnet instead of plain pnpm dev.
  • Can connect locally but not remotely: verify both devices are on the same Tailscale network and port 3100 is reachable.