Extension users: Open the Setup Panel (
CursorRemote: Open Setup Panel) and select Specific address (Tailscale / custom) under Networking. Enter your Tailscale IP, click Save & Restart, and you're done. The instructions below cover the full manual setup.
Tailscale creates a private mesh VPN between your devices. Instead of exposing port 3000 to your LAN (or the internet), you access the web app over a Tailscale IP that only your devices can reach. No port forwarding, firewall rules, or DNS configuration required.
- Zero exposure -- the relay server is never reachable from the public internet
- Works across networks -- access from phone on cellular, laptop at a coffee shop, etc.
- No port forwarding -- especially useful for WSL2 where LAN exposure is painful
- End-to-end encrypted -- WireGuard under the hood
- Free tier -- up to 100 devices on the personal plan
Install on the machine (or WSL2 instance) where the relay server runs.
curl -fsSL https://tailscale.com/install.sh | sh
sudo tailscale upFollow the auth URL printed in the terminal to log in.
brew install tailscale
sudo tailscale upwinget install tailscale
tailscale upOR
Download from tailscale.com/download and sign in.
Or install the App Store version.
tailscale ip -4
# prints something like 100.64.1.23- iOS: App Store
- Android: Play Store
Sign in with the same account. Both devices should appear in your Tailscale admin console.
Open http://<tailscale-ip>:3000 on your phone, where <tailscale-ip> is the server's Tailscale IP from step 1 (e.g. http://100.64.1.23:3000).
If you have Tailscale MagicDNS enabled, you can use the machine name instead:
http://my-desktop:3000
By default the server binds to 127.0.0.1 (localhost). To restrict it to Tailscale only:
- Extension: Open Setup Panel > Networking > select "Specific address (Tailscale / custom)" > enter your Tailscale IP > Save & Restart. Or set
cursorRemote.serverHostdirectly in Settings. - Standalone: Set
SERVER_HOSTin.env:
# .env
SERVER_HOST=100.64.1.23 # your Tailscale IPNow the server only listens on the Tailscale interface. Local network and internet connections are rejected at the OS level.
For extra security, combine Tailscale with the webapp password:
- Extension: The password is auto-generated on first install. You can view or change it in the Setup Panel or in Settings (
cursorRemote.webappPassword). - Standalone: Set both in
.env:
# .env
SERVER_HOST=100.64.1.23
WEBAPP_PASSWORD=my-secret-passwordThis way, even if someone joins your Tailscale network, they still need the password.
If you need to share access temporarily without requiring Tailscale on the other device:
tailscale funnel 3000This creates a public HTTPS URL (e.g. https://my-desktop.tail1234.ts.net:443). Stop it with Ctrl+C when done. Combine with WEBAPP_PASSWORD to prevent unauthorized access through the funnel.
- Both devices signed into the same Tailscale account?
tailscale statusshows both devices as connected?- Server running with the correct
SERVER_HOST?
- Install Tailscale inside WSL2, not on the Windows host (unless using mirrored networking)
- If using mirrored networking, you can install Tailscale on Windows and it works for WSL2 too
- Enable MagicDNS in your Tailscale admin console (DNS settings)
- On some phones you may need to restart the Tailscale app after enabling