Private access to internal & third-party apps

Self-hosted consoles, vendor admin panels, license-locked tools — publish them to the tailnet instead of the internet.

Your apps, minus the internet

Internal tools don't belong on public IPs with basic auth hoping for the best. Publish them to the tailnet and they become reachable by name — for exactly the people your IdP says should see them, from anywhere, invisible to everyone else.

  • ✓No public IP, no open port, no scanner noise
  • ✓HTTPS with valid certs handled for you
  • ✓Access revoked the moment the IdP says so
published apps — tailnet only
grafanadashboards · group:eng:443PRIVATE
airflowpipelines · group:data:8080PRIVATE
vendor-admin3rd-party · group:ops:443PRIVATE
staging-apicontractors · 30-day grant:443SCOPED

Vendor apps, fronted by your identity

Third-party consoles with IP allowlists and no SSO are a quiet compliance problem. Put a subnet router in front of the vendor and access rides your network with your identity — the vendor never changes a thing and your auditors get real logs.

vendor access — via your mesh
payments-consoleegress: office-gwallowlisted IPYOUR IDENTITY
analytics-suiteegress: vps-frastatic IPYOUR IDENTITY
legacy-erpoffice-licensedworks from homeEXIT NODE

Apps that shouldn't be public

Admin consoles

Grafana, Airflow, internal dashboards — reachable by your team from anywhere, invisible to scanners.

Legacy intranet apps

That one app that only does HTTP? It stays on a private tailnet address; access is identity-gated anyway.

Staging environments

Test instances shared with contractors via scoped tailnet access, not public URLs with basic auth.

Internal APIs

Microservices consumed by both laptops and other services, all on one private network with one policy file.

Vendor panels

Third-party SaaS with IP allowlists or no SSO — front them with a subnet router and your own identity.

License-locked tools

Software licensed to office IPs keeps working from home through an exit node at the office.

Partner integrations

Contractors reach exactly one app for exactly as long as the project runs — then the grant expires.

M&A due-diligence data rooms

Stand up private access to a target's systems in an afternoon, revoke it the day the deal closes.

Auditor access

Grant the external auditor a scoped account for the review window; it evaporates when the engagement ends.

Board portals

Sensitive briefing material on a private address that exists for the meeting, not in some vendor's cloud.

How publishing works

Inside the tailnet (default)

The app keeps its private address; authorized users reach it directly through the mesh with MagicDNS names. No public exposure at all.

Funnel to the internet (opt-in)

Need to share with someone outside the tailnet? Publish a specific service through the funnel with TLS — public only for exactly that path.

Funnel documentation →

Policy examples

# who may reach the Grafana console
acls[{
  action: accept, src: [group:eng],
  dst: [grafana.tailnet.com:443]
}],
# everyone else: denied by default

Secure app access FAQs

Do users need to install anything?
For full tailnet access, yes — the standard client. For apps published through the funnel, a browser is enough: they open a URL and authenticate through your identity provider.
What about apps that only speak HTTP?
They stay on private tailnet addresses as-is. The mesh handles transport encryption; the app itself never needs to learn TLS. Access is identity-gated at the network layer regardless.
Can contractors get access without joining our IdP?
Yes — invite them as tailnet users with scoped grants, or share a funnel link for browser-only access. Either way you see exactly what they touched and can revoke it in one place.
How is this different from a Zero Trust access broker?
Brokers proxy each app through a vendor's cloud. Here the network itself enforces policy — same identity model, no per-app connector to maintain, and your traffic never detours through a third party.
Does it work for apps hosted in the cloud?
Yes — a subnet router in the same VPC publishes cloud-hosted apps to the tailnet, keeping them off the public internet without any VPC peering.

Unpublish your apps

Move one internal tool behind the tailnet today — free in ten minutes.