> ## Documentation Index
> Fetch the complete documentation index at: https://docs.armyofagents.org/llms.txt
> Use this file to discover all available pages before exploring further.

# Tailscale Private Access

Use this when you want to access AoA over Tailscale (or a private LAN/VPN) instead of only `localhost`.

## 1. Start AoA in private authenticated mode

```sh theme={null}
pnpm dev --tailscale-auth
```

This configures:

* `AOA_DEPLOYMENT_MODE=authenticated`
* `AOA_DEPLOYMENT_EXPOSURE=private`
* `AOA_AUTH_BASE_URL_MODE=auto`
* `HOST=0.0.0.0` (bind on all interfaces)

Equivalent flag:

```sh theme={null}
pnpm dev --authenticated-private
```

## 2. Find your reachable Tailscale address

From the machine running AoA:

```sh theme={null}
tailscale ip -4
```

You can also use your Tailscale MagicDNS hostname (for example `my-macbook.tailnet.ts.net`).

## 3. Open AoA from another device

Use the Tailscale IP or MagicDNS host with the AoA port:

```txt theme={null}
http://<tailscale-host-or-ip>:3100
```

Example:

```txt theme={null}
http://my-macbook.tailnet.ts.net:3100
```

## 4. Allow custom private hostnames when needed

If you access AoA with a custom private hostname, add it to the allowlist:

```sh theme={null}
pnpm aoa allowed-hostname my-macbook.tailnet.ts.net
```

## 5. Verify the server is reachable

From a remote Tailscale-connected device:

```sh theme={null}
curl http://<tailscale-host-or-ip>:3100/api/health
```

Expected result:

```json theme={null}
{"status":"ok"}
```

## Troubleshooting

* Login or redirect errors on a private hostname: add it with `aoa allowed-hostname`.
* App only works on `localhost`: make sure you started with `--tailscale-auth` (or set `HOST=0.0.0.0` in private mode).
* Can connect locally but not remotely: verify both devices are on the same Tailscale network and port `3100` is reachable.
