Skip to content
qwest.devChangelogGet Qwest
Self-hosting, step 3 of 4About an hour in all
  1. Get a server
  2. Install Qwest
  3. Let your team in
  4. Keep it running

Private access with Tailscale

Reach Qwest from anywhere over a private network, with HTTPS, without putting it on the internet.

2 min read

Tailscale connects your team’s devices to the server over a private, encrypted network. Qwest stays invisible to the rest of the internet, and you get an https:// address for free, which phones need to install the app.

Best for: teams who don’t want Qwest on the public internet. Works for VPSs and old PCs alike, even behind a home router.

Sign up at login.tailscale.com. The free plan covers small teams. See Tailscale’s pricing for bigger ones.

Then, in the admin console’s DNS page, make sure MagicDNS and HTTPS Certificates are turned on.

Linux (VPS or old PC):

Terminal window
curl -fsSL https://tailscale.com/install.sh | sh
sudo tailscale up

Open the link it prints and sign in.

Windows or Mac: install the app from tailscale.com/download and sign in.

On the server (on Windows and Mac, in a terminal; drop sudo):

Terminal window
sudo tailscale serve --bg 8080

It prints your address, like https://qwest.tail1234.ts.net. This keeps working after restarts.

In .env (in your qwest folder):

BETTER_AUTH_URL=https://qwest.tail1234.ts.net
QWEST_PORT=127.0.0.1:8080

Then restart:

Terminal window
docker compose up -d
  1. In the Tailscale admin console, Users›Invite users, and invite each teammate.
  2. Each of them installs Tailscale on their computer and phone (tailscale.com/download) and signs in.
  3. They open https://qwest.tail1234.ts.net, and sign up with their Qwest invite link.
  • Studio network only: no Tailscale needed. People open http://192.168.1.42:8080 while in the studio. Phones can’t install the app over http://.
  • Your own VPN (WireGuard, a router’s VPN, ZeroTier…): works the same. Use the server’s VPN address in BETTER_AUTH_URL.