- Get a server
- Install Qwest
- Let your team in
- Keep it running
Private access with Tailscale
Reach Qwest from anywhere over a private network, with HTTPS, without putting it on the internet.
Tailscale connects your team’s devices to the server over a private, encrypted network. Qwest stays invisible to the rest of the internet, and you get an https:// address for free, which phones need to install the app.
Best for: teams who don’t want Qwest on the public internet. Works for VPSs and old PCs alike, even behind a home router.
1. Make a Tailscale account
Section titled “1. Make a Tailscale account”Sign up at login.tailscale.com. The free plan covers small teams. See Tailscale’s pricing for bigger ones.
Then, in the admin console’s DNS page, make sure MagicDNS and HTTPS Certificates are turned on.
2. Put the server on it
Section titled “2. Put the server on it”Linux (VPS or old PC):
curl -fsSL https://tailscale.com/install.sh | shsudo tailscale upOpen the link it prints and sign in.
Windows or Mac: install the app from tailscale.com/download and sign in.
3. Serve Qwest over HTTPS
Section titled “3. Serve Qwest over HTTPS”On the server (on Windows and Mac, in a terminal; drop sudo):
sudo tailscale serve --bg 8080It prints your address, like https://qwest.tail1234.ts.net. This keeps working after restarts.
4. Point Qwest at it
Section titled “4. Point Qwest at it”In .env (in your qwest folder):
BETTER_AUTH_URL=https://qwest.tail1234.ts.netQWEST_PORT=127.0.0.1:8080Then restart:
docker compose up -d5. Bring your team in
Section titled “5. Bring your team in”- In the Tailscale admin console, Users›Invite users, and invite each teammate.
- Each of them installs Tailscale on their computer and phone (tailscale.com/download) and signs in.
- They open
https://qwest.tail1234.ts.net, and sign up with their Qwest invite link.
Other options
Section titled “Other options”- Studio network only: no Tailscale needed. People open
http://192.168.1.42:8080while in the studio. Phones can’t install the app overhttp://. - Your own VPN (WireGuard, a router’s VPN, ZeroTier…): works the same. Use the server’s VPN address in
BETTER_AUTH_URL.