localhost.
1. Start Paperclip in private authenticated mode
PAPERCLIP_DEPLOYMENT_MODE=authenticatedPAPERCLIP_DEPLOYMENT_EXPOSURE=privatePAPERCLIP_BIND=tailnet
authenticated/private + bind=lan:
pnpm dev —authenticated-private
pnpm dev —tailscale-auth
my-macbook.tailnet.ts.net).
3. Open Paperclip from another device
Use the Tailscale IP or MagicDNS host with the Paperclip port:4. Allow custom private hostnames when needed
If you access Paperclip with a custom private hostname, add it to the allowlist:5. Verify the server is reachable
From a remote Tailscale-connected device:Troubleshooting
- Login or redirect errors on a private hostname: add it with
paperclipai allowed-hostname. - App only works on
localhost: make sure you started with--bind lanor--bind tailnetinstead of plainpnpm dev. - Can connect locally but not remotely: verify both devices are on the same Tailscale network and port
3100is reachable.