blitz.cloudBetaDeutschDESign inStart free

Private apps with Tailscale or WireGuard on blitz.cloud

Make an app private on blitz.cloud so only your own devices can open it, through your Tailscale tailnet or your WireGuard network. How to connect, and what changes.

Updated

A private app on blitz.cloud has no public address. Only devices on your own network can open it: your Tailscale tailnet, or a WireGuard network you already run, for example on your router. Connect a network on the Private network page in the dashboard, then switch an app to private in its Settings tab. The free plan connects one network with as many private apps as you like, Pro up to five.

When a private app makes sense

Some apps should never face the internet: a password manager only your family uses, a photo library, an admin panel, a database tool. Making them private removes the public address altogether, so nobody can find them, guess a login or try an exploit against them.

Connect Tailscale

  1. Open Private network in the dashboard and click Connect Tailscale.
  2. Sign in with your Tailscale account. The card updates by itself once you're signed in.
  3. Install Tailscale on your phone or laptop and sign in with the same account, if you haven't already.

Your private apps then join your tailnet as one device. If you'd rather have a name per app, such as http://immich, and a count of your devices, choose "Use an OAuth client instead": create an OAuth client in Tailscale's admin console and paste its secret. blitz.cloud adds the tag its devices need to your tailnet's policy, so you don't have to edit access controls by hand. The dashboard also shows the narrower rights if you prefer to set the tag up yourself.

Connect WireGuard

If you already run a WireGuard server or a router with WireGuard, such as a FRITZ!Box:

  1. Add a new device (a "peer") on your router or VPN server and download its config. Use it only for blitz.cloud, because two devices can't share one config.
  2. On Private network, click Upload config and choose the file.

blitz.cloud joins your network as that device. The config holds a private key; it is stored encrypted and used only to join your network. A config whose router can't be reached from the internet is refused when you upload it, with the reason. That happens behind carrier-grade NAT, which many home connections use, and with IPv6-only connections.

Once connected, open the address shown on the card from a device in your network. It lists all your private apps.

Make an app private

Open the app, go to Settings and switch it to private. What changes:

  • The public address stops working. Instead of Visit, the app shows "Private, on your network".
  • The app no longer sleeps, so it answers straight away when you open it from your network.
  • With Tailscale it gets a stable name on your tailnet. With WireGuard it gets a stable port on the address blitz.cloud has in your network.

Switching it back to public brings the address back.

Disconnect a network

Disconnecting asks what should happen to the apps that depend on the network: make them public again or pause them. Nothing is deleted.

Limits

FreePro
Networks you can connect1Up to 5
Private apps per networkAs many as you likeAs many as you like

You need to confirm your email address before you can connect a network. An AI assistant connected over MCP can list your networks and make an app private or public, but connecting a network stays in the dashboard, because it needs a secret or a config file. See connect an AI assistant.

Put your first app online today.

Free plan, no credit card, no waiting list.

Create a free account