Take the full DST portal with you
DST stays local-only by default. When you choose remote access, the same responsive portal can run on a phone, tablet, or another PC through a stable HTTPS address. Optional host-managed accounts replace credential-bearing links with normal sign-in and enforce Owner/Admin boundaries in both navigation and APIs.
Your control room, on a smaller screen.
Open the same responsive Browser Portal in your device's browser. Account login uses host-created credentials, not a password hidden in the shared link.
New setups use Tailscale Funnel. Existing Cloudflare configuration remains available but its legacy portal is disabled by default. Keep it disabled unless you explicitly need it.
Start with Tailscale Funnel1 · What each role can access
The Browser Portal is the normal DST AppShell, not a reduced companion dashboard. It uses the same pages, responsive navigation, and updates as the desktop portal. Host-only safeguards still apply.
Owner
Trusted remote administration across the full portal except host-local surfaces such as PowerShell, Solo Mode, Setup, local paths, credentials, SSH controls, and local client configuration.
Admin
Operational access to server health, pods, approved Commands, Gameplay Admin, Broadcasts, DD Atlas, and Map Management. Game Config, Experimental, Database, Sietches, and Settings remain unavailable.
Only the host can create, promote, demote, disable, reset, or delete Browser Portal accounts. Users cannot self-register.
2 · How access is protected
- A public HTTPS transport forwards to DST's loopback-only bridge on 127.0.0.1:47900. No router port-forward or inbound Windows Firewall rule is required.
- Account mode uses host-created usernames, PBKDF2-HMAC-SHA256 password hashes, forced replacement of one-time passwords, opaque server-side sessions, lockouts, origin checks, and immediate revocation.
- The shared QR/link becomes a stable token-free address after account mode is enabled. A username or password is still required, so the address itself is not an administrator credential.
- Owner/Admin authorization is enforced by backend routes as well as the visible navigation. Hiding a page is not the security boundary.
Until account mode is enabled, DST preserves the legacy magic-link flow. Enabling account mode invalidates those browser sessions and retires paired native iOS/Android apps, whose token header cannot be safely distinguished from a browser request.
3 · Recommended: Tailscale Funnel — no domain required
Install Tailscale on the DST PC
Download it from tailscale.com/download and sign in. A personal account is enough for one host.
Enable Funnel on the bridge
Run in PowerShell on the DST PC:
tailscale funnel --bg http://127.0.0.1:47900
Follow Tailscale's one-time enablement link if it prints one, then run the command again. Funnel works behind CGNAT and does not carry Dune game traffic.
Confirm Remote Device Access
Open Settings → Remote Device Access. DST should show the stable .ts.net address and a ready local bridge.
4 · Create Browser Portal accounts
- In Settings → Remote Device Access, create the first Owner.
- Copy and store the one-time password. DST cannot reveal it again.
- Verify that Owner password locally on the host.
- Acknowledge native-app retirement, then enable account login.
- Create additional Owner or Admin accounts as needed.
Account roles can be changed in place without changing the username or password. Password reset revokes that account's existing sessions. Hosts can also revoke sessions, disable an account, or delete it.
5 · Open the portal on a phone, tablet, or PC
- Scan the QR with the device's normal camera, or open the copied Browser Portal link.
- Sign in with the account and one-time password supplied privately by the host.
- Create a permanent password when prompted.
- Use Remember me only on a trusted personal device.
Save it like an app
On iPhone or iPad, open the portal in Safari and choose Share → Add to Home Screen. On Android, open it in Chrome and choose Add to Home screen or Install app. The icon opens the responsive Browser Portal; no separate DST mobile app is required.
6 · Migrate an existing Cloudflare domain — deprecated
v15 retains existing Cloudflare named-tunnel/Access configuration, but its legacy portal is disabled by default. It can be explicitly re-enabled in local Settings if needed, but new setups use Tailscale Funnel. DST does not manage the Cloudflare tunnel itself.
- Run tailscale funnel --bg http://127.0.0.1:47900 in PowerShell.
- Confirm the .ts.net URL appears in Remote Device Access.
- Under Browser Portal accounts, create and locally verify an Owner.
- Acknowledge native-app retirement, then enable account login.
- Create any Browser Portal Admin account needed for role-boundary testing.
- Test Owner sign-in and Admin restricted navigation from outside the LAN.
- Leave the legacy Cloudflare portal disabled in local Settings unless you explicitly need to restore it.
7 · Troubleshooting
No remote address appears
Confirm tailscale funnel status lists the proxy to 127.0.0.1:47900, then refresh Remote Device Access.
The device cannot reach DST
DST or its background service must be running on the host. Reopen the current QR/link if the public hostname changed.
The one-time password does not work
The host can reset that account's password in local Settings. The reset creates a new one-time password and revokes existing sessions.
Password change reports a security check failure
Reopen the current Browser Portal QR or stable link so the request uses the configured HTTPS authority, then sign in and try again.
8 · Disable or revoke access
- One device: sign out, or revoke that account's sessions from local Settings.
- One account: disable, reset, demote, or delete it from Browser Portal account management.
- All account sessions: use the local emergency Disable action. This restores legacy magic-link behavior.
- Public endpoint: turn off Funnel. Legacy Cloudflare portal enablement is separate from its tunnel lifecycle, which DST does not manage.
- Background access: disable Help → Keep serving while DST is closed.