Local LLM · Tailscale

Your local LLM away from home: a private Tailscale client

Reach the LLM server on your home computer from your phone while you are out, over Tailscale or another private VPN, without exposing the engine to the public internet.

Updated
  • Use the compute you already own from another device, with no API credential on local HTTP.
  • Oriveo is a client: your local LLM must run on a computer or server. It does not run the model on your phone.
  • Never expose an unauthenticated engine to the public internet. Use local Wi-Fi or a supported private VPN such as Tailscale; public and mixed DNS targets are rejected.
Oriveo on iPhone: the providers screen, listing the providers you connected and this month’s spend.

Prepare your local LLM server

Start the engine on a private interface, confirm the port locally, then allow that port only on your LAN or private VPN.

  • tailscale ip -4
  • 100.64.0.0/10 · fd7a:115c:a1e0::/48
  • Oriveo → Private VPN

Connect from outside your home network

Choose Local compute in Providers, select the matching engine, enter the private address, and verify the discovered model before saving.

Keep the endpoint private

Never expose an unauthenticated engine to the public internet. Use local Wi-Fi or a supported private VPN such as Tailscale; public and mixed DNS targets are rejected.

Common app questions

Does this require an Oriveo server proxy?
No. Native apps connect directly. The web app uses browser Local Network Access and CORS and does not proxy a private address through Oriveo servers.
Does the model run on the phone?
No. The model runs on your computer or server; the phone is the client.
Which commands and ports are involved?
tailscale ip -4 · 100.64.0.0/10 · fd7a:115c:a1e0::/48 · Oriveo → Private VPN

Related reads

From the blog

Connect your own compute

Get the native Oriveo app on iOS or Android, or open Oriveo in your browser, then connect the engine on your private network.

No API key yet? Oriveo Free lets you start without one.