{"name":"io.github.itunified-io/tailscale","slug":"itunified-io-tailscale","title":"Tailscale MCP Server","description":"Secure MCP access for private infrastructure over Tailscale — 48 tools across 9 domains","url":"https://mcp.market/server/itunified-io-tailscale","rating":null,"grade":"C","score":65,"certified":false,"status":"active","category":"other","tags":[],"presence":{"score":10,"stars":null,"forks":null,"downloads_week":109,"last_push_at":null,"license":"AGPL-3.0-only"},"uptime":null,"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/itunified-io/mcp-tailscale","website":null,"version":"2026.3.16","remotes":[],"packages":[{"registryType":"npm","identifier":"tailscale-mcp","version":"2026.3.16","runtimeHint":"npx","transport":{"type":"stdio"},"environmentVariables":[{"description":"Tailscale API key","name":"TAILSCALE_API_KEY"},{"description":"OAuth client ID (alternative to API key)","name":"TAILSCALE_OAUTH_CLIENT_ID"},{"description":"OAuth client secret","name":"TAILSCALE_OAUTH_CLIENT_SECRET"},{"description":"Tailnet name","name":"TAILSCALE_TAILNET"}]}],"tools":[{"name":"tailscale_acl_get","description":"Get the current ACL policy for the tailnet as JSON. Returns the full policy including rules, groups, hosts, and tag owners.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_acl_preview","description":"Preview what the ACL policy would allow for a specific user or IP. Useful for testing before applying changes.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_acl_set","description":"Set (replace) the ACL policy for the tailnet. Requires confirm: true. The entire policy is replaced — provide the complete policy.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_acl_test","description":"Run ACL tests defined in the policy's 'tests' field by validating the policy. Returns validation results including test pass/fail outcomes.","write_action":true,"price_micros":0,"input_schema":null},{"name":"tailscale_acl_validate","description":"Validate an ACL policy without applying it. Returns any errors or warnings found in the policy.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_api_verify","description":"Verify API connectivity and authentication by making a lightweight request to the Tailscale API.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_derp_map","description":"Get the DERP relay map for the tailnet. Shows all DERP regions and their relay nodes used for traffic routing.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_device_authorize","description":"Authorize a device that is pending approval. Sets the device's authorized status to true.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_device_delete","description":"Delete a device from the tailnet. This removes the device and revokes its access. Requires confirm: true.","write_action":true,"price_micros":0,"input_schema":null},{"name":"tailscale_device_expire","description":"Expire a device's key, forcing it to re-authenticate. The device remains in the tailnet but loses connectivity until re-authenticated. This is one-directional — once expired, the device must re-auth. Requires confirm: true.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_device_get","description":"Get details of a specific device by its ID.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_device_list","description":"List all devices in the tailnet. Returns all registered devices with their IP addresses, hostname, OS, and connection status.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_device_posture_get","description":"Get custom posture attributes for a device. Returns all key-value posture attributes.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_device_posture_set","description":"Set a custom posture attribute on a device. Creates or updates a single attribute key-value pair.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_device_rename","description":"Set a custom display name for a device. This changes the device's 'given name' in Tailscale, not the machine hostname.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_device_routes_get","description":"Get the advertised and enabled subnet routes for a device.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_device_routes_set","description":"Set the enabled subnet routes for a device. Replaces the current set of enabled routes.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_device_tags_set","description":"Set ACL tags on a device. Replaces all existing tags. Use an empty array to remove all tags.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_dns_nameservers_get","description":"Get the global DNS nameservers configured for the tailnet. Also returns whether MagicDNS is enabled.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_dns_nameservers_set","description":"Set the global DNS nameservers for the tailnet. Replaces all existing nameservers.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_dns_preferences_get","description":"Get DNS preferences for the tailnet, including MagicDNS status.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_dns_preferences_set","description":"Set DNS preferences for the tailnet. Toggle MagicDNS on or off.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_dns_searchpaths_get","description":"Get the DNS search paths configured for the tailnet.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_dns_searchpaths_set","description":"Set the DNS search paths for the tailnet. Replaces all existing search paths.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_dns_splitdns_get","description":"Get the split DNS configuration for the tailnet. Returns a map of domain names to their resolver IP addresses.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_dns_splitdns_set","description":"Update split DNS configuration for the tailnet using a PATCH operation. Provide a map of domain names to resolver IP addresses. Use null values to remove a domain.","write_action":true,"price_micros":0,"input_schema":null},{"name":"tailscale_key_create","description":"Create a new auth key for the tailnet. Returns the key value — store it securely as it cannot be retrieved again.","write_action":true,"price_micros":0,"input_schema":null},{"name":"tailscale_key_delete","description":"Delete (revoke) an auth key. Devices already authenticated with this key will not be affected. Requires confirm: true.","write_action":true,"price_micros":0,"input_schema":null},{"name":"tailscale_key_get","description":"Get details of a specific auth key by its ID.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_key_list","description":"List all auth keys for the tailnet. Returns key metadata (but not the secret key values).","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_log_stream_get","description":"Get the current log streaming configuration for the tailnet. Log types: 'configuration' or 'network'.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_log_stream_set","description":"Configure log streaming for the tailnet. Requires confirm: true. Streams logs to a specified URL endpoint.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_posture_integration_create","description":"Create a new third-party posture provider integration. Supported providers: crowdstrike, falcon, intune, jamfPro, kandji, kolide, sentinelone. Required fields depend on the provider.","write_action":true,"price_micros":0,"input_schema":null},{"name":"tailscale_posture_integration_delete","description":"Delete a posture provider integration. Requires confirm: true.","write_action":true,"price_micros":0,"input_schema":null},{"name":"tailscale_posture_integration_get","description":"Get details for a specific posture provider integration by ID.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_posture_integration_list","description":"List all configured third-party posture provider integrations for the tailnet (e.g., CrowdStrike, Intune, Jamf).","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_status","description":"Get a summary of the tailnet status including total device count, online/offline counts, and last-seen timestamps.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_tailnet_contacts_get","description":"Get the contact email addresses configured for the tailnet (account, support, and security contacts).","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_tailnet_contacts_set","description":"Update contact email addresses for the tailnet. Requires confirm: true. Provide any combination of account, support, or security contacts.","write_action":true,"price_micros":0,"input_schema":null},{"name":"tailscale_tailnet_lock_status","description":"Get the Tailnet Lock status. Tailnet Lock allows requiring cryptographic signatures on all node key registrations.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_tailnet_settings_get","description":"Get the tailnet settings including device approval, auto-updates, key expiry, and posture identity collection.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_tailnet_settings_update","description":"Update tailnet settings. Requires confirm: true. All settings fields are optional — only provided fields will be updated.","write_action":true,"price_micros":0,"input_schema":null},{"name":"tailscale_user_get","description":"Get details for a specific user by their user ID. Returns display name, login, role, status, device count, and last seen.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_user_list","description":"List all users in the tailnet. Optionally filter by type (member/shared) or role (owner/admin/member/auditor/it-admin/network-admin/billing-admin).","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_webhook_create","description":"Create a new webhook endpoint. Returns the webhook including the signing secret (only shown once). Event types: nodeCreated, nodeApproved, nodeNeedsApproval, nodeKeyExpiringInOneDay, nodeKeyExpired, nodeDeleted, policyUpdate, userCreated, userDeleted, userApproved, userSuspended, userRestored, userRoleUpdated, subnetIPForwardingNotEnabled, exitNodeIPForwardingNotEnabled.","write_action":true,"price_micros":0,"input_schema":null},{"name":"tailscale_webhook_delete","description":"Delete a webhook endpoint. Requires confirm: true.","write_action":true,"price_micros":0,"input_schema":null},{"name":"tailscale_webhook_get","description":"Get details for a specific webhook endpoint by ID.","write_action":false,"price_micros":0,"input_schema":null},{"name":"tailscale_webhook_list","description":"List all webhook endpoints configured for the tailnet.","write_action":false,"price_micros":0,"input_schema":null}],"scan":{"score":65,"grade":"C","scanned_at":"2026-09-27T23:37:35.654Z","report":{"scannerVersion":"0.1.10","scannedAt":"2026-09-27T23:37:35.617Z","components":{"code":{"score":25,"max":25,"notes":["37 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":12,"max":15,"notes":["local package, no credentials required"]},"maintenance":{"score":3,"max":15,"notes":["repository not readable: repo not found"]},"identity":{"score":2,"max":10,"notes":["no repository or website to verify"]}},"findings":[],"inputs":{"packages":[{"registryType":"npm","identifier":"tailscale-mcp","version":"2026.3.16","found":true,"license":"AGPL-3.0-only","hasInstallScripts":false,"dependencyCount":4,"publishedAt":"2026-03-15T09:05:16.589Z","repositoryUrl":"git+https://github.com/itunified-io/mcp-tailscale.git","weeklyDownloads":109}],"repo":{"found":false,"owner":"itunified-io","repo":"mcp-tailscale","error":"repo not found"},"icon":{"url":null,"source":"none"},"presence":{"stars":null,"forks":null,"downloadsWeek":109,"license":"AGPL-3.0-only","lastPushAt":null,"score":10}}}},"grade_history":[],"reviews":[]}