Tailscale MCP Server
Secure MCP access for private infrastructure over Tailscale — 48 tools across 9 domains
109 downloads/wk
Reviews
Write oneNobody has reviewed Tailscale MCP Server yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Tailscale MCP Server tools (48, 11 write)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
tailscale_acl_getGet the current ACL policy for the tailnet as JSON. Returns the full policy including rules, groups, hosts, and tag owners.
tailscale_acl_previewPreview what the ACL policy would allow for a specific user or IP. Useful for testing before applying changes.
tailscale_acl_setSet (replace) the ACL policy for the tailnet. Requires confirm: true. The entire policy is replaced — provide the complete policy.
tailscale_acl_testwrite actionRun ACL tests defined in the policy's 'tests' field by validating the policy. Returns validation results including test pass/fail outcomes.
tailscale_acl_validateValidate an ACL policy without applying it. Returns any errors or warnings found in the policy.
tailscale_api_verifyVerify API connectivity and authentication by making a lightweight request to the Tailscale API.
tailscale_derp_mapGet the DERP relay map for the tailnet. Shows all DERP regions and their relay nodes used for traffic routing.
tailscale_device_authorizeAuthorize a device that is pending approval. Sets the device's authorized status to true.
tailscale_device_deletewrite actionDelete a device from the tailnet. This removes the device and revokes its access. Requires confirm: true.
tailscale_device_expireExpire a device's key, forcing it to re-authenticate. The device remains in the tailnet but loses connectivity until re-authenticated. This is one-directional — once expired, the device must re-auth. Requires confirm: true.
tailscale_device_getGet details of a specific device by its ID.
tailscale_device_listList all devices in the tailnet. Returns all registered devices with their IP addresses, hostname, OS, and connection status.
tailscale_device_posture_getGet custom posture attributes for a device. Returns all key-value posture attributes.
tailscale_device_posture_setSet a custom posture attribute on a device. Creates or updates a single attribute key-value pair.
tailscale_device_renameSet a custom display name for a device. This changes the device's 'given name' in Tailscale, not the machine hostname.
tailscale_device_routes_getGet the advertised and enabled subnet routes for a device.
tailscale_device_routes_setSet the enabled subnet routes for a device. Replaces the current set of enabled routes.
tailscale_device_tags_setSet ACL tags on a device. Replaces all existing tags. Use an empty array to remove all tags.
tailscale_dns_nameservers_getGet the global DNS nameservers configured for the tailnet. Also returns whether MagicDNS is enabled.
tailscale_dns_nameservers_setSet the global DNS nameservers for the tailnet. Replaces all existing nameservers.
tailscale_dns_preferences_getGet DNS preferences for the tailnet, including MagicDNS status.
tailscale_dns_preferences_setSet DNS preferences for the tailnet. Toggle MagicDNS on or off.
tailscale_dns_searchpaths_getGet the DNS search paths configured for the tailnet.
tailscale_dns_searchpaths_setSet the DNS search paths for the tailnet. Replaces all existing search paths.
tailscale_dns_splitdns_getGet the split DNS configuration for the tailnet. Returns a map of domain names to their resolver IP addresses.
tailscale_dns_splitdns_setwrite actionUpdate split DNS configuration for the tailnet using a PATCH operation. Provide a map of domain names to resolver IP addresses. Use null values to remove a domain.
tailscale_key_createwrite actionCreate a new auth key for the tailnet. Returns the key value — store it securely as it cannot be retrieved again.
tailscale_key_deletewrite actionDelete (revoke) an auth key. Devices already authenticated with this key will not be affected. Requires confirm: true.
tailscale_key_getGet details of a specific auth key by its ID.
tailscale_key_listList all auth keys for the tailnet. Returns key metadata (but not the secret key values).
tailscale_log_stream_getGet the current log streaming configuration for the tailnet. Log types: 'configuration' or 'network'.
tailscale_log_stream_setConfigure log streaming for the tailnet. Requires confirm: true. Streams logs to a specified URL endpoint.
tailscale_posture_integration_createwrite actionCreate a new third-party posture provider integration. Supported providers: crowdstrike, falcon, intune, jamfPro, kandji, kolide, sentinelone. Required fields depend on the provider.
tailscale_posture_integration_deletewrite actionDelete a posture provider integration. Requires confirm: true.
tailscale_posture_integration_getGet details for a specific posture provider integration by ID.
tailscale_posture_integration_listList all configured third-party posture provider integrations for the tailnet (e.g., CrowdStrike, Intune, Jamf).
tailscale_statusGet a summary of the tailnet status including total device count, online/offline counts, and last-seen timestamps.
tailscale_tailnet_contacts_getGet the contact email addresses configured for the tailnet (account, support, and security contacts).
tailscale_tailnet_contacts_setwrite actionUpdate contact email addresses for the tailnet. Requires confirm: true. Provide any combination of account, support, or security contacts.
tailscale_tailnet_lock_statusGet the Tailnet Lock status. Tailnet Lock allows requiring cryptographic signatures on all node key registrations.
tailscale_tailnet_settings_getGet the tailnet settings including device approval, auto-updates, key expiry, and posture identity collection.
tailscale_tailnet_settings_updatewrite actionUpdate tailnet settings. Requires confirm: true. All settings fields are optional — only provided fields will be updated.
tailscale_user_getGet details for a specific user by their user ID. Returns display name, login, role, status, device count, and last seen.
tailscale_user_listList all users in the tailnet. Optionally filter by type (member/shared) or role (owner/admin/member/auditor/it-admin/network-admin/billing-admin).
tailscale_webhook_createwrite actionCreate a new webhook endpoint. Returns the webhook including the signing secret (only shown once). Event types: nodeCreated, nodeApproved, nodeNeedsApproval, nodeKeyExpiringInOneDay, nodeKeyExpired, nodeDeleted, policyUpdate, userCreated, userDeleted, userApproved, userSuspended, userRestored, userRoleUpdated, subnetIPForwardingNotEnabled, exitNodeIPForwardingNotEnabled.
tailscale_webhook_deletewrite actionDelete a webhook endpoint. Requires confirm: true.
tailscale_webhook_getGet details for a specific webhook endpoint by ID.
tailscale_webhook_listList all webhook endpoints configured for the tailnet.
Public scan report
scanner v0.1.10 · 2026-09-27 · same rubric, same numbers if you re-run it
- Code scan37 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancerepository not readable: repo not found3/15
- Maintainer identityno repository or website to verify2/10
Install Tailscale MCP Server in Claude Code, Cursor or VS Code
Runs npx -y tailscale-mcp on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add tailscale -- npx -y tailscale-mcp
Tailscale MCP Server: common questions
- Is Tailscale MCP Server safe?
- With care: it is graded C, so read the findings first (65/100). Read the Tailscale MCP Server safety report
- How do I install Tailscale MCP Server?
- It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
- Does Tailscale MCP Server need an API key?
- No secret keys are declared. It reads 4 settings from the environment.
- Is Tailscale MCP Server maintained?
- The latest release is v2026.3.16.