Mmcp.market

Tailscale MCP Server

by itunified-io·io.github.itunified-io/tailscale·v2026.3.16

Secure MCP access for private infrastructure over Tailscale — 48 tools across 9 domains

C65/100grade C
What users say
No reviews yet
Be the first
Safety scan
C65/100

full report

Adoption
New

109 downloads/wk

Reviews

Write one

Nobody has reviewed Tailscale MCP Server yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Tailscale MCP Server tools (48, 11 write)

write = sends, deletes, buys or posts

Read from the package source without running it. The installed server may list more.

  • tailscale_acl_get

    Get the current ACL policy for the tailnet as JSON. Returns the full policy including rules, groups, hosts, and tag owners.

  • tailscale_acl_preview

    Preview what the ACL policy would allow for a specific user or IP. Useful for testing before applying changes.

  • tailscale_acl_set

    Set (replace) the ACL policy for the tailnet. Requires confirm: true. The entire policy is replaced — provide the complete policy.

  • tailscale_acl_testwrite action

    Run ACL tests defined in the policy's 'tests' field by validating the policy. Returns validation results including test pass/fail outcomes.

  • tailscale_acl_validate

    Validate an ACL policy without applying it. Returns any errors or warnings found in the policy.

  • tailscale_api_verify

    Verify API connectivity and authentication by making a lightweight request to the Tailscale API.

  • tailscale_derp_map

    Get the DERP relay map for the tailnet. Shows all DERP regions and their relay nodes used for traffic routing.

  • tailscale_device_authorize

    Authorize a device that is pending approval. Sets the device's authorized status to true.

  • tailscale_device_deletewrite action

    Delete a device from the tailnet. This removes the device and revokes its access. Requires confirm: true.

  • tailscale_device_expire

    Expire a device's key, forcing it to re-authenticate. The device remains in the tailnet but loses connectivity until re-authenticated. This is one-directional — once expired, the device must re-auth. Requires confirm: true.

  • tailscale_device_get

    Get details of a specific device by its ID.

  • tailscale_device_list

    List all devices in the tailnet. Returns all registered devices with their IP addresses, hostname, OS, and connection status.

  • tailscale_device_posture_get

    Get custom posture attributes for a device. Returns all key-value posture attributes.

  • tailscale_device_posture_set

    Set a custom posture attribute on a device. Creates or updates a single attribute key-value pair.

  • tailscale_device_rename

    Set a custom display name for a device. This changes the device's 'given name' in Tailscale, not the machine hostname.

  • tailscale_device_routes_get

    Get the advertised and enabled subnet routes for a device.

  • tailscale_device_routes_set

    Set the enabled subnet routes for a device. Replaces the current set of enabled routes.

  • tailscale_device_tags_set

    Set ACL tags on a device. Replaces all existing tags. Use an empty array to remove all tags.

  • tailscale_dns_nameservers_get

    Get the global DNS nameservers configured for the tailnet. Also returns whether MagicDNS is enabled.

  • tailscale_dns_nameservers_set

    Set the global DNS nameservers for the tailnet. Replaces all existing nameservers.

  • tailscale_dns_preferences_get

    Get DNS preferences for the tailnet, including MagicDNS status.

  • tailscale_dns_preferences_set

    Set DNS preferences for the tailnet. Toggle MagicDNS on or off.

  • tailscale_dns_searchpaths_get

    Get the DNS search paths configured for the tailnet.

  • tailscale_dns_searchpaths_set

    Set the DNS search paths for the tailnet. Replaces all existing search paths.

  • tailscale_dns_splitdns_get

    Get the split DNS configuration for the tailnet. Returns a map of domain names to their resolver IP addresses.

  • tailscale_dns_splitdns_setwrite action

    Update split DNS configuration for the tailnet using a PATCH operation. Provide a map of domain names to resolver IP addresses. Use null values to remove a domain.

  • tailscale_key_createwrite action

    Create a new auth key for the tailnet. Returns the key value — store it securely as it cannot be retrieved again.

  • tailscale_key_deletewrite action

    Delete (revoke) an auth key. Devices already authenticated with this key will not be affected. Requires confirm: true.

  • tailscale_key_get

    Get details of a specific auth key by its ID.

  • tailscale_key_list

    List all auth keys for the tailnet. Returns key metadata (but not the secret key values).

  • tailscale_log_stream_get

    Get the current log streaming configuration for the tailnet. Log types: 'configuration' or 'network'.

  • tailscale_log_stream_set

    Configure log streaming for the tailnet. Requires confirm: true. Streams logs to a specified URL endpoint.

  • tailscale_posture_integration_createwrite action

    Create a new third-party posture provider integration. Supported providers: crowdstrike, falcon, intune, jamfPro, kandji, kolide, sentinelone. Required fields depend on the provider.

  • tailscale_posture_integration_deletewrite action

    Delete a posture provider integration. Requires confirm: true.

  • tailscale_posture_integration_get

    Get details for a specific posture provider integration by ID.

  • tailscale_posture_integration_list

    List all configured third-party posture provider integrations for the tailnet (e.g., CrowdStrike, Intune, Jamf).

  • tailscale_status

    Get a summary of the tailnet status including total device count, online/offline counts, and last-seen timestamps.

  • tailscale_tailnet_contacts_get

    Get the contact email addresses configured for the tailnet (account, support, and security contacts).

  • tailscale_tailnet_contacts_setwrite action

    Update contact email addresses for the tailnet. Requires confirm: true. Provide any combination of account, support, or security contacts.

  • tailscale_tailnet_lock_status

    Get the Tailnet Lock status. Tailnet Lock allows requiring cryptographic signatures on all node key registrations.

  • tailscale_tailnet_settings_get

    Get the tailnet settings including device approval, auto-updates, key expiry, and posture identity collection.

  • tailscale_tailnet_settings_updatewrite action

    Update tailnet settings. Requires confirm: true. All settings fields are optional — only provided fields will be updated.

  • tailscale_user_get

    Get details for a specific user by their user ID. Returns display name, login, role, status, device count, and last seen.

  • tailscale_user_list

    List all users in the tailnet. Optionally filter by type (member/shared) or role (owner/admin/member/auditor/it-admin/network-admin/billing-admin).

  • tailscale_webhook_createwrite action

    Create a new webhook endpoint. Returns the webhook including the signing secret (only shown once). Event types: nodeCreated, nodeApproved, nodeNeedsApproval, nodeKeyExpiringInOneDay, nodeKeyExpired, nodeDeleted, policyUpdate, userCreated, userDeleted, userApproved, userSuspended, userRestored, userRoleUpdated, subnetIPForwardingNotEnabled, exitNodeIPForwardingNotEnabled.

  • tailscale_webhook_deletewrite action

    Delete a webhook endpoint. Requires confirm: true.

  • tailscale_webhook_get

    Get details for a specific webhook endpoint by ID.

  • tailscale_webhook_list

    List all webhook endpoints configured for the tailnet.

Public scan report

scanner v0.1.10 · 2026-09-27 · same rubric, same numbers if you re-run it

no findings
  • Code scan37 source files scanned25/25
  • –Live reliabilityno gateway calls yet and no remote to proben/a
  • –Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancerepository not readable: repo not found3/15
  • Maintainer identityno repository or website to verify2/10
Overall 65/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install Tailscale MCP Server in Claude Code, Cursor or VS Code

Runs npx -y tailscale-mcp on your machine. Read the scan report first; the gateway never runs local packages.

claude mcp add tailscale -- npx -y tailscale-mcp
Add to Cursor

Tailscale MCP Server: common questions

Is Tailscale MCP Server safe?
With care: it is graded C, so read the findings first (65/100). Read the Tailscale MCP Server safety report
How do I install Tailscale MCP Server?
It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
Does Tailscale MCP Server need an API key?
No secret keys are declared. It reads 4 settings from the environment.
Is Tailscale MCP Server maintained?
The latest release is v2026.3.16.

More from itunified-io →