Developer Tools · Security

Tailscale MCP

hexsleeves/tailscale-mcp

A Model Context Protocol (MCP) server for operating Tailscale from any MCP client. Supports local stdio for desktop clients and an authenticated HTTP transport for private tailnet deployments. Defaults to read-only access, localhost binding, and short-lived OAuth credentials where available.

Install

npx -y @hexsleeves/tailscale-mcp-server

Client configuration

{
  "mcpServers": {
    "tailscale": {
      "command": "npx",
      "args": [
        "-y",
        "@hexsleeves/tailscale-mcp-server"
      ],
      "env": {
        "TAILSCALE_OAUTH_CLIENT_ID": "<TAILSCALE_OAUTH_CLIENT_ID>",
        "TAILSCALE_OAUTH_CLIENT_SECRET": "<TAILSCALE_OAUTH_CLIENT_SECRET>",
        "TAILSCALE_TAILNET": "<TAILSCALE_TAILNET>"
      }
    }
  }
}

Environment variables

TAILSCALE_OAUTH_CLIENT_IDTAILSCALE_OAUTH_CLIENT_SECRETTAILSCALE_TAILNETTAILSCALE_API_KEYMCP_TRANSPORTMCP_HTTP_BEARER_TOKEN
Category
Developer Tools, Security
Updated
Oct 6, 2026

Features

  • Device management — list, authorize, deauthorize, delete, expire keys, manage routes.

  • Network operations — connect/disconnect host, ping peers, get CLI status and version.

  • Administration — tailnet info, file sharing, exit nodes, webhooks, device tags, server version.

  • ACL and policy — read/validate/update ACL, DNS settings, auth keys, policy file, network lock.

  • Read-only resources — tailnet summary, device list, per-device detail, current ACL.

  • Prompts — guided connectivity diagnosis and ACL change review.

  • Risk-gated tools — read, write, and admin levels via TAILSCALE_ALLOWED_TOOL_RISK.

  • OAuth + API key — OAuth client credentials (preferred) or legacy API key.

  • Private HTTP mode — bearer auth, Host validation, request size limits, health check endpoint.

  • Docker support — pre-built images on Docker Hub and GHCR; sidecar deployment with Tailscale Serve.

Tools (19)

  • list_devices

    List all devices in the configured tailnet

  • device_action

    Authorize or expire a device key (write); deauthorize or delete (admin)

  • manage_routes

    Enable or disable advertised routes for a device

  • get_network_status

    Get current Tailscale network status via local CLI

  • connect_network

    Connect this host to Tailscale with optional CLI flags

  • disconnect_network

    Disconnect this host from Tailscale

  • ping_peer

    Ping a Tailscale peer through the local CLI

  • get_version

    Get local Tailscale CLI version information

  • get_tailnet_info

    Get detailed information about the configured tailnet

  • manage_file_sharing

    Read (read) or update (write) tailnet file sharing settings

  • manage_exit_nodes

    List exit nodes (read); set, clear, advertise, or stop advertising (admin)

  • manage_webhooks

    List webhooks (read); create, delete, or test webhooks (write)

  • manage_device_tags

    Read (read) or update (write) tags for a device

  • get_version_info

    Return server version identifier

  • manage_acl

    Read (read), validate, or update (write) the tailnet ACL policy

  • manage_dns

    Read (read) or update (write) Tailscale DNS settings

  • manage_keys

    List auth keys (read); create or delete (admin)

  • manage_policy_file

    Read (read) or update (write) the tailnet policy file

  • manage_network_lock

    Network lock status (read) and mutation operations (admin)

Details on this page are taken from the project's README. Open README

Supported clients

Clients mentioned in this server's README:

View all
Claude Desktop logo

Claude Desktop

Desktop · Freemium · Proprietary

Anthropic's official Claude AI desktop application. Supports MCP servers to extend functionality.

WindowsMacOS
Cursor logo

Cursor

Desktop · Freemium · Proprietary

The first agentic IDE. The Cursor editor truly merges how developers and AI work together, delivering a magical coding experience.

WindowsMacOSLinux

Related MCP servers

More servers
Playwright logo

Playwright

microsoft/playwright

72.2k

Playwright is a framework for web automation and testing. It drives Chromium, Firefox, and WebKit with a single API — in your tests, in your scripts, and as a tool for AI agents.

Developer Tools
repomix logo

repomix

yamadashy/repomix

15.2k

Repomix is a tool that packs a codebase into an AI-friendly format, supporting local and remote repository processing and providing code compression, security checks and multiple output formats.

Developer Tools
UI-TARS-desktop logo

UI-TARS-desktop

bytedance/UI-TARS-desktop

12.9k

TARS is ByteDance's multimodal AI agent stack, shipping two projects: Agent TARS (a CLI and Web UI agent built on MCP) and UI-TARS-desktop (a desktop GUI agent).

Developer Tools
blender logo

blender

ahujasid/blender-mcp

10.6k

formerly blender-mcp — the PyPI package is now mcp-for-blender. Existing setups keep working; no config change is required. Read more.

Developer Tools
Playwright Browser Automation logo

Playwright Browser Automation

microsoft/playwright-mcp

9.2k

A Model Context Protocol (MCP) server that provides browser automation capabilities using Playwright. This server enables LLMs to interact with web pages through structured accessibility snapshots, bypassing the need for screenshots or visually-tuned models.

Developer Tools
2344 logo

2344

comet-ml/opik

7k

Opik is the open-source LLM observability and evaluation platform for AI agent tracing, LLM evaluation, prompt management, and production monitoring. Built by Comet. Apache-2.0 licensed, free to self-host the full platform, with 20,000+ GitHub stars.

Developer Tools