Tailscale MCP logo

Tailscale MCP

Unclaimed

by YawLabs

Tailscale MCP server for managing your tailnet from AI assistants

Set up this server

01 / Choose your client

02 / Before you connect

Authentication is not specified. Check the project instructions before connecting.

Install the runtime required by the project and make it available to your client.

Project instructions

Use names from the project instructions, separated by commas. Enter names only, never secret values.

03 / Add the configuration

Source: generated from public install instructions

claude mcp add --transport stdio 'yawlabs-tailscale-mcp' -- 'npx' '-y' '@yawlabs/tailscale-mcp@latest' 'validate-acl' 'tailscale/acl.json'

Run in your terminal after replacing any placeholders.

04 / Check it in your client

Open your client’s MCP settings and confirm the server connects and lists its tools. A copied configuration does not confirm a working connection.

aclaiai-agentsaudit-logauth-keysclaude-codecursordnsgitopsmagicdnsmcpmcp-servermodel-context-protocolnetworkingoauthtailnettailscaletailscale-apivpnwebhooks

More in Security

Browse the full directory

Unclaimed listing

Is this your MCP server?

This listing was auto-indexed from the public record. Claim it to edit the page, set compatibility and unlock growth tools. Takes under two minutes.

Claim this server

Security profile

Claimed and verified servers get a weekly static scan that shows what the code can reach: external services, environment variables, shell commands, agent configuration folders, plus any dependencies with known advisories. Claim this listing to get one. How the security profile works

40 of 40 tools

Documented tools (40)

From project documentation. A server handshake does not verify each tool’s description or behavior.

tailscale_authorize_device

Authorize a pending device

tailscale_batch_update_posture_attributes

Batch update custom posture attributes across devices

tailscale_create_key

Create an auth key, OAuth client (keyType=client), or federated identity (keyType=federated)

tailscale_deauthorize_device

Deauthorize a device

tailscale_delete_device

Remove a device from the tailnet

tailscale_delete_device_posture_attribute

Delete a custom posture attribute

tailscale_delete_key

Delete a key

tailscale_expire_device

Expire a device's key, forcing re-authentication

tailscale_get_acl

Get ACL policy with formatting preserved (HuJSON) + ETag

tailscale_get_device

Get detailed info for a specific device

tailscale_get_device_posture_attributes

Get all posture attributes for a device

tailscale_get_device_routes

Get advertised and enabled subnet routes

tailscale_get_dns_configuration

Get unified DNS configuration (all settings in one call)

tailscale_get_dns_preferences

Get DNS preferences (MagicDNS)

tailscale_get_key

Get details for a key

tailscale_get_nameservers

Get DNS nameservers

tailscale_get_search_paths

Get DNS search paths

tailscale_get_split_dns

Get split DNS configuration

tailscale_get_user

Get details for a specific user

tailscale_list_devices

List all devices with status, IPs, OS, and last seen

tailscale_list_keys

List keys (auth keys; pass all=true to include OAuth clients and federated identities)

tailscale_list_users

List all users in the tailnet

tailscale_preview_acl

Preview rules that would apply to a user or IP

tailscale_rename_device

Rename a device

tailscale_set_device_ip

Set a device's Tailscale IPv4 address

tailscale_set_device_posture_attribute

Set a custom posture attribute (with optional expiry)

tailscale_set_device_routes

Enable or disable subnet routes

tailscale_set_device_tags

Set ACL tags on a device

tailscale_set_devices_authorized

Authorize/deauthorize many devices in one call (parallel, per-id error reporting)

tailscale_set_dns_configuration

Set unified DNS configuration (all settings in one call)

tailscale_set_dns_preferences

Set DNS preferences (MagicDNS)

tailscale_set_nameservers

Set DNS nameservers

tailscale_set_search_paths

Set DNS search paths

tailscale_set_split_dns

Set split DNS configuration (full replace)

tailscale_status

Verify API connection, see tailnet info and device count

tailscale_update_acl

Update ACL policy (requires ETag for safe concurrent edits)

tailscale_update_device_key

Update device key settings (e.g. disable key expiry)

tailscale_update_key

Update a key's description, scopes, tags, or federated claim settings

tailscale_update_split_dns

Update split DNS configuration (partial merge)

tailscale_validate_acl

Validate a policy without applying it

Tool change history

Compared across complete checks of the same configuration. Tools were listed, not invoked. Input-schema changes are not measured here.

No complete tool checks yet.

FAQ

Questions about Tailscale MCP Server

How do I connect Tailscale MCP Server to Claude?
Run `claude mcp add yawlabs-tailscale-mcp -- npx -y @yawlabs/tailscale-mcp@latest validate-acl tailscale/acl.json` in Claude Code, or add the same command and arguments under mcpServers in Cursor's mcp.json or Claude Desktop's claude_desktop_config.json, then restart the client. The blocks above are ready to paste.
Is Tailscale MCP Server free?
The listed licence is MIT. Check the upstream terms for permitted use and commercial requirements; a public repository does not by itself mean the software is free or open source. Connected APIs and hosted services may have separate charges.
What can Tailscale MCP Server do?
Tailscale MCP Server documents 40 tools to the agent, including tailscale_authorize_device, tailscale_batch_update_posture_attributes, tailscale_create_key. The descriptions above come from project documentation. A live handshake does not test individual tool behavior.