@yawlabs/tailscale-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| TAILSCALE_DEBUG | No | Set to '1' to enable debug logging | |
| TAILSCALE_TOOLS | No | Comma-separated tool groups to include | |
| TAILSCALE_BINARY | No | Absolute path to tailscale binary | |
| TAILSCALE_API_KEY | No | Tailscale API key (or use OAuth credentials) | |
| TAILSCALE_PROFILE | No | Preset filter: minimal, core, or full | |
| TAILSCALE_TAILNET | No | Tailnet to use (defaults to your default tailnet) | |
| TAILSCALE_READONLY | No | Set to '1' or 'true' to drop mutation tools | |
| TAILSCALE_LOCAL_CLI | No | Set to '1' to enable local CLI diagnostics | |
| TAILSCALE_MAX_CONCURRENT | No | Cap in-flight API requests at N | |
| TAILSCALE_OAUTH_CLIENT_ID | No | OAuth client ID | |
| TAILSCALE_REQUEST_BUDGET_MS | No | Total wall-clock budget per request in ms (default 90000) | |
| TAILSCALE_OAUTH_CLIENT_SECRET | No | OAuth client secret | |
| TAILSCALE_EXTRA_WEBHOOK_EVENTS | No | Comma-separated list of extra webhook event types to accept |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| resources | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| tailscale_tool_groupsA | Explain which of this server's tools are available and why. Call this FIRST when a Tailscale tool you expected is missing, instead of assuming the capability does not exist -- tools can be withheld by configuration, and the fix is usually one environment variable. Pass |
| tailscale_statusA | Check that the Tailscale API connection is working. Returns your tailnet name, device count, and confirms authentication is valid. Use this to verify setup. |
| tailscale_list_devicesA | List all devices in your tailnet with their status, IP addresses, OS, and last seen time. 'lastSeen' is omitted while a device is connected (connectedToControl: true) and for devices that have never been online -- on a connected device a missing lastSeen means online now, not never seen. |
| tailscale_get_deviceA | Get detailed information about a specific device by its ID. Returns the default field subset unless fields: 'all'. 'lastSeen' is omitted while a device is connected (connectedToControl: true) and for devices that have never been online -- on a connected device a missing lastSeen means online now, not never seen. |
| tailscale_authorize_deviceA | Authorize a device that is pending authorization. |
| tailscale_deauthorize_deviceA | Deauthorize a device, immediately removing its access to the tailnet. The device will need to be re-authorized to reconnect. |
| tailscale_delete_deviceA | Permanently remove a device from the tailnet. This is irreversible — the device must re-authenticate to rejoin. |
| tailscale_rename_deviceA | Set the name of a device in the tailnet, or reset it to its OS hostname. |
| tailscale_expire_deviceA | Expire a device's key, forcing it to re-authenticate. |
| tailscale_get_device_routesA | Get the subnet routes a device advertises and which are enabled. |
| tailscale_set_device_routesA | Set the enabled subnet routes for a device. Replaces all currently enabled routes — pass the full list of routes you want enabled. |
| tailscale_get_device_posture_attributesA | Get all posture attributes for a device, including custom and system-managed attributes. |
| tailscale_set_device_posture_attributeB | Set a custom posture attribute on a device. Creates or updates the attribute. Attribute keys must start with 'custom:'. Useful for compliance tracking, JIT access, and custom security policies. |
| tailscale_delete_device_posture_attributeA | Delete a custom posture attribute from a device. This is irreversible. |
| tailscale_set_device_tagsA | Set ACL tags on a device. Replaces all existing tags — pass the full list of tags you want applied. |
| tailscale_set_device_ipA | Set the Tailscale IPv4 address for a device. |
| tailscale_update_device_keyA | Update a device's key settings, such as disabling key expiry. Useful for servers that should never need to re-authenticate. |
| tailscale_set_devices_authorizedA | Authorize or deauthorize multiple devices in one call. Each device's POST runs in parallel; per-device errors are returned alongside the successes so a partial failure doesn't lose the work that succeeded. On partial failure the call still returns success (ok) with data: { authorized, succeeded, failed } -- inspect data.failed for the per-device errors. Common use: authorize a batch of newly-enrolled CI hosts, or deauthorize a group of devices flagged by a security review. |
| tailscale_batch_update_posture_attributesA | Batch update custom posture attributes across multiple devices. Each attribute key must start with 'custom:'. Uses JSON Merge Patch semantics — pass null as the attribute config to delete. |
| tailscale_get_aclA | Get the current ACL policy for your tailnet. Returns the raw policy text with original formatting preserved, including comments and trailing commas (HuJSON). Also returns an ETag — you must pass it to tailscale_update_acl to safely update the policy. |
| tailscale_update_aclA | Update the ACL policy for your tailnet. Accepts the full policy as a string to preserve formatting, comments, and trailing commas (HuJSON). You MUST pass the ETag from tailscale_get_acl to prevent overwriting concurrent changes, or |
| tailscale_validate_aclA | Validate an ACL policy without applying it. Returns any errors found, or confirms the policy is valid. |
| tailscale_preview_aclA | Preview the ACL rules that would apply to a specific user or IP address if a proposed policy were applied. |
| tailscale_diff_acl_accessA | Answer 'who loses access?' before applying an ACL change. Compares the CURRENT policy against a proposed one and reports, per user, which destinations they gain and lose. Run this before tailscale_update_acl -- validate_acl only checks syntax and the policy's own tests block, so a policy with no tests validates clean while revoking everyone. LIMITS, all reported in the response rather than left to be discovered. It compares USER principals only, so a revocation that runs through a tag or group can show a clean diff, and an empty result is never proof a change is safe. Posture DEFINITION changes ARE detected: posture names are resolved to their rules, so tightening |
| tailscale_get_nameserversB | Get the DNS nameservers configured for your tailnet. |
| tailscale_set_nameserversA | Set the DNS nameservers for your tailnet. Replaces all existing nameservers. Removing every nameserver may also change MagicDNS: the API reference says it is switched off, while Tailscale's current MagicDNS docs say a nameserver is no longer required -- check |
| tailscale_get_search_pathsA | Get the DNS search paths configured for your tailnet. |
| tailscale_set_search_pathsA | Set the DNS search paths for your tailnet. Replaces all existing search paths. |
| tailscale_get_split_dnsB | Get the split DNS configuration for your tailnet. |
| tailscale_set_split_dnsA | Set split DNS configuration. Maps domains to specific nameservers. Replaces the entire split DNS configuration: a domain you leave out is removed, and an empty object clears every domain. Per the API reference, setting a domain to null clears that domain's nameservers. |
| tailscale_get_dns_preferencesB | Get DNS preferences for your tailnet, including whether MagicDNS is enabled. |
| tailscale_set_dns_preferencesA | Set DNS preferences for your tailnet, such as enabling or disabling MagicDNS. The API reference says enabling can fail when the tailnet has no nameservers; if it does, add one with tailscale_set_nameservers first. |
| tailscale_update_split_dnsA | Partially update split DNS configuration. Merges the provided domains with the existing config -- only the specified domains are changed, others are untouched. To remove a domain, set it to null: that is the idiom the API reference documents. An empty array is also accepted and forwarded as-is -- it is what Tailscale's Terraform provider sends. |
| tailscale_get_dns_configurationA | Get the unified DNS configuration for your tailnet, including nameservers, search paths, split DNS, and MagicDNS preference in a single call. |
| tailscale_set_dns_configurationA | Set the unified DNS configuration for your tailnet in a single call. Replaces all DNS settings (nameservers, search paths, split DNS, MagicDNS preference). |
| tailscale_list_keysA | List keys in your tailnet: auth keys, API access tokens, OAuth clients and federated identities. Without 'all', what comes back depends on the credential this server runs on -- a user-owned API key sees only that user's keys (including the API access token the server itself is using, keyType 'api'); an OAuth-client token sees the tailnet's OAuth clients; a federated-identity token sees its federated identities. Set 'all' to true for the tailnet-wide list (needs the matching :read scopes; only 'all:read' and 'all' return every API access token). |
| tailscale_get_keyA | Get details for a specific key (auth key, API access token, OAuth client, or federated identity). A revoked or expired key is still returned, with |
| tailscale_create_keyA | Create a new key in your tailnet. Supports auth keys (for adding devices), OAuth clients (for programmatic API access), and federated identities (for OIDC-based CI/CD access). Returns the key value -- save it immediately, as it cannot be retrieved again. SECURITY: the response body contains a long-lived credential verbatim. MCP clients commonly persist tool responses to logs and conversation transcripts; treat this response as sensitive (do not commit it, avoid re-sharing it in unrelated chat history). Examples:
|
| tailscale_delete_keyA | Delete a key (auth key, API access token, OAuth client, or federated identity). This is irreversible. For auth keys, devices already authenticated are unaffected but no new devices can use it. For OAuth clients and federated identities, any integrations using them lose access immediately. API access tokens are deletable here too: if keyId is the token this server authenticates with -- it shows up in tailscale_list_keys under API-key auth -- the server revokes its own credential and every later call fails with 401 until it is reconfigured. |
| tailscale_update_keyA | Update an existing key. Supported fields depend on the key type: all key types accept 'description'; OAuth clients and federated identities additionally accept 'scopes' and 'tags'; federated identities additionally accept 'issuer', 'subject', 'audience', and 'customClaimRules'. For auth keys, pass only 'description' — the Tailscale API will reject other fields. |
| tailscale_create_oauth_appA | Create an OAuth App for device provisioning (Tailscale alpha). Lets a third-party application enroll a device into your tailnet via the authorization-code flow, after a user consents. Returns the app's client secret -- save it immediately, it cannot be retrieved again. SECURITY: the response body contains a long-lived credential verbatim. MCP clients commonly persist tool responses to logs and conversation transcripts; treat this response as sensitive. Use scope 'auth_keys:create:once' (one auth key per authorization, no refresh token) -- the scope Tailscale's device-provisioning guide documents. The API reference's example shows 'auth_keys:create'; this tool does not restrict the value. Distinct from tailscale_create_key with keyType='client', which mints a machine-to-machine OAuth client instead. |
| tailscale_get_oauth_appA | Get an OAuth App's configuration (name, redirect URIs, scopes) by its app ID. Use this to verify an app was registered as intended. The client secret is not returned -- it is only available at creation time. |
| tailscale_list_oauth_appsA | List the OAuth Apps registered in your tailnet (Tailscale alpha). Returns an |
| tailscale_delete_oauth_appA | Delete an OAuth App (Tailscale alpha). This is irreversible: the app's client secret stops working immediately and any integration using it loses its device-enrollment path, so no further device can be authorized through it. Devices already enrolled stay in the tailnet, exactly as they do when the auth key that added them is deleted. Use tailscale_list_oauth_apps to find the id. |
| tailscale_list_usersB | List all users in your tailnet. |
| tailscale_get_userB | Get details for a specific user. |
| tailscale_approve_userA | Approve a pending user, granting them access to the tailnet. |
| tailscale_suspend_userA | Suspend a user, immediately revoking their access to the tailnet. Their devices will be disconnected. Can be reversed with tailscale_restore_user. |
| tailscale_restore_userA | Restore a previously suspended user, re-granting them access to the tailnet. |
| tailscale_update_user_roleB | Update a user's role in the tailnet. |
| tailscale_delete_userA | Delete a user from the tailnet. This is irreversible — the user and all their devices will be removed. |
| tailscale_get_tailnet_settingsA | Get your tailnet settings (device approval, key expiry, HTTPS certificates, etc.). |
| tailscale_update_tailnet_settingsB | Update tailnet settings (device approval, auto-updates, key expiry, HTTPS certificates, network flow logging, regional routing, posture identity collection). |
| tailscale_get_contactsA | Get the tailnet contact information (security, support, admin emails). |
| tailscale_set_contactsA | Update tailnet contact information. Each provided contact type (account/support/security) is PATCHed in parallel; per-type errors are returned alongside the successes so a partial failure doesn't lose the work that succeeded. On partial failure the response is data: { applied, failed } -- inspect data.failed for per-type error details. |
| tailscale_resend_contact_verificationC | Resend the verification email for a tailnet contact. |
| tailscale_list_org_tailnetsA | List the tailnets in your organization, including API-only tailnets created via the API. Paginated: returns at most |
| tailscale_create_org_tailnetA | Create a new API-only tailnet in your organization. Returns the tailnet (id, displayName, orgId, dnsName, createdAt) AND a freshly-minted OAuth client for it. SECURITY: the response body contains that OAuth client's secret verbatim, and it cannot be retrieved again. MCP clients commonly persist tool responses to logs and conversation transcripts; treat this response as sensitive. Requires an OAuth client with the 'tailnets' scope -- an API key will not work. To then operate on the new tailnet, set TAILSCALE_OAUTH_TAILNET to its id and use an OAuth client with the 'all' scope. Organizations are limited to 10 tailnets including the original unless Tailscale sales has raised the limit. The response may include |
| tailscale_delete_tailnetA | Permanently delete a tailnet. This is IRREVERSIBLE and removes every device, user, ACL, and key in it. By default it acts on the tailnet the current credentials point at (TAILSCALE_TAILNET, or TAILSCALE_OAUTH_TAILNET when targeting an API-only tailnet). Pass |
| tailscale_list_webhooksA | List all webhooks configured for your tailnet. |
| tailscale_get_webhookB | Get details for a specific webhook. |
| tailscale_create_webhookA | Create a new webhook. The response includes the webhook's signing secret -- this is the only opportunity to capture it; save it immediately. Set providerType when the endpoint is a Slack, Mattermost, Google Chat or Discord incoming-webhook URL, so the events arrive in the format that provider renders. SECURITY: the response body contains the secret verbatim. MCP clients commonly persist tool responses to logs and conversation transcripts; treat this response as sensitive. |
| tailscale_update_webhookA | Update an existing webhook's endpoint URL and/or subscriptions. |
| tailscale_delete_webhookA | Delete a webhook. This is irreversible — the webhook secret cannot be recovered. |
| tailscale_rotate_webhook_secretA | Rotate a webhook's secret. Returns the new secret — save it immediately, as it cannot be retrieved again. The old secret is immediately invalidated. SECURITY: the response body contains the secret verbatim. MCP clients commonly persist tool responses to logs and conversation transcripts; treat this response as sensitive. |
| tailscale_test_webhookA | Send a test event to a webhook endpoint to verify it is configured correctly and receiving events. |
| tailscale_list_posture_integrationsA | List all device posture integrations configured for your tailnet. |
| tailscale_get_posture_integrationA | Get details for a specific device posture integration. |
| tailscale_create_posture_integrationB | Create a new device posture integration. |
| tailscale_update_posture_integrationC | Update an existing posture integration's credentials or configuration. |
| tailscale_delete_posture_integrationB | Delete a posture integration. This is irreversible. |
| tailscale_get_audit_logA | Get the tailnet audit/configuration log. Shows who changed what and when -- useful for troubleshooting and compliance. Optional actor, target and event filters narrow the query server-side, so a targeted question doesn't have to pull the whole window. |
| tailscale_get_network_flow_logsA | Get network traffic flow logs showing connections between devices. Shows source/destination nodes, timestamps, and traffic metadata — useful for security monitoring and debugging connectivity. |
| tailscale_list_device_invitesA | List all device invites for a specific device. |
| tailscale_create_device_inviteA | Create a device share invitation that allows an external user to access a specific device in your tailnet. |
| tailscale_get_device_inviteC | Get details for a specific device invite. |
| tailscale_delete_device_inviteA | Delete a device invite. This is irreversible — the invite link will stop working. |
| tailscale_accept_device_inviteB | Accept a device share invitation using the invite URL or code. |
| tailscale_list_user_invitesA | List the open (not yet accepted) user invites for your tailnet. Accepted invites are not returned. |
| tailscale_create_user_inviteC | Create a new user invite that allows someone to join your tailnet. |
| tailscale_get_user_inviteB | Get details for a specific user invite. |
| tailscale_delete_user_inviteA | Delete a user invite. This is irreversible — the invite link will stop working. |
| tailscale_resend_device_inviteC | Resend a device invite email. |
| tailscale_resend_user_inviteB | Resend a user invite email. |
| tailscale_list_servicesA | List all Tailscale Services in your tailnet. Services provide stable MagicDNS names and virtual IPs, decoupled from individual devices. Note: services are created implicitly when a node first advertises one ( |
| tailscale_get_serviceB | Get details for a specific Tailscale Service, including its MagicDNS name, virtual IP, and configuration. |
| tailscale_update_serviceC | Update a Tailscale Service's configuration. |
| tailscale_delete_serviceA | Delete a Tailscale Service. This is irreversible — the service's MagicDNS name and virtual IP will be released. |
| tailscale_list_service_hostsA | List devices hosting a specific Tailscale Service. |
| tailscale_get_service_device_approvalB | Get the approval status of a specific device for a Tailscale Service. |
| tailscale_set_service_device_approvalB | Approve or reject a device to host a Tailscale Service. |
| tailscale_list_log_stream_configsA | List all log streaming configurations for your tailnet. Fetches both 'configuration' (audit) and 'network' (flow) log stream configs. Log streaming sends logs to external destinations like Axiom, Datadog, Splunk, Elasticsearch, or S3. |
| tailscale_get_log_stream_configB | Get the log streaming configuration for a specific log type. |
| tailscale_set_log_stream_configA | Set the log streaming configuration for a specific log type. Configures where logs are sent (e.g. Axiom, Datadog, Splunk, Elasticsearch, S3). Per-destination required fields:
|
| tailscale_delete_log_stream_configA | Delete a log streaming configuration. Logs will stop being sent to the configured destination. |
| tailscale_get_log_stream_statusA | Get the status of log streaming for a specific log type. Shows whether logs are being delivered successfully. |
| tailscale_create_aws_external_idA | Create or get the AWS external ID Tailscale presents when assuming your IAM role for S3 log streaming. Put it in the role trust policy's sts:ExternalId condition, then check it with tailscale_validate_aws_trust_policy. |
| tailscale_validate_aws_trust_policyA | Validate that an AWS IAM role trust policy is correctly configured with the Tailscale external ID. Use this after setting up the IAM role for S3 log streaming. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| tailnet-status | Current tailnet status including device count and settings |
| tailnet-devices | List of all devices in the tailnet with their status |
| tailnet-acl | Current ACL policy (HuJSON with comments preserved) |
| tailnet-dns | DNS configuration including nameservers, search paths, split DNS, and MagicDNS status |
TDQS
Scored across 98 tools
Most tools are clearly separated by resource and action (devices, users, ACL, DNS, services, webhooks, keys, etc.), so an agent can usually tell them apart. Some overlap exists between the unified DNS getter/setter and the individual DNS tools, and between single-device and batch operations, but the descriptions explain the distinctions. With 98 tools, a few pairs still risk misselection.
Almost all tools follow the tailscale_verb_noun pattern (list_devices, create_webhook, delete_device, update_acl), which is highly consistent. Minor exceptions like tailscale_status and tailscale_tool_groups break the verb_noun pattern, and a few singular/plural mismatches (set_device_posture_attribute vs get_device_posture_attributes) keep it from being perfect.
98 tools is far beyond the well-scoped range and even the heavy 25+ threshold. While Tailscale's API is broad, this is too many tools for one MCP server; agents will struggle to navigate the surface. Many tools could be consolidated (e.g., unified DNS vs individual DNS setters) or split into domain-specific servers.
The tool set covers essentially the full Tailscale management surface: devices, users, invites, keys, ACL, DNS, services, posture integrations, webhooks, log streaming, OAuth apps, tailnet settings, contacts, audit logs, and network flow logs. CRUD/lifecycle operations are present for each resource, and destructive operations are paired with getters/listers, leaving no obvious dead ends.