Skip to main content
Glama
YawLabs

@yawlabs/tailscale-mcp

by YawLabs

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
TAILSCALE_DEBUGNoSet to '1' to enable debug logging
TAILSCALE_TOOLSNoComma-separated tool groups to include
TAILSCALE_BINARYNoAbsolute path to tailscale binary
TAILSCALE_API_KEYNoTailscale API key (or use OAuth credentials)
TAILSCALE_PROFILENoPreset filter: minimal, core, or full
TAILSCALE_TAILNETNoTailnet to use (defaults to your default tailnet)
TAILSCALE_READONLYNoSet to '1' or 'true' to drop mutation tools
TAILSCALE_LOCAL_CLINoSet to '1' to enable local CLI diagnostics
TAILSCALE_MAX_CONCURRENTNoCap in-flight API requests at N
TAILSCALE_OAUTH_CLIENT_IDNoOAuth client ID
TAILSCALE_REQUEST_BUDGET_MSNoTotal wall-clock budget per request in ms (default 90000)
TAILSCALE_OAUTH_CLIENT_SECRETNoOAuth client secret
TAILSCALE_EXTRA_WEBHOOK_EVENTSNoComma-separated list of extra webhook event types to accept

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}
resources
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
tailscale_tool_groupsA

Explain which of this server's tools are available and why. Call this FIRST when a Tailscale tool you expected is missing, instead of assuming the capability does not exist -- tools can be withheld by configuration, and the fix is usually one environment variable. Pass toolName to ask about one specific tool (e.g. 'tailscale_delete_device'): the answer distinguishes 'no such tool exists' -- where you should find another approach -- from 'it exists but its group is not loaded' and 'it exists and loaded but writes are withheld there', both of which the operator can enable and neither of which you should work around. With no arguments it lists every group with its availability and, where something is withheld, the exact environment change that would restore it. Always available regardless of filters.

tailscale_statusA

Check that the Tailscale API connection is working. Returns your tailnet name, device count, and confirms authentication is valid. Use this to verify setup.

tailscale_list_devicesA

List all devices in your tailnet with their status, IP addresses, OS, and last seen time. 'lastSeen' is omitted while a device is connected (connectedToControl: true) and for devices that have never been online -- on a connected device a missing lastSeen means online now, not never seen.

tailscale_get_deviceA

Get detailed information about a specific device by its ID. Returns the default field subset unless fields: 'all'. 'lastSeen' is omitted while a device is connected (connectedToControl: true) and for devices that have never been online -- on a connected device a missing lastSeen means online now, not never seen.

tailscale_authorize_deviceA

Authorize a device that is pending authorization.

tailscale_deauthorize_deviceA

Deauthorize a device, immediately removing its access to the tailnet. The device will need to be re-authorized to reconnect.

tailscale_delete_deviceA

Permanently remove a device from the tailnet. This is irreversible — the device must re-authenticate to rejoin.

tailscale_rename_deviceA

Set the name of a device in the tailnet, or reset it to its OS hostname.

tailscale_expire_deviceA

Expire a device's key, forcing it to re-authenticate.

tailscale_get_device_routesA

Get the subnet routes a device advertises and which are enabled.

tailscale_set_device_routesA

Set the enabled subnet routes for a device. Replaces all currently enabled routes — pass the full list of routes you want enabled.

tailscale_get_device_posture_attributesA

Get all posture attributes for a device, including custom and system-managed attributes.

tailscale_set_device_posture_attributeB

Set a custom posture attribute on a device. Creates or updates the attribute. Attribute keys must start with 'custom:'. Useful for compliance tracking, JIT access, and custom security policies.

tailscale_delete_device_posture_attributeA

Delete a custom posture attribute from a device. This is irreversible.

tailscale_set_device_tagsA

Set ACL tags on a device. Replaces all existing tags — pass the full list of tags you want applied.

tailscale_set_device_ipA

Set the Tailscale IPv4 address for a device.

tailscale_update_device_keyA

Update a device's key settings, such as disabling key expiry. Useful for servers that should never need to re-authenticate.

tailscale_set_devices_authorizedA

Authorize or deauthorize multiple devices in one call. Each device's POST runs in parallel; per-device errors are returned alongside the successes so a partial failure doesn't lose the work that succeeded. On partial failure the call still returns success (ok) with data: { authorized, succeeded, failed } -- inspect data.failed for the per-device errors. Common use: authorize a batch of newly-enrolled CI hosts, or deauthorize a group of devices flagged by a security review.

tailscale_batch_update_posture_attributesA

Batch update custom posture attributes across multiple devices. Each attribute key must start with 'custom:'. Uses JSON Merge Patch semantics — pass null as the attribute config to delete.

tailscale_get_aclA

Get the current ACL policy for your tailnet. Returns the raw policy text with original formatting preserved, including comments and trailing commas (HuJSON). Also returns an ETag — you must pass it to tailscale_update_acl to safely update the policy.

tailscale_update_aclA

Update the ACL policy for your tailnet. Accepts the full policy as a string to preserve formatting, comments, and trailing commas (HuJSON). You MUST pass the ETag from tailscale_get_acl to prevent overwriting concurrent changes, or ts-default for the first write to a tailnet nobody has edited yet. Always get the current ACL first, make targeted edits to the text, and pass the full modified text back.

tailscale_validate_aclA

Validate an ACL policy without applying it. Returns any errors found, or confirms the policy is valid.

tailscale_preview_aclA

Preview the ACL rules that would apply to a specific user or IP address if a proposed policy were applied.

tailscale_diff_acl_accessA

Answer 'who loses access?' before applying an ACL change. Compares the CURRENT policy against a proposed one and reports, per user, which destinations they gain and lose. Run this before tailscale_update_acl -- validate_acl only checks syntax and the policy's own tests block, so a policy with no tests validates clean while revoking everyone. LIMITS, all reported in the response rather than left to be discovered. It compares USER principals only, so a revocation that runs through a tag or group can show a clean diff, and an empty result is never proof a change is safe. Posture DEFINITION changes ARE detected: posture names are resolved to their rules, so tightening posture:corp shows as a change -- except when a preview omits the definitions map, where it falls back to comparing names. It costs two preview requests per user, so it checks the first 25 by default and stops after 60 seconds regardless; either way it sets truncated, reports how many were skipped, and says which limit stopped it. Users whose preview fails are listed in failed and excluded from the compared count -- a failure is never reported as lost access, and if nothing could be compared the call fails rather than returning an empty diff.

tailscale_get_nameserversB

Get the DNS nameservers configured for your tailnet.

tailscale_set_nameserversA

Set the DNS nameservers for your tailnet. Replaces all existing nameservers. Removing every nameserver may also change MagicDNS: the API reference says it is switched off, while Tailscale's current MagicDNS docs say a nameserver is no longer required -- check magicDNS in the response.

tailscale_get_search_pathsA

Get the DNS search paths configured for your tailnet.

tailscale_set_search_pathsA

Set the DNS search paths for your tailnet. Replaces all existing search paths.

tailscale_get_split_dnsB

Get the split DNS configuration for your tailnet.

tailscale_set_split_dnsA

Set split DNS configuration. Maps domains to specific nameservers. Replaces the entire split DNS configuration: a domain you leave out is removed, and an empty object clears every domain. Per the API reference, setting a domain to null clears that domain's nameservers.

tailscale_get_dns_preferencesB

Get DNS preferences for your tailnet, including whether MagicDNS is enabled.

tailscale_set_dns_preferencesA

Set DNS preferences for your tailnet, such as enabling or disabling MagicDNS. The API reference says enabling can fail when the tailnet has no nameservers; if it does, add one with tailscale_set_nameservers first.

tailscale_update_split_dnsA

Partially update split DNS configuration. Merges the provided domains with the existing config -- only the specified domains are changed, others are untouched. To remove a domain, set it to null: that is the idiom the API reference documents. An empty array is also accepted and forwarded as-is -- it is what Tailscale's Terraform provider sends.

tailscale_get_dns_configurationA

Get the unified DNS configuration for your tailnet, including nameservers, search paths, split DNS, and MagicDNS preference in a single call.

tailscale_set_dns_configurationA

Set the unified DNS configuration for your tailnet in a single call. Replaces all DNS settings (nameservers, search paths, split DNS, MagicDNS preference).

tailscale_list_keysA

List keys in your tailnet: auth keys, API access tokens, OAuth clients and federated identities. Without 'all', what comes back depends on the credential this server runs on -- a user-owned API key sees only that user's keys (including the API access token the server itself is using, keyType 'api'); an OAuth-client token sees the tailnet's OAuth clients; a federated-identity token sees its federated identities. Set 'all' to true for the tailnet-wide list (needs the matching :read scopes; only 'all:read' and 'all' return every API access token).

tailscale_get_keyA

Get details for a specific key (auth key, API access token, OAuth client, or federated identity). A revoked or expired key is still returned, with invalid: true.

tailscale_create_keyA

Create a new key in your tailnet. Supports auth keys (for adding devices), OAuth clients (for programmatic API access), and federated identities (for OIDC-based CI/CD access). Returns the key value -- save it immediately, as it cannot be retrieved again.

SECURITY: the response body contains a long-lived credential verbatim. MCP clients commonly persist tool responses to logs and conversation transcripts; treat this response as sensitive (do not commit it, avoid re-sharing it in unrelated chat history).

Examples:

  • Auth key: {keyType:'auth', reusable:true, tags:['tag:ci']}

  • OAuth client: {keyType:'client', scopes:['devices:core:read','dns:read']}

  • Federated (GitHub Actions): {keyType:'federated', scopes:['devices:core:read'], issuer:'https://token.actions.githubusercontent.com', subject:'repo:my-org/my-repo:*'}

tailscale_delete_keyA

Delete a key (auth key, API access token, OAuth client, or federated identity). This is irreversible. For auth keys, devices already authenticated are unaffected but no new devices can use it. For OAuth clients and federated identities, any integrations using them lose access immediately. API access tokens are deletable here too: if keyId is the token this server authenticates with -- it shows up in tailscale_list_keys under API-key auth -- the server revokes its own credential and every later call fails with 401 until it is reconfigured.

tailscale_update_keyA

Update an existing key. Supported fields depend on the key type: all key types accept 'description'; OAuth clients and federated identities additionally accept 'scopes' and 'tags'; federated identities additionally accept 'issuer', 'subject', 'audience', and 'customClaimRules'. For auth keys, pass only 'description' — the Tailscale API will reject other fields.

tailscale_create_oauth_appA

Create an OAuth App for device provisioning (Tailscale alpha). Lets a third-party application enroll a device into your tailnet via the authorization-code flow, after a user consents. Returns the app's client secret -- save it immediately, it cannot be retrieved again.

SECURITY: the response body contains a long-lived credential verbatim. MCP clients commonly persist tool responses to logs and conversation transcripts; treat this response as sensitive.

Use scope 'auth_keys:create:once' (one auth key per authorization, no refresh token) -- the scope Tailscale's device-provisioning guide documents. The API reference's example shows 'auth_keys:create'; this tool does not restrict the value. Distinct from tailscale_create_key with keyType='client', which mints a machine-to-machine OAuth client instead.

tailscale_get_oauth_appA

Get an OAuth App's configuration (name, redirect URIs, scopes) by its app ID. Use this to verify an app was registered as intended. The client secret is not returned -- it is only available at creation time.

tailscale_list_oauth_appsA

List the OAuth Apps registered in your tailnet (Tailscale alpha). Returns an oauthApps array describing each app (id, name, redirect URIs, scopes). Client secrets are NOT included -- a secret is only returned once, by tailscale_create_oauth_app at creation time. This is how you recover the id of an app you did not record; pass that id to tailscale_delete_oauth_app to revoke it.

tailscale_delete_oauth_appA

Delete an OAuth App (Tailscale alpha). This is irreversible: the app's client secret stops working immediately and any integration using it loses its device-enrollment path, so no further device can be authorized through it. Devices already enrolled stay in the tailnet, exactly as they do when the auth key that added them is deleted. Use tailscale_list_oauth_apps to find the id.

tailscale_list_usersB

List all users in your tailnet.

tailscale_get_userB

Get details for a specific user.

tailscale_approve_userA

Approve a pending user, granting them access to the tailnet.

tailscale_suspend_userA

Suspend a user, immediately revoking their access to the tailnet. Their devices will be disconnected. Can be reversed with tailscale_restore_user.

tailscale_restore_userA

Restore a previously suspended user, re-granting them access to the tailnet.

tailscale_update_user_roleB

Update a user's role in the tailnet.

tailscale_delete_userA

Delete a user from the tailnet. This is irreversible — the user and all their devices will be removed.

tailscale_get_tailnet_settingsA

Get your tailnet settings (device approval, key expiry, HTTPS certificates, etc.).

tailscale_update_tailnet_settingsB

Update tailnet settings (device approval, auto-updates, key expiry, HTTPS certificates, network flow logging, regional routing, posture identity collection).

tailscale_get_contactsA

Get the tailnet contact information (security, support, admin emails).

tailscale_set_contactsA

Update tailnet contact information. Each provided contact type (account/support/security) is PATCHed in parallel; per-type errors are returned alongside the successes so a partial failure doesn't lose the work that succeeded. On partial failure the response is data: { applied, failed } -- inspect data.failed for per-type error details.

tailscale_resend_contact_verificationC

Resend the verification email for a tailnet contact.

tailscale_list_org_tailnetsA

List the tailnets in your organization, including API-only tailnets created via the API. Paginated: returns at most limit results (Tailscale defaults to 100) plus a cursor. Pass that cursor back to fetch the next page; an empty cursor in the response means you have reached the end. Requires OAuth authentication.

tailscale_create_org_tailnetA

Create a new API-only tailnet in your organization. Returns the tailnet (id, displayName, orgId, dnsName, createdAt) AND a freshly-minted OAuth client for it.

SECURITY: the response body contains that OAuth client's secret verbatim, and it cannot be retrieved again. MCP clients commonly persist tool responses to logs and conversation transcripts; treat this response as sensitive.

Requires an OAuth client with the 'tailnets' scope -- an API key will not work. To then operate on the new tailnet, set TAILSCALE_OAUTH_TAILNET to its id and use an OAuth client with the 'all' scope.

Organizations are limited to 10 tailnets including the original unless Tailscale sales has raised the limit.

The response may include alreadyExists: true; Tailscale's spec ALSO documents a 400 for a name already in use and neither has been observed, so after a timeout call tailscale_list_org_tailnets before retrying rather than assuming either.

tailscale_delete_tailnetA

Permanently delete a tailnet. This is IRREVERSIBLE and removes every device, user, ACL, and key in it.

By default it acts on the tailnet the current credentials point at (TAILSCALE_TAILNET, or TAILSCALE_OAUTH_TAILNET when targeting an API-only tailnet). Pass tailnet to name a different one -- e.g. an id returned by tailscale_list_org_tailnets -- which requires credentials scoped to reach it; UNVERIFIED against a live tailnet, so expect a 403/404 if your token cannot. You must always pass confirmTailnet matching the effective target exactly; the call is refused locally otherwise. That check is a typo guard, not an authorization gate: when you also pass tailnet you are supplying both halves of the comparison, so it proves only that they agree -- it is a genuine second look only on the omit-tailnet path, where the value has to match the operator's environment. Restricting who may delete at all is TAILSCALE_READONLY / TAILSCALE_TOOLS, which drop this tool from the server entirely. Intended for tearing down API-only tailnets created by tailscale_create_org_tailnet.

tailscale_list_webhooksA

List all webhooks configured for your tailnet.

tailscale_get_webhookB

Get details for a specific webhook.

tailscale_create_webhookA

Create a new webhook. The response includes the webhook's signing secret -- this is the only opportunity to capture it; save it immediately. Set providerType when the endpoint is a Slack, Mattermost, Google Chat or Discord incoming-webhook URL, so the events arrive in the format that provider renders.

SECURITY: the response body contains the secret verbatim. MCP clients commonly persist tool responses to logs and conversation transcripts; treat this response as sensitive.

tailscale_update_webhookA

Update an existing webhook's endpoint URL and/or subscriptions.

tailscale_delete_webhookA

Delete a webhook. This is irreversible — the webhook secret cannot be recovered.

tailscale_rotate_webhook_secretA

Rotate a webhook's secret. Returns the new secret — save it immediately, as it cannot be retrieved again. The old secret is immediately invalidated.

SECURITY: the response body contains the secret verbatim. MCP clients commonly persist tool responses to logs and conversation transcripts; treat this response as sensitive.

tailscale_test_webhookA

Send a test event to a webhook endpoint to verify it is configured correctly and receiving events.

tailscale_list_posture_integrationsA

List all device posture integrations configured for your tailnet.

tailscale_get_posture_integrationA

Get details for a specific device posture integration.

tailscale_create_posture_integrationB

Create a new device posture integration.

tailscale_update_posture_integrationC

Update an existing posture integration's credentials or configuration.

tailscale_delete_posture_integrationB

Delete a posture integration. This is irreversible.

tailscale_get_audit_logA

Get the tailnet audit/configuration log. Shows who changed what and when -- useful for troubleshooting and compliance. Optional actor, target and event filters narrow the query server-side, so a targeted question doesn't have to pull the whole window.

tailscale_get_network_flow_logsA

Get network traffic flow logs showing connections between devices. Shows source/destination nodes, timestamps, and traffic metadata — useful for security monitoring and debugging connectivity.

tailscale_list_device_invitesA

List all device invites for a specific device.

tailscale_create_device_inviteA

Create a device share invitation that allows an external user to access a specific device in your tailnet.

tailscale_get_device_inviteC

Get details for a specific device invite.

tailscale_delete_device_inviteA

Delete a device invite. This is irreversible — the invite link will stop working.

tailscale_accept_device_inviteB

Accept a device share invitation using the invite URL or code.

tailscale_list_user_invitesA

List the open (not yet accepted) user invites for your tailnet. Accepted invites are not returned.

tailscale_create_user_inviteC

Create a new user invite that allows someone to join your tailnet.

tailscale_get_user_inviteB

Get details for a specific user invite.

tailscale_delete_user_inviteA

Delete a user invite. This is irreversible — the invite link will stop working.

tailscale_resend_device_inviteC

Resend a device invite email.

tailscale_resend_user_inviteB

Resend a user invite email.

tailscale_list_servicesA

List all Tailscale Services in your tailnet. Services provide stable MagicDNS names and virtual IPs, decoupled from individual devices. Note: services are created implicitly when a node first advertises one (tailscale up --advertise-services=svc:name); there is no API endpoint to create a service from this MCP. Use the update/delete/approval tools here once the service exists.

tailscale_get_serviceB

Get details for a specific Tailscale Service, including its MagicDNS name, virtual IP, and configuration.

tailscale_update_serviceC

Update a Tailscale Service's configuration.

tailscale_delete_serviceA

Delete a Tailscale Service. This is irreversible — the service's MagicDNS name and virtual IP will be released.

tailscale_list_service_hostsA

List devices hosting a specific Tailscale Service.

tailscale_get_service_device_approvalB

Get the approval status of a specific device for a Tailscale Service.

tailscale_set_service_device_approvalB

Approve or reject a device to host a Tailscale Service.

tailscale_list_log_stream_configsA

List all log streaming configurations for your tailnet. Fetches both 'configuration' (audit) and 'network' (flow) log stream configs. Log streaming sends logs to external destinations like Axiom, Datadog, Splunk, Elasticsearch, or S3.

tailscale_get_log_stream_configB

Get the log streaming configuration for a specific log type.

tailscale_set_log_stream_configA

Set the log streaming configuration for a specific log type. Configures where logs are sent (e.g. Axiom, Datadog, Splunk, Elasticsearch, S3).

Per-destination required fields:

  • splunk / elastic / panther / cribl / datadog / axiom: url + token (user optional)

  • s3: s3Bucket + s3Region + s3AuthenticationType, plus either (s3AccessKeyId + s3SecretAccessKey) for 'accesskey' auth or s3RoleArn for 'rolearn' auth. Call tailscale_create_aws_external_id first when using 'rolearn'.

tailscale_delete_log_stream_configA

Delete a log streaming configuration. Logs will stop being sent to the configured destination.

tailscale_get_log_stream_statusA

Get the status of log streaming for a specific log type. Shows whether logs are being delivered successfully.

tailscale_create_aws_external_idA

Create or get the AWS external ID Tailscale presents when assuming your IAM role for S3 log streaming. Put it in the role trust policy's sts:ExternalId condition, then check it with tailscale_validate_aws_trust_policy.

tailscale_validate_aws_trust_policyA

Validate that an AWS IAM role trust policy is correctly configured with the Tailscale external ID. Use this after setting up the IAM role for S3 log streaming.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription
tailnet-statusCurrent tailnet status including device count and settings
tailnet-devicesList of all devices in the tailnet with their status
tailnet-aclCurrent ACL policy (HuJSON with comments preserved)
tailnet-dnsDNS configuration including nameservers, search paths, split DNS, and MagicDNS status

TDQS

A3.5/5.0

Scored across 98 tools

Disambiguation4/5

Most tools are clearly separated by resource and action (devices, users, ACL, DNS, services, webhooks, keys, etc.), so an agent can usually tell them apart. Some overlap exists between the unified DNS getter/setter and the individual DNS tools, and between single-device and batch operations, but the descriptions explain the distinctions. With 98 tools, a few pairs still risk misselection.

Naming Consistency4/5

Almost all tools follow the tailscale_verb_noun pattern (list_devices, create_webhook, delete_device, update_acl), which is highly consistent. Minor exceptions like tailscale_status and tailscale_tool_groups break the verb_noun pattern, and a few singular/plural mismatches (set_device_posture_attribute vs get_device_posture_attributes) keep it from being perfect.

Tool Count2/5

98 tools is far beyond the well-scoped range and even the heavy 25+ threshold. While Tailscale's API is broad, this is too many tools for one MCP server; agents will struggle to navigate the surface. Many tools could be consolidated (e.g., unified DNS vs individual DNS setters) or split into domain-specific servers.

Completeness5/5

The tool set covers essentially the full Tailscale management surface: devices, users, invites, keys, ACL, DNS, services, posture integrations, webhooks, log streaming, OAuth apps, tailnet settings, contacts, audit logs, and network flow logs. CRUD/lifecycle operations are present for each resource, and destructive operations are paired with getters/listers, leaving no obvious dead ends.

Maintenance

ActivityActive
ResponsivenessUnresponsive