Skip to main content
Glama
YawLabs

@yawlabs/tailscale-mcp

by YawLabs

Create webhook

tailscale_create_webhook

Create a webhook to receive Tailscale events at an HTTPS endpoint. Provides a signing secret for verification; save it immediately, and optionally format deliveries for Slack, Mattermost, Google Chat, or Discord.

Instructions

Create a new webhook. The response includes the webhook's signing secret -- this is the only opportunity to capture it; save it immediately. Set providerType when the endpoint is a Slack, Mattermost, Google Chat or Discord incoming-webhook URL, so the events arrive in the format that provider renders.

SECURITY: the response body contains the secret verbatim. MCP clients commonly persist tool responses to logs and conversation transcripts; treat this response as sensitive.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
endpointUrlYesThe HTTPS URL to send webhook events to
providerTypeNoFormat deliveries for a chat provider's incoming-webhook URL. Omit for raw Tailscale JSON -- the default, and what a custom receiver verifying signatures wants. Set once: it cannot be changed after creation.
subscriptionsYesEvent types to subscribe to (at least one). 'categoryTailnetManagement' and 'categoryDeviceMisconfigurations' subscribe to a whole category, including events Tailscale adds to it later.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed3 schema fields changedv0.21.0
    • addedInput schema / properties / providerType
      Added value: +{
      +  "description": "Format deliveries for a chat provider's incoming-webhook URL. Omit for raw Tailscale JSON -- the default, and what a custom receiver verifying signatures wants. Set once: it cannot be changed after creation.",
      +  "enum": [
      +    "slack",
      +    "mattermost",
      +    "googlechat",
      +    "discord"
      +  ],
      +  "type": "string"
      +}
    • changedInput schema / properties / subscriptions / description
      Previous value: -"Event types to subscribe to (at least one)"New value: +"Event types to subscribe to (at least one). 'categoryTailnetManagement' and 'categoryDeviceMisconfigurations' subscribe to a whole category, including events Tailscale adds to it later."
    • changedInput schema / properties / subscriptions / items / enum
      Previous value: -[
      -  "exitNodeIPForwardingNotEnabled",
      -  "nodeApproved",
      -  "nodeCreated",
      -  "nodeDeleted",
      -  "nodeKeyExpired",
      -  "nodeKeyExpiringInOneDay",
      -  "nodeNeedsApproval",
      -  "nodeNeedsSignature",
      -  "nodeSigned",
      -  "policyUpdate",
      -  "subnetIPForwardingNotEnabled",
      -  "userApproved",
      -  "userCreated",
      -  "userDeleted",
      -  "userNeedsApproval",
      -  "userRestored",
      -  "userRoleUpdated",
      -  "userSuspended"
      -]New value: +[
      +  "categoryDeviceMisconfigurations",
      +  "categoryTailnetManagement",
      +  "exitNodeIPForwardingNotEnabled",
      +  "nodeApproved",
      +  "nodeCreated",
      +  "nodeDeleted",
      +  "nodeKeyExpired",
      +  "nodeKeyExpiringInOneDay",
      +  "nodeNeedsApproval",
      +  "nodeNeedsSignature",
      +  "nodeSigned",
      +  "policyUpdate",
      +  "subnetIPForwardingNotEnabled",
      +  "userApproved",
      +  "userCreated",
      +  "userDeleted",
      +  "userNeedsApproval",
      +  "userRestored",
      +  "userRoleUpdated",
      +  "userSuspended"
      +]
  2. Changed1 schema field changedv0.17.1
    • addedInput schema / properties / subscriptions / items / enum
      Added value: +[
      +  "exitNodeIPForwardingNotEnabled",
      +  "nodeApproved",
      +  "nodeCreated",
      +  "nodeDeleted",
      +  "nodeKeyExpired",
      +  "nodeKeyExpiringInOneDay",
      +  "nodeNeedsApproval",
      +  "nodeNeedsSignature",
      +  "nodeSigned",
      +  "policyUpdate",
      +  "subnetIPForwardingNotEnabled",
      +  "userApproved",
      +  "userCreated",
      +  "userDeleted",
      +  "userNeedsApproval",
      +  "userRestored",
      +  "userRoleUpdated",
      +  "userSuspended"
      +]
  3. First observedv0.13.3

TDQS

A4.3/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description discloses the most important behavioral trait: the signing secret appears only once in the response and must be saved immediately. It also adds a security warning that MCP clients may persist responses to logs, which is valuable context beyond the annotations. The annotations already indicate this is a non-read, non-idempotent, non-destructive operation, and the description complements them with the one-time-secret and providerType-immutability details.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is compact and front-loaded: the one-time secret warning appears in the first sentence, followed by providerType guidance and a security note. Every sentence earns its place, and the SECURITY section is clearly separated. No filler or repetition of schema content.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a create operation with no output schema, the description covers the critical response behavior (one-time secret), the key parameter decision (providerType), and the security implications. It doesn't describe the full response shape or error cases, but the essential information an agent needs to call this correctly and handle the result is present.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the schema already documents all three parameters. The description adds value by explaining the consequence of providerType (format deliveries for chat providers, cannot be changed after creation) and the consequence of subscriptions (category subscriptions include future events). This goes beyond the schema's basic descriptions, though it doesn't add syntax details for endpointUrl.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb and resource ('Create a new webhook') and adds the critical detail that the response contains a one-time signing secret. It doesn't explicitly differentiate from sibling tools like tailscale_update_webhook or tailscale_test_webhook, but the create semantics are clear enough that an agent can distinguish it from list/get/delete/update siblings.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives clear context on when to set providerType (when the endpoint is a Slack, Mattermost, Google Chat or Discord incoming-webhook URL) and when to omit it (raw Tailscale JSON for custom receivers verifying signatures). It doesn't explicitly say 'use tailscale_update_webhook to modify later' or 'use tailscale_test_webhook to test', but the create-vs-alternative distinction is reasonably inferable from the sibling names and the description's focus on creation-time constraints.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools