Update ACL policy
tailscale_update_aclUpdate your Tailscale ACL policy safely by passing the full policy text and current ETag to prevent overwriting concurrent changes. Preserves formatting and comments.
Instructions
Update the ACL policy for your tailnet. Accepts the full policy as a string to preserve formatting, comments, and trailing commas (HuJSON). You MUST pass the ETag from tailscale_get_acl to prevent overwriting concurrent changes, or ts-default for the first write to a tailnet nobody has edited yet. Always get the current ACL first, make targeted edits to the text, and pass the full modified text back.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| etag | Yes | The ETag from tailscale_get_acl (quotes optional -- they are normalized). Required to prevent concurrent edit conflicts. For the FIRST write to a fresh tailnet you may pass `ts-default` instead: the update then succeeds only if the policy file is still Tailscale's untouched default. | |
| policy | Yes | The full ACL policy text. Preserve existing formatting, comments, and structure. Only modify the specific parts that need to change. |