Tailscale MCP Server

Tailscale MCP Server is an MCP server that connects AI assistants to the Tailscale API and local Tailscale command-line interface. Built for systems administrators, DevOps engineers, and network operators, it enables large language models to inspect, diagnose, and configure private tailnets directly from MCP-compliant clients. The server supports both local standard input/output execution for desktop workflows and an authenticated HTTP transport tailored for private network deployments behind Tailscale Serve. Users can monitor overall network status, ping peers, examine connected devices, and inspect tailnet summary metrics. Through risk-gated access tiers categorized by read, write, and admin permissions, operators can control an assistant's ability to update access control lists, manage advertised routes, change DNS records, manage webhooks, and cycle authentication keys. It also provides built-in prompt templates to assist in connectivity diagnostics and policy review workflows. Default settings enforce read-only visibility, ensuring secure operations across private infrastructure.

Category: Cloud & Infrastructure

Tags: infrastructure, networking, security, tailscale, vpn

Visit Tailscale MCP Server

How to install and configure Tailscale MCP Server

  1. Ensure Node.js 20+, Bun, or Docker is installed on your system. 2. Obtain a Tailscale OAuth client ID and client secret, or an API key, from the Tailscale admin console. 3. Open your client configuration file, such as ~/.claude/claude_desktop_config.json for Claude Desktop or .cursor/mcp.json for Cursor. 4. Add the server configuration under mcpServers: json { "mcpServers": { "tailscale": { "command": "npx", "args": ["-y", "@hexsleeves/tailscale-mcp-server"], "env": { "TAILSCALE_OAUTH_CLIENT_ID": "your-client-id", "TAILSCALE_OAUTH_CLIENT_SECRET": "your-client-secret", "TAILSCALE_TAILNET": "-" } } } } 5. Optionally set TAILSCALE_ALLOWED_TOOL_RISK to write or admin in the env object to enable mutating actions. 6. Restart your MCP client to initialize the server.

What you can do with Tailscale MCP Server

  • Diagnosing tailnet connectivity by running guided diagnostics, inspecting network status via local CLI, and pinging peer nodes. - Inspecting and auditing tailnet device inventories, route advertisements, and node tags to maintain network visibility across environments. - Reviewing, validating, and updating tailnet access control policies and DNS configurations without manually editing JSON files in the browser. - Automating auth key provisioning, key expiry, and device authorization during infrastructure onboarding with gated administrative safeguards. - Managing exit nodes and advertised subnet routes dynamically during remote debugging and cloud infrastructure setup.

Key facts

  • https://github.com/HexSleeves/tailscale-mcp
  • Cloud & Infrastructure, DevOps, CI/CD & Version Control
  • infrastructure, networking, security, tailscale, vpn

Part of MCP Servers

Related MCP servers

  • MCP KQL Server β€” MCP KQL Server is an MCP server that connects AI assistants to Azure Data Explorer clusters using Azure CLI authentication.…
  • MCP Media Player β€” MCP Media Player is an MCP server that exposes playback controls for Home Assistant media players to AI agents. It…
  • MCP Kubernetes Server β€” MCP Kubernetes Server is an MCP server that provides tools for managing and inspecting Kubernetes clusters directly through Large Language…
  • MCP Nomad Go β€” MCP Nomad Go is an MCP server that connects AI assistants to HashiCorp Nomad clusters. Written in Go, it allows…
  • MCP Minecraft Remote β€” MCP Minecraft Remote is an MCP server that enables AI assistants to remotely connect to and control a player character…
  • MCP My Mac β€” MCP My Mac is an MCP server that exposes macOS system hardware specifications, system configurations, and environment details to AI…

How do I install Tailscale MCP Server?

You can run Tailscale MCP Server using npx with Node.js 20 or Bun, or execute it via Docker. In your MCP client configuration, such as Claude Desktop or Cursor, configure the command to launch the npm package @hexsleeves/tailscale-mcp-server with your Tailscale OAuth credentials or API key passed as environment variables.

What can Tailscale MCP Server do?

The server allows LLM assistants to query device status, ping network peers, validate and modify access control list policies, adjust DNS configurations, and manage subnet routes. It also supports administrative actions such as authoring auth keys, managing exit nodes, and modifying device authorization tags based on configured risk permissions.

Which MCP clients work with Tailscale MCP Server?

Tailscale MCP Server functions with any client compatible with the Model Context Protocol. This includes Claude Desktop, Claude Code CLI, and Cursor using the standard input and output transport, as well as remote tailnet setups operating over private HTTP bearer token connections.

How does risk management work in Tailscale MCP Server?

The server restricts capabilities using the TAILSCALE_ALLOWED_TOOL_RISK environment variable. By default, it operates in read mode to protect configurations. Setting the variable to write unlocks policy, route, and tag updates, while setting it to admin permits potentially disruptive operations like disconnecting hosts or revoking authorization keys.

Is Tailscale MCP Server open source?

Yes, Tailscale MCP Server is open source and distributed under the MIT License. Its source repository, issue tracker, and release artifacts are maintained publicly on GitHub.

  • AI Tools
  • Categories
  • Industries
  • CLI Coding Agents
  • MCP Servers
  • MCP Categories