{
 "categories": [
  "identity",
  "devsecops"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-10-01",
   "fact": "homepage",
   "note": "The Tailscale llms.txt describes Tailscale as a zero-trust identity-based connectivity platform for remote teams, multi-cloud networks, CI/CD, and edge devices.",
   "source": "https://tailscale.com/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-10-01",
   "fact": "license",
   "note": "The Personal plan is free. Standard is $8 per user per month and Premium is $18 per user per month. Enterprise is custom.",
   "source": "https://tailscale.com/pricing",
   "tier": "declared"
  },
  {
   "date": "2026-10-01",
   "fact": "deployment",
   "note": "The API and admin console are Tailscale-hosted. Access tokens are created on the Keys page of the admin console.",
   "source": "https://tailscale.com/docs/reference/tailscale-api",
   "tier": "declared"
  },
  {
   "date": "2026-10-01",
   "fact": "platforms",
   "note": "The CLI page documents Linux, macOS, and Windows clients, and states that iOS and Android have no CLI. The admin console used for keys and webhooks is a web application.",
   "source": "https://tailscale.com/docs/reference/tailscale-cli",
   "tier": "declared"
  },
  {
   "date": "2026-10-01",
   "fact": "modalities.api.exists",
   "note": "Tailscale documents an API for automating the network. The page says the API is available for all plans.",
   "source": "https://tailscale.com/docs/reference/tailscale-api",
   "tier": "declared"
  },
  {
   "date": "2026-10-01",
   "fact": "modalities.api.kinds[0]",
   "note": "OAuth examples call HTTPS endpoints under https://api.tailscale.com/api/v2/, including GET /api/v2/tailnet/-/devices and POST to the token endpoint.",
   "source": "https://tailscale.com/docs/features/oauth-clients",
   "tier": "declared"
  },
  {
   "date": "2026-10-01",
   "fact": "modalities.api.auth[0]",
   "note": "An access token, also called an API key, is created on the Keys page of the admin console. The caller chooses an expiry from 1 to 90 days inclusive.",
   "source": "https://tailscale.com/docs/reference/tailscale-api",
   "tier": "declared"
  },
  {
   "date": "2026-10-01",
   "fact": "modalities.api.auth[1]",
   "note": "OAuth clients use the OAuth 2.0 client-credentials grant at https://api.tailscale.com/api/v2/oauth/token. The returned access token expires after one hour and is limited to the client's scopes.",
   "source": "https://tailscale.com/docs/features/oauth-clients",
   "tier": "declared"
  },
  {
   "date": "2026-10-01",
   "fact": "modalities.api.coverage",
   "note": "The opened OAuth guide names device, DNS nameserver, DNS preference, DNS search-path, and key endpoints, and says scopes are limited to the endpoints an operation needs. That is a partial map of the v2 API.",
   "source": "https://tailscale.com/docs/features/oauth-clients",
   "tier": "declared"
  },
  {
   "date": "2026-10-01",
   "fact": "modalities.api.docs",
   "note": "Opened as the current Tailscale API overview. The page was marked last validated Jun 24, 2026.",
   "source": "https://tailscale.com/docs/reference/tailscale-api",
   "tier": "declared"
  },
  {
   "date": "2026-10-01",
   "fact": "modalities.mcp.first_party",
   "note": "Tailscale documents two Aperture connectors, Tailnet and Tailscale SSH, whose tools ship with the product and use protocol mcp. They are marked alpha. Tools are Tailnet_provision_node, TailnetSSH_list_machines, and TailnetSSH_run_command.",
   "source": "https://tailscale.com/docs/aperture/connectors/built-in-connectors",
   "tier": "declared"
  },
  {
   "date": "2026-10-01",
   "fact": "modalities.mcp.verdict",
   "note": "The built-in connectors page is Tailscale's own documentation and says Aperture supplies the tools instead of polling an upstream MCP server.",
   "source": "https://tailscale.com/docs/aperture/connectors/built-in-connectors",
   "tier": "declared"
  },
  {
   "date": "2026-10-01",
   "fact": "modalities.mcp.third_party[0]",
   "note": "The YawLabs README describes a third-party Tailscale v2 admin server for devices, ACLs, DNS, keys, and users. The GitHub API reported the repo unarchived, MIT-licensed, and pushed at 2026-09-30T13:47:17Z.",
   "source": "https://github.com/YawLabs/tailscale-mcp",
   "tier": "community"
  },
  {
   "date": "2026-10-01",
   "fact": "modalities.mcp.third_party[0]",
   "note": "A latest-version registry search for tailscale on 2026-10-01 listed io.github.YawLabs/tailscale-mcp. No com.tailscale server name was in that result set. The Aperture connectors are documented by Tailscale outside this registry.",
   "source": "https://registry.modelcontextprotocol.io/v0.1/servers?search=tailscale&version=latest",
   "tier": "scraped"
  },
  {
   "date": "2026-10-01",
   "fact": "modalities.mcp.third_party[1]",
   "note": "The jaxxstorm README describes an independent server that serves Streamable HTTP on /mcp and uses Tailscale OAuth grants. The GitHub API reported the repo unarchived, not a fork, and pushed at 2026-09-23T10:58:04Z.",
   "source": "https://github.com/jaxxstorm/tailscale-mcp",
   "tier": "community"
  },
  {
   "date": "2026-10-01",
   "fact": "modalities.cli.exists",
   "note": "Tailscale documents the tailscale CLI for managing the local device. It is available on all plans for Linux, macOS, and Windows.",
   "source": "https://tailscale.com/docs/reference/tailscale-cli",
   "tier": "declared"
  },
  {
   "date": "2026-10-01",
   "fact": "modalities.extensibility.webhooks",
   "note": "Tailscale sends HTTPS POST webhook events for node, user, policy, and webhook-management changes. Endpoints are configured in the admin console and signed with a Tailscale-Webhook-Signature HMAC.",
   "source": "https://tailscale.com/docs/features/webhooks",
   "tier": "declared"
  },
  {
   "date": "2026-10-01",
   "fact": "modalities.data_access.export[0]",
   "note": "Webhook events are JSON objects in an array, with timestamp, version, type, tailnet, message, and optional data.",
   "source": "https://tailscale.com/docs/features/webhooks",
   "tier": "declared"
  },
  {
   "date": "2026-10-01",
   "fact": "modalities.agent_docs.llms_txt",
   "note": "https://tailscale.com/llms.txt is a plain-text index that points agents at the Tailscale documentation.",
   "source": "https://tailscale.com/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-10-01",
   "fact": "verdict.scores.api",
   "note": "The v2 API supports access tokens that expire in 1 to 90 days and scoped OAuth client credentials whose tokens expire in one hour. Documented calls cover devices, DNS, and auth keys on every plan, which is useful production coverage with those lifetime and scope limits.",
   "source": "https://tailscale.com/docs/features/oauth-clients",
   "tier": "declared"
  },
  {
   "date": "2026-10-01",
   "fact": "verdict.scores.mcp",
   "note": "The official MCP tools are an alpha Aperture preview with three tools for one-time node provisioning and a single SSH command. YawLabs and jaxxstorm maintain broader third-party servers. That is a limited vendor preview plus community servers, scored 6.",
   "source": "https://tailscale.com/docs/aperture/connectors/built-in-connectors",
   "tier": "declared"
  },
  {
   "date": "2026-10-01",
   "fact": "verdict.scores.cli",
   "note": "The official CLI manages and troubleshoots the local device on Linux, macOS, and Windows. The same page says there is no CLI support for iOS and Android, so the CLI is a device path with that platform limit.",
   "source": "https://tailscale.com/docs/reference/tailscale-cli",
   "tier": "declared"
  },
  {
   "date": "2026-10-01",
   "fact": "freshness.watch[0].url",
   "note": "Opened the Tailscale API overview. Access tokens from the Keys page and the all-plans note are still there.",
   "source": "https://tailscale.com/docs/reference/tailscale-api",
   "tier": "declared"
  },
  {
   "date": "2026-10-01",
   "fact": "freshness.watch[1].url",
   "note": "Opened the OAuth clients page. The token endpoint and one-hour access tokens match the record.",
   "source": "https://tailscale.com/docs/features/oauth-clients",
   "tier": "declared"
  },
  {
   "date": "2026-10-01",
   "fact": "freshness.watch[2].url",
   "note": "Opened the Aperture built-in connectors page. Tailnet and Tailscale SSH remain alpha MCP connectors.",
   "source": "https://tailscale.com/docs/aperture/connectors/built-in-connectors",
   "tier": "declared"
  },
  {
   "date": "2026-10-01",
   "fact": "freshness.watch[3].url",
   "note": "Opened the YawLabs README and the GitHub API record. The repo was unarchived and pushed on 2026-09-30.",
   "source": "https://github.com/YawLabs/tailscale-mcp",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-10-01",
  "volatility": "high",
  "watch": [
   {
    "type": "docs",
    "url": "https://tailscale.com/docs/reference/tailscale-api"
   },
   {
    "type": "docs",
    "url": "https://tailscale.com/docs/features/oauth-clients"
   },
   {
    "type": "mcp",
    "url": "https://tailscale.com/docs/aperture/connectors/built-in-connectors"
   },
   {
    "type": "repository",
    "url": "https://github.com/YawLabs/tailscale-mcp"
   }
  ]
 },
 "homepage": "https://tailscale.com/",
 "id": "tailscale",
 "license": "freemium",
 "modalities": {
  "agent_docs": {
   "llms_txt": true
  },
  "api": {
   "auth": [
    "access-token",
    "oauth2-client-credentials"
   ],
   "coverage": "partial",
   "docs": "https://tailscale.com/docs/reference/tailscale-api",
   "exists": true,
   "kinds": [
    "rest"
   ]
  },
  "cli": {
   "exists": true
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "json"
   ],
   "import": []
  },
  "extensibility": {
   "scripting": [],
   "webhooks": true
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": true,
   "third_party": [
    {
     "maintained": true,
     "registries": [
      "official-mcp-registry",
      "github"
     ],
     "repo": "https://github.com/YawLabs/tailscale-mcp"
    },
    {
     "maintained": true,
     "registries": [
      "github"
     ],
     "repo": "https://github.com/jaxxstorm/tailscale-mcp"
    }
   ],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. The Tailscale API, the tailscale CLI, webhooks, and MCP connectors cover tailnet administration and device registration without a measured browser probe.\n",
   "ui_stack": [
    "web-dom"
   ],
   "vendor_support": []
  },
  "sdk": {
   "exists": "unknown",
   "languages": [],
   "official": "unknown"
  }
 },
 "name": "Tailscale",
 "platforms": [
  "linux",
  "macos",
  "windows",
  "ios",
  "android",
  "web"
 ],
 "related": {
  "alternatives": [
   "cloudflare"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Tailscale",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 7,
   "cli": 6,
   "computer_use": null,
   "integrations": null,
   "mcp": 6,
   "overall": 7,
   "rpa": null
  },
  "summary": "Tailscale is automatable today through the Tailscale API. This record is the tailnet control plane for devices, users, auth keys, DNS, and ACL policy. The API is available on all plans. Owners, Admins, IT admins, and Network admins create an access token on the Keys page. Tokens expire after 1 to 90 days and are sent as Authorization Bearer or as HTTP basic with an empty password. OAuth clients use the client-credentials flow at https://api.tailscale.com/api/v2/oauth/token. Those access tokens expire after one hour and are limited to the scopes selected for the client. Documented examples include GET /api/v2/tailnet/-/devices, DNS nameserver and preference reads, and POST /api/v2/tailnet/-/keys for auth keys. The tailscale CLI manages the local device on Linux, macOS, and Windows. tailscale up accepts an OAuth client secret as --auth-key when the client has the auth_keys scope. There is no CLI for iOS or Android. Webhooks POST JSON events for node, user, and policy changes, and each endpoint has an HMAC SHA-256 signing secret. Tailscale Aperture ships two alpha built-in MCP connectors. Tailnet_provision_node returns a single-use auth key after a person approves it. TailnetSSH_list_machines and TailnetSSH_run_command list SSH-enabled machines and run one command. An admin must enable each connector. Two maintained third-party servers also target the admin API. YawLabs/tailscale-mcp maps devices, ACLs, DNS, keys, and users. jaxxstorm/tailscale-mcp serves Streamable HTTP on /mcp and uses Tailscale OAuth grants. https://tailscale.com/llms.txt is a short documentation index. iPaaS connector catalogs were not opened. Computer-use viability is unassessed. API scores 7 and is the best path. The official MCP connectors are an alpha preview inside Aperture, so MCP scores 6.\n"
 }
}