TailscaleCAUTION
server that provides seamless integration with Tailscale's CLI commands and REST API, enabling automated network management and monitoring through a standardized interface
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server for operating Tailscale from any MCP client. Supports local stdio for desktop clients and an authenticated HTTP transport for private tailnet deployments. Defaults to read-only access, localhost binding, and short-lived OAuth credentials where available.
Table of Contents
- Features
- Requirements
- Quick Start
- Claude Desktop
- Claude Code (CLI)
- Cursor
- Tool Reference
- Resources and Prompts
- Configuration
- HTTP Transport
- Docker
- Example Prompts
- Development
- Contributing
Features
- Device management — list, authorize, deauthorize, delete, expire keys, manage routes.
- Network operations — connect/disc
1efe97ac13a9OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add tailscale-mcp-server --env TAILSCALE_API_KEY=${TAILSCALE_API_KEY} -- npx -y @hexsleeves/[email protected]{
"mcpServers": {
"tailscale-mcp-server": {
"command": "npx",
"args": [
"-y",
"@hexsleeves/[email protected]"
],
"env": {
"TAILSCALE_API_KEY": "${TAILSCALE_API_KEY}"
}
}
}
}Exposed tools (19)
19 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
connect_network | read | |
device_action | read | |
disconnect_network | read | |
get_network_status | read | |
get_tailnet_info | read | |
get_version | read | |
get_version_info | read | |
list_devices | read | |
manage_acl | read | |
manage_device_tags | read | |
manage_dns | read | |
manage_exit_nodes | read | |
manage_file_sharing | read | |
manage_keys | read | |
manage_network_lock | read | |
manage_policy_file | read | |
manage_routes | read | |
manage_webhooks | read | |
ping_peer | read |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (6 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (12)
CMD bun -e "fetch('http://127.0.0.1:3000/health').then(r => process.exit(r.ok ? 0 : 1)).catch(() => process.exit(1))""Proxy": "http://127.0.0.1:$port"
expect(() => validateTarget("~/.ssh/id_rsa")).toThrow();import { loadConfig } from "../../config/env.js";import { registerAclTools } from "../../mcp/tools/acl.js";import { registerAdminTools } from "../../mcp/tools/admin.js";import { DevicesOutputSchema } from "../../mcp/schemas/tool-results.js";import { registerDeviceTools } from "../../mcp/tools/devices.js";to `http://127.0.0.1:${MCP_HTTP_PORT}`.tailscale serve --bg --https=443 http://127.0.0.1:3000
"http://127.0.0.1:8080",
curl -fsSL https://tailscale.com/install.sh | sh
Gates applied: no_behavioural_pass.
1efe97ac13a9full audit observations/trust-audit/mcp-server/hexsleeves__tailscale-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 1efe97ac13a9 | CAUTION | B | 89 | first audit |
Questions
What is the Tailscale MCP server?
server that provides seamless integration with Tailscale's CLI commands and REST API, enabling automated network management and monitoring through a standardized interface
What tools does Tailscale expose?
19 in total: 19 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Tailscale safe to connect to an agent?
With care. The audit graded it B (89/100) and found 12 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Tailscale need?
It reads TAILSCALE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Tailscale run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @hexsleeves/tailscale-mcp-server at 1.3.4.
How current is this page?
The grade is for one exact copy of the source (1efe97ac13a9), read on 2026-10-07. The repository is watched and re-audited when it changes.