Tailscale EchoSAFE
Identity aware MCP server example using Tailscale serve.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Create an identiy aware MCP server that runs inside your private Tailscale network (Tailnet). This example leverages identity headers that are passed through to applications running behind tailscale serve.
Using this as starting point you can create MCP servers that are identity aware (with access to the logged in user's email) and can access internal APIs or services on thier behalf.
Instructions
Starting the Server
- If you don't already have a Tailnet setup you'll need to signup for one.
- Create an API auth key and save it into a
.envfile in the root of this project with the following format:TS_AUTHKEY=tskey-auth-... - With Docker already installed, run
docker compose upto start the server.
This will spin up two containers. The MCP server and a Tailscale container running tailscale serve as a proxy to your tailnet.
Using the Server
If you have an MCP Client that supports direct access to Streaming HTTP MCP servers, then you should be able to connect to the server by pointing it to https://ts-mcp-echo.yourtailnetname.ts.net/mcp.
Claude Desktop
Claude desktop does not currently support remote MCP servers (only stdio), but you can use the mcp-remote tool (or any other proxy) to connect to it.
- Install mcp-remote with
npm install -g mcp-remote - Add the following configuration to your
claude_desktop_config.jsonfile:
{
"mcpServers": {
"tailscale-remote-echo-example": {
"command": "npx",
"args": [
"mcp-remote",
"https://ts-mcp-echo.yourtailnetname.ts.net/mcp"
]
604265f032dbOBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add tailscale-mcp-echo -- uvx tailscale-mcp-echo
{
"mcpServers": {
"tailscale-mcp-echo": {
"command": "uvx",
"args": [
"tailscale-mcp-echo"
]
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
greet | read | req: Request = get_http_request() |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
streamable-http
Gates applied: no_behavioural_pass.
604265f032dbfull audit observations/trust-audit/mcp-server/remyguercio__tailscale-echo.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 604265f032db | SAFE | B | 89 | first audit |
Questions
What is the Tailscale Echo MCP server?
Identity aware MCP server example using Tailscale serve.
What tools does Tailscale Echo expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Tailscale Echo safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Tailscale Echo need?
No credential environment variables were found in its source, so it appears to need none.
How does Tailscale Echo run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as tailscale-mcp-echo.
How current is this page?
The grade is for one exact copy of the source (604265f032db), read on 2026-10-09. The repository is watched and re-audited when it changes.