Tailscale MCP Server
by tailscale-mcpio.github.tailscale-mcp/tailscale-mcpv1.3.2
Drive a Tailscale node and its tailnet through the CLI and the control-plane API
context tax
queued
security
queued
cold start
queued
freshness
Active3d ago
Install Tailscale MCP server
Install in Claude Code
claude mcp add tailscale-tailscale-mcp -e TAILSCALE_API_KEY='<tailscale-api-key>' -e TAILSCALE_OAUTH_CLIENT_SECRET='<tailscale-oauth-client-secret>' -- npx -y @tailscale-mcp/tailscale-mcpInstall in Cursor
{
"mcpServers": {
"tailscale-tailscale-mcp": {
"command": "npx",
"args": [
"-y",
"@tailscale-mcp/tailscale-mcp"
],
"env": {
"TAILSCALE_API_KEY": "<tailscale-api-key>",
"TAILSCALE_OAUTH_CLIENT_SECRET": "<tailscale-oauth-client-secret>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"tailscale-tailscale-mcp": {
"command": "npx",
"args": [
"-y",
"@tailscale-mcp/tailscale-mcp"
],
"env": {
"TAILSCALE_API_KEY": "<tailscale-api-key>",
"TAILSCALE_OAUTH_CLIENT_SECRET": "<tailscale-oauth-client-secret>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"tailscale-tailscale-mcp": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@tailscale-mcp/tailscale-mcp"
],
"env": {
"TAILSCALE_API_KEY": "<tailscale-api-key>",
"TAILSCALE_OAUTH_CLIENT_SECRET": "<tailscale-oauth-client-secret>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"tailscale-tailscale-mcp": {
"command": "npx",
"args": [
"-y",
"@tailscale-mcp/tailscale-mcp"
],
"env": {
"TAILSCALE_API_KEY": "<tailscale-api-key>",
"TAILSCALE_OAUTH_CLIENT_SECRET": "<tailscale-oauth-client-secret>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| TAILSCALE_API_KEY | — | yes | A control-plane API access token. One of this, the OAuth client pair, or the OAuth JWT file is needed for the tailnet tools; without any of them only the local tools are offered. |
| TAILSCALE_OAUTH_CLIENT_ID | — | — | An OAuth client id, used with TAILSCALE_OAUTH_CLIENT_SECRET when there is no API access token. |
| TAILSCALE_OAUTH_CLIENT_SECRET | — | yes | The OAuth client secret that goes with TAILSCALE_OAUTH_CLIENT_ID. |
| TAILSCALE_TAILNET | — | — | The tailnet the control-plane tools act on. Without it they act on the one the credential belongs to. |
| TAILSCALE_MCP_PRESET | — | — | Which tools are offered: minimal, core or full. |
| TAILSCALE_MCP_ALLOW_WRITE | — | — | Offer the tools that change something. Read-only without it. |
| TAILSCALE_MCP_ALLOW_DESTRUCTIVE | — | — | Offer the tools that remove or sever something. Implies the write tier. |
Freshness
Active — last maintenance signal 3d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-10-07 · 3d ago · GitHub
Latest release
2026-10-07 · 3d ago · GitHub · v1.3.2
Package published
no data · npm/PyPI
Registry entry updated
2026-10-07 · 3d ago · official registry · v1.3.2
FAQ
›How do I install the Tailscale MCP server in Claude Code?
Run: claude mcp add tailscale-tailscale-mcp -e TAILSCALE_API_KEY='<tailscale-api-key>' -e TAILSCALE_OAUTH_CLIENT_SECRET='<tailscale-oauth-client-secret>' -- npx -y @tailscale-mcp/tailscale-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Tailscale require an API key?
Yes. It expects TAILSCALE_API_KEY, TAILSCALE_OAUTH_CLIENT_SECRET, of which 2 are secrets.
›Can I use Tailscale as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Tailscale in the official MCP registry?
Yes, as io.github.tailscale-mcp/tailscale-mcp.