io.usefulapi/tailscale

Tailscale MCP by usefulapi

Read devices, users, keys, ACLs and DNS for a tailnet; manage devices, routes and auth keys.

1.11.1
Version
remote
Transport
22
Tools

Security review

Partly reviewed

Reviewed 1h ago.

  • tools: 22 tools scanned
  • metadata: scanned
  • mediumReviewRemote tools take credentials as input

    Whatever an agent passes to a remote tool leaves the machine. Never send connection strings, tokens or passwords to a third-party MCP server unless it is the service those credentials belong to.

    tailscale_list_keys, tailscale_get_key, tailscale_delete_key

Tools (22)

  • tailscale_list_devices

    List all devices in the tailnet (name, addresses, OS, last seen, tags, etc.). Tailscale REST: GET /tailnet/{tailnet}/devices.

  • tailscale_get_device

    Get a single device by id. Tailscale REST: GET /device/{deviceId}.

  • tailscale_list_device_routes

    List the subnet routes a device advertises and which are enabled. Tailscale REST: GET /device/{deviceId}/routes.

  • tailscale_list_keys

    List auth keys and API access tokens for the tailnet. Tailscale REST: GET /tailnet/{tailnet}/keys.

  • tailscale_get_key

    Get details of a single auth key / API access token by id (capabilities, expiry, usage). Tailscale REST: GET /tailnet/{tailnet}/keys/{keyId}.

  • tailscale_get_policy_file

    Get the tailnet's ACL / policy file (returned as JSON via the Accept header, not HuJSON). Tailscale REST: GET /tailnet/{tailnet}/acl.

  • tailscale_list_dns_nameservers

    List the global DNS nameservers configured for the tailnet. Tailscale REST: GET /tailnet/{tailnet}/dns/nameservers.

  • tailscale_get_dns_preferences

    Get the tailnet's DNS preferences (e.g. whether MagicDNS is enabled). Tailscale REST: GET /tailnet/{tailnet}/dns/preferences.

  • tailscale_list_dns_searchpaths

    List the DNS search paths (search domains) configured for the tailnet. Tailscale REST: GET /tailnet/{tailnet}/dns/searchpaths.

  • tailscale_get_split_dns

    Get the tailnet's split-DNS configuration — a map of domain → nameservers. Tailscale REST: GET /tailnet/{tailnet}/dns/split-dns.

  • tailscale_list_users

    List users of the tailnet, optionally filtered by type, role or status. Tailscale REST: GET /tailnet/{tailnet}/users.

  • tailscale_get_user

    Get a single user by id. Tailscale REST: GET /users/{userId}.

  • tailscale_list_webhooks

    List the webhook endpoints configured for the tailnet. Tailscale REST: GET /tailnet/{tailnet}/webhooks.

  • tailscale_get_tailnet_settings

    Get the tailnet's settings (device approval, key expiry, posture, etc.). Tailscale REST: GET /tailnet/{tailnet}/settings.

  • tailscale_authorize_device

    Authorize or de-authorize a device (only relevant when device approval is enabled for the tailnet). Tailscale REST: POST /device/{deviceId}/authorized.

  • tailscale_set_device_name

    Set (rename) a device's name. Tailscale REST: POST /device/{deviceId}/name.

  • tailscale_set_device_tags

    Set a device's ACL tags. REPLACES the device's existing tags. Tailscale REST: POST /device/{deviceId}/tags.

  • tailscale_expire_device_key

    Expire a device's node key, forcing it to re-authenticate — a security response to a compromised or lost device. Tailscale REST: POST /device/{deviceId}/expire.

  • tailscale_set_device_routes

    Set the subnet routes ENABLED for a device (from the routes it advertises). REPLACES the enabled set. Tailscale REST: POST /device/{deviceId}/routes.

  • tailscale_create_auth_key

    Create a new auth key for the tailnet (used to register new devices). Tailscale REST: POST /tailnet/{tailnet}/keys.

  • tailscale_delete_key

    Delete (revoke) an auth key or API access token by id — a security response. Tailscale REST: DELETE /tailnet/{tailnet}/keys/{keyId}.

  • tailscale_delete_device

    Delete a device, removing it from the tailnet. Tailscale REST: DELETE /device/{deviceId}.