Install
curl -fsSL https://tailscale.com/install.sh | shVendor-official, but review any script before piping it to a shell.
Showcase


Verified integrations
No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.
By theme — the product's score on each story themeBy theme
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Git code — core git and code operations — cloning, branching, pushing, code browsingGit codeevidence →
Core git and code operations — cloning, branching, pushing, code browsing
n/a
Networking access — stories about networking access in this arenaNetworking accessevidence →
Stories about networking access in this arena
Offline sync — stories about offline sync in this arenaOffline syncevidence →
Stories about offline sync in this arena
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Running agents — operating agents in production — sessions, persistence, recoveryRunning agentsevidence →
Operating agents in production — sessions, persistence, recovery
n/a
Security — security posture and hardening storiesSecurityevidence →
Security posture and hardening stories
Terminal ssh — terminal and SSH workflows — shells, sessions, remote accessTerminal sshevidence →
Terminal and SSH workflows — shells, sessions, remote access
Ux ergonomics — stories about ux ergonomics in this arenaUx ergonomicsevidence →
Stories about ux ergonomics in this arena
n/a
Story verdicts — every judged story with its evidenceStory verdicts
Follow the green: where the map greys out is where Tailscale stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
~3/10
unlocks → Official SDKs · Scoped API keys · Machine-readable spec · Versioning policy
Subscribe to events via webhooks
~5/10
Build against official SDKs
—0/10
Issue scoped/least-privilege API credentials for an agent
—0/10
Connect an agent via an official MCP server
n/an/a
Download a machine-readable API spec (OpenAPI or equivalent)
—0/10
Rely on versioned APIs with a documented deprecation policy
—0/10
Test against a sandbox environment without touching production data
n/an/a
Explore an interactive API reference with runnable examples
—0/10
Docs for agents
Point an agent at llms.txt or agent-oriented docs
—0/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
n/an/a
Operate the product with natural-language commands
—0/10
Plug MCP servers into this product so it can use their tools
n/an/a
Get AI-generated insights and suggestions from my data inside the product
n/an/a
Set up automations that run autonomously in the background
~3/10
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Git code — core git and code operations — cloning, branching, pushing, code browsingGit code
Core git and code operations — cloning, branching, pushing, code browsing
Networking access — stories about networking access in this arenaNetworking access
Stories about networking access in this arena
Offline sync — stories about offline sync in this arenaOffline sync
Stories about offline sync in this arena
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Running agents — operating agents in production — sessions, persistence, recoveryRunning agents
Operating agents in production — sessions, persistence, recovery
Security — security posture and hardening storiesSecurity
Security posture and hardening stories
Terminal ssh — terminal and SSH workflows — shells, sessions, remote accessTerminal ssh
Terminal and SSH workflows — shells, sessions, remote access
Local dev environment
Ux ergonomics — stories about ux ergonomics in this arenaUx ergonomics
Stories about ux ergonomics in this arena
Sorted by importance (agentic first) (high → low) · 69/69 stories · click a row’s chevron for the rationale and evidence
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | partial | 3/10 | Tprobed | |
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Tprobed | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Cclaimed | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Tprobed | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 3/10 | Cclaimed | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | n/a | untested | none yet | |
Get secure infrastructure access to resources wherever they live, including Kubernetes clusters C Mesh network | developer | Networking access — stories about networking access in this arenaNetworking access | 3 | full | 8/10 | Xcommunity | |
Connect to remote servers using SSH with Ed25519, ECDSA, or RSA keys C Ssh connections | developer | Terminal ssh — terminal and SSH workflows — shells, sessions, remote accessTerminal ssh | 3 | partial | 5/10 | Xcommunity | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | partial | 3/10 | Cclaimed | |
Keep my terminal session alive across network changes and device sleep C Ssh connections | power-user | Terminal ssh — terminal and SSH workflows — shells, sessions, remote accessTerminal ssh | 3 | partial | 3/10 | Xcommunity | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | none | 0/10 | ||
Assign an issue to an AI coding agent and receive a ready-to-review pull request C Ai coding agents | ai-native user | Running agents — operating agents in production — sessions, persistence, recoveryRunning agents | 3 | n/a | untested | none yet | |
Clone Git repositories over HTTPS, SSH, or the Git protocol C Repo management | developer | Git code — core git and code operations — cloning, branching, pushing, code browsingGit code | 3 | n/a | untested | none yet | |
Commit and push changes directly from my device C Repo management | developer | Git code — core git and code operations — cloning, branching, pushing, code browsingGit code | 3 | n/a | untested | none yet | |
Create pull requests on hosted Git platforms directly from my device C Repo management | developer | Git code — core git and code operations — cloning, branching, pushing, code browsingGit code | 3 | n/a | untested | none yet | |
Direct an AI agent to browse, search, edit, commit, pull, and push in a repository via conversation C Ai coding agents | ai-native user | Running agents — operating agents in production — sessions, persistence, recoveryRunning agents | 3 | n/a | untested | none yet | |
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | n/a | untested | none yet | |
Have an AI agent analyze my pull requests and suggest code improvements from my phone C Ai coding agents | ai-native user | Running agents — operating agents in production — sessions, persistence, recoveryRunning agents | 3 | n/a | untested | none yet | |
Open multiple terminal sessions, each with its own context, appearance, and history C Ssh connections | power-user | Terminal ssh — terminal and SSH workflows — shells, sessions, remote accessTerminal ssh | 3 | n/a | untested | none yet | |
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | n/a | untested | none yet | |
Review pull requests from my phone while on the go C Repo management | developer | Git code — core git and code operations — cloning, branching, pushing, code browsingGit code | 3 | n/a | untested | none yet | |
Run local UNIX commands like ls, grep, cat, tar, and curl directly in the app C Ssh connections | developer | Terminal ssh — terminal and SSH workflows — shells, sessions, remote accessTerminal ssh | 3 | n/a | untested | none yet | |
Use subnet routers to reach devices outside my local network as if I were on it C Mesh network | developer | Networking access — stories about networking access in this arenaNetworking access | 2 | full | 9/10 | Xcommunity | |
Route all my internet traffic through a specific device on my network using an exit node C Mesh network | power-user | Networking access — stories about networking access in this arenaNetworking access | 2 | full | 8/10 | Xcommunity | |
Connect directly to my servers without relying on a cloud relay, proxy, or VPN C Mesh network | power-user | Networking access — stories about networking access in this arenaNetworking access | 2 | disputed | 6/10 | Dcontradicted | |
Connect to a saved host with one tap without re-entering credentials C Ssh connections | power-user | Terminal ssh — terminal and SSH workflows — shells, sessions, remote accessTerminal ssh | 2 | partial | 6/10 | Xcommunity | |
Generate SSH key pairs for password-less access to my servers C Ssh connections | power-user | Terminal ssh — terminal and SSH workflows — shells, sessions, remote accessTerminal ssh | 2 | partial | 5/10 | Xcommunity | |
Transfer files to and from remote hosts via scp and sftp using my configured keys C Ssh connections | developer | Terminal ssh — terminal and SSH workflows — shells, sessions, remote accessTerminal ssh | 2 | partial | 5/10 | Xcommunity | |
Sync my saved hosts and connection settings across all my devices C Cross device sync | power-user | Offline sync — stories about offline sync in this arenaOffline sync | 2 | partial | 4/10 | Cclaimed | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 3/10 | Tprobed | |
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | partial | 3/10 | Tprobed | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | none | 0/10 | ||
Access and work with files and repositories from other apps' sandboxes on my device C Cross device sync | developer | Offline sync — stories about offline sync in this arenaOffline sync | 2 | n/a | untested | none yet | |
Amend the latest commit or undo unpushed commits to fix or split them C Repo management | power-user | Git code — core git and code operations — cloning, branching, pushing, code browsingGit code | 2 | n/a | untested | none yet | |
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Converse with an AI agent in natural language to get insights into repositories and open pull requests C Ai coding agents | ai-native user | Running agents — operating agents in production — sessions, persistence, recoveryRunning agents | 2 | n/a | untested | none yet | |
Customize the font, colors, and cursor appearance of my terminal and persist the settings C Terminal customization | power-user | Ux ergonomics — stories about ux ergonomics in this arenaUx ergonomics | 2 | n/a | untested | none yet | |
Describe what I want in plain language and have the tool generate the corresponding shell command C Ai coding agents | ai-native user | Running agents — operating agents in production — sessions, persistence, recoveryRunning agents | 2 | n/a | untested | none yet | |
Edit files with a terminal-based editor and run syntax/lint checkers inside the app C Local dev environment | developer | Terminal ssh — terminal and SSH workflows — shells, sessions, remote accessTerminal ssh | 2 | n/a | untested | none yet | |
Get AI-generated commit message suggestions based on my staged changes C Ai coding agents | ai-native user | Running agents — operating agents in production — sessions, persistence, recoveryRunning agents | 2 | n/a | untested | none yet | |
Group multiple terminal sessions together and broadcast the same command to all of them C Ssh connections | power-user | Terminal ssh — terminal and SSH workflows — shells, sessions, remote accessTerminal ssh | 2 | n/a | untested | none yet | |
Install additional pure-Python packages using pip directly on my device C Local dev environment | developer | Terminal ssh — terminal and SSH workflows — shells, sessions, remote accessTerminal ssh | 2 | n/a | untested | none yet | |
Interactively rewrite history by deleting, editing, squashing, or reordering commits C Repo management | power-user | Git code — core git and code operations — cloning, branching, pushing, code browsingGit code | 2 | n/a | untested | none yet | |
Manage and track cloud-based coding agent tasks from my phone C Ai coding agents | developer | Running agents — operating agents in production — sessions, persistence, recoveryRunning agents | 2 | n/a | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Preview Markdown, HTML, and other rendered files with live reload C Repo management | developer | Git code — core git and code operations — cloning, branching, pushing, code browsingGit code | 2 | n/a | untested | none yet | |
Protect my remote connections with biometric authentication like Face ID or fingerprint C Credential protection | developer | Security — security posture and hardening storiesSecurity | 2 | none | untested | none yet | |
Resolve merge conflicts across many files at once with a dedicated tool C Repo management | developer | Git code — core git and code operations — cloning, branching, pushing, code browsingGit code | 2 | n/a | untested | none yet | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | n/a | untested | none yet | |
Search and navigate code content using fuzzy matching, filters, and regular expressions C Repo management | developer | Git code — core git and code operations — cloning, branching, pushing, code browsingGit code | 2 | n/a | untested | none yet | |
Stash and unstash changes to temporarily clear my working directory C Repo management | power-user | Git code — core git and code operations — cloning, branching, pushing, code browsingGit code | 2 | n/a | untested | none yet | |
Store credentials once in a secure vault and reference them from multiple hosts C Credential protection | developer | Security — security posture and hardening storiesSecurity | 2 | n/a | untested | none yet | |
Store my SSH keys in a hardware-backed secure enclave protected by biometrics C Credential protection | power-user | Security — security posture and hardening storiesSecurity | 2 | n/a | untested | none yet | |
Visualize the full commit graph across branches C Repo management | power-user | Git code — core git and code operations — cloning, branching, pushing, code browsingGit code | 2 | n/a | untested | none yet | |
Clone, update, and manage Git submodules within a repository C Repo management | power-user | Git code — core git and code operations — cloning, branching, pushing, code browsingGit code | 1 | n/a | untested | none yet | |
Sign my commits with a GPG or SSH key for verification C Repo management | power-user | Git code — core git and code operations — cloning, branching, pushing, code browsingGit code | 1 | n/a | untested | none yet | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | n/a | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 27 stories with headroom
What would move Tailscale’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productDrive the product through a documented public API
partialq3/10moves agent-readyimpact 31.5
Missing: explicit API reference docs, endpoint list, authentication scheme details, and independent corroboration of API usage by AI/automation tools.
Openness — open source, data portability, and self-hosting storiesSelf-host the core product
nonemoves PA Scoreimpact 30
No vendor documentation claims a self-hostable control server; multiple independent community comments explicitly note Tailscale's coordination/control server is closed-source and cannot be self-hosted, with users citing this as a trust/lock-in concern.
Agenticness — how well agents can access and operate the productPoint an agent at llms.txt or agent-oriented docs
nonemoves agent-readyimpact 30
A direct probe found llms.txt returns 404, and there is no evidence of agent-oriented documentation or an llms.txt file anywhere in the evidence pack.
Agenticness — how well agents can access and operate the productOperate the product with natural-language commands
nonemoves Built-in AIimpact 30
Missing: any NL command parsing, AI assistant integration, or documented conversational interface.
Agenticness — how well agents can access and operate the productIssue scoped/least-privilege API credentials for an agent
nonemoves agent-readyimpact 30
The evidence pack shows general automation/API mentions (docs-12) and API keys expiring after 60 days (comm-15), but nothing about issuing scoped or least-privilege credentials specifically for an AI agent's use — no ACL tag scoping, OAuth client scopes, or agent-specific access controls are documented.
Agenticness — how well agents can access and operate the productBuild against official SDKs
nonemoves agent-readyimpact 30
Evidence shows only infra-as-code/webhook integrations and a CLI reference, with no mention of official SDKs; probes explicitly show the OpenAPI spec and llms.txt endpoints returning 404, indicating no discoverable machine-readable API/SDK surface for AI-native builders.
Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples
nonemoves API qualityimpact 30
No evidence of an interactive API reference or runnable examples; probes for OpenAPI/swagger specs returned 404s, and there's no mention of an interactive API explorer in the docs pack.
Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)
nonemoves API qualityimpact 30
Missing: a downloadable OpenAPI/Swagger JSON or YAML spec, any documentation page linking to such a spec.
Showing the top 8 of 27 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map5 surfaces · 18 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
Kb docs11 stories
- Run the product headlessly / in CI for automation
- Drive the product through a documented public API
- Subscribe to events via webhooks
- Set up automations that run autonomously in the background
- Perform bulk operations across many items at once
- Define rules that trigger actions automatically on events
- Route all my internet traffic through a specific device on my network using an exit node
- Get secure infrastructure access to resources wherever they live, including Kubernetes clusters
- Use subnet routers to reach devices outside my local network as if I were on it
- Sync my saved hosts and connection settings across all my devices
- Do everything through the API that I can do in the UI
Hacker News10 stories
- Run the product headlessly / in CI for automation
- Connect directly to my servers without relying on a cloud relay, proxy, or VPN
- Route all my internet traffic through a specific device on my network using an exit node
- Get secure infrastructure access to resources wherever they live, including Kubernetes clusters
- Use subnet routers to reach devices outside my local network as if I were on it
- Transfer files to and from remote hosts via scp and sftp using my configured keys
- Keep my terminal session alive across network changes and device sleep
- Connect to remote servers using SSH with Ed25519, ECDSA, or RSA keys
- Generate SSH key pairs for password-less access to my servers
- Connect to a saved host with one tap without re-entering credentials
tailscale.com9 stories
- Connect directly to my servers without relying on a cloud relay, proxy, or VPN
- Get secure infrastructure access to resources wherever they live, including Kubernetes clusters
- Use subnet routers to reach devices outside my local network as if I were on it
- Sync my saved hosts and connection settings across all my devices
- Transfer files to and from remote hosts via scp and sftp using my configured keys
- Keep my terminal session alive across network changes and device sleep
- Connect to remote servers using SSH with Ed25519, ECDSA, or RSA keys
- Generate SSH key pairs for password-less access to my servers
- Connect to a saved host with one tap without re-entering credentials
docs5 stories
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
3 of 4 testable claims verified · 0 contradicted → integrity 75/100
8 distinct capability claims found in Tailscale’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
3
Verified
1
Unverified
0
Contradicted
13
Undersold
Verified (3)
“Provides secure network access to infrastructure resources wherever they live, including Kubernetes clusters”
Get secure infrastructure access to resources wherever they live, including Kubernetes clustersfullproof ↗
“Subnet routers let devices outside your local network reach services within specific subnets”
Use subnet routers to reach devices outside my local network as if I were on itfullproof ↗
“Can route all internet traffic through a specific device on the network via an exit node”
Route all my internet traffic through a specific device on my network using an exit nodefullproof ↗
Unverified (1)
“Supports automating your tailnet via infrastructure-as-code providers, webhooks, and other integrations”
Undersold (13)
Run the product headlessly / in CI for automationpartialproof ↗
Drive the product through a documented public APIpartialproof ↗
Set up automations that run autonomously in the backgroundpartialproof ↗
Perform bulk operations across many items at oncepartialproof ↗
Define rules that trigger actions automatically on eventspartialproof ↗
Sync my saved hosts and connection settings across all my devicespartialproof ↗
Do everything through the API that I can do in the UIpartialproof ↗
Transfer files to and from remote hosts via scp and sftp using my configured keyspartialproof ↗
Keep my terminal session alive across network changes and device sleeppartialproof ↗
Connect to remote servers using SSH with Ed25519, ECDSA, or RSA keyspartialproof ↗
Generate SSH key pairs for password-less access to my serverspartialproof ↗
Connect to a saved host with one tap without re-entering credentialspartialproof ↗
Claims outside our story set (4)
Real capability claims found in Tailscale’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.
“Lets you connect SaaS and third-party apps to your network without exposing them publicly”
source ↗“Provides auditable access to SSH, Kubernetes, databases, and other resources”
source ↗“Can be used inside Docker containers for networking”
source ↗“Allows inviting users, assigning or changing roles, removing users, and switching between accounts”
source ↗
Business model
Free Personal tier (up to 6 users); paid Standard and Premium per-seat subscriptions; custom Enterprise pricing.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
