Tailscale is a free, open source network security project written in Go and released under BSD-3-Clause. It has 36,587 GitHub stars, 3,218 forks and 4,569 open issues, and was last pushed 3 hours ago. On this registry it ranks #1 of 7 tracked projects in Network Security, with 5 head-to-head comparisons available. It gained 200 stars over the last 6 tracked days.

Tailscale — Zero-config VPN with WireGuard for secure networking

What is Tailscale?

What it is

Tailscale is an open-source implementation of a zero-configuration VPN built on WireGuard, designed to simplify secure network connectivity across devices. It lives in the network security ecosystem and provides private, encrypted networks without manual firewall or IP management. The project delivers both a daemon (tailscaled) and CLI tool (tailscale) that enable peer-to-peer connectivity using WireGuard, augmented with identity-based access controls and optional cloud-managed features.

Key capabilities

  • Establishes end-to-end encrypted WireGuard tunnels between devices using public key identity
  • Supports multi-factor authentication (2FA) and OAuth/SAML-based single sign-on (SSO) for user authentication
  • Enables mesh networking without manual IP assignment or port forwarding
  • Provides ACL-based access control lists for fine-grained authorization between nodes
  • Integrates with identity providers for centralized user and device management
  • Supports DNS-based service discovery and split DNS routing
  • Offers built-in exit node functionality for routing all traffic through a designated node

Who uses it and how

System administrators deploy tailscaled on Linux servers and workstations to create secure internal networks for remote access or inter-service communication. Developers use the CLI to on-demand connect to services behind NATs without reconfiguring firewalls. Enterprises integrate Tailscale with Okta, Google Workspace, or Azure AD to enforce SSO and policy-based access across hybrid cloud and on-prem infrastructure. Mobile teams use iOS and Android clients (which embed this repo’s code) to securely reach internal resources while off-network.

Getting started

Install via official packages at https://pkgs.tailscale.com or run the Docker image tailscale/tailscale. Start the daemon with tailscaled, then authenticate with tailscale up. Hosted control plane is provided by Tailscale Inc., with optional self-hosted control and coordination servers available.

When to use it — and when not to

Use Tailscale when you need secure, zero-trust networking with minimal configuration overhead and strong identity controls. Avoid it if you require full control over the control plane without relying on Tailscale Inc.’s hosted service (self-hosting requires operating a separate coordination server and storage backend). It replaces paid VPN solutions but does not support legacy IPsec or SSL-based VPN protocols. The open-source core lacks GUI wrappers for macOS/iOS/Windows, which are proprietary and distributed separately.

project readme (upstream, from github) — read inline

Tailscale

https://tailscale.com

Private WireGuard® networks made easy

Overview

This repository contains the majority of Tailscale's open source code. Notably, it includes the tailscaled daemon and the tailscale CLI tool. The tailscaled daemon runs on Linux, Windows, macOS, and to varying degrees on FreeBSD and OpenBSD. The Tailscale iOS and Android apps use this repo's code, but this repo doesn't contain the mobile GUI code.

Other Tailscale repos of note:

For background on which parts of Tailscale are open source and why, see https://tailscale.com/opensource/.

Using

We serve packages for a variety of distros and platforms at https://pkgs.tailscale.com.

Other clients

The macOS, iOS, and Windows clients use the code in this repository but additionally include small GUI wrappers. The GUI wrappers on non-open source platforms are themselves not open source.

Building

We always require the latest Go release, currently Go 1.27. (While we build releases with our Go fork, its use is not required.)

go install tailscale.com/cmd/tailscale{,d}

If you're packaging Tailscale for distribution, use build_dist.sh instead, to burn commit IDs and version info into the binaries:

./build_dist.sh tailscale.com/cmd/tailscale
./build_dist.sh tailscale.com/cmd/tailscaled

If your distro has conventions that preclude the use of build_dist.sh, please do the equivalent of what it does in your distro's way, so that bug reports contain useful version information.

Bugs

Please file any issues about this code or the hosted service on the issue tracker.

Contributing

PRs welcome! But please file bugs. Commit messages should reference bugs.

We require Developer Certificate of Origin Signed-off-by lines in commits.

See commit-messages.md (or skim git log) for our commit message style.

About Us

Tailscale is primarily developed by the people at https://github.com/orgs/tailscale/people. For other contributors, see:

Legal

WireGuard is a registered trademark of Jason A. Donenfeld.

Frequently asked questions

Is Tailscale free to use?

Tailscale is open source under the BSD-3-Clause licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does Tailscale do?

Zero-config VPN with WireGuard for secure networking

What is Tailscale written in?

Tailscale is primarily written in Go. Its source is publicly available at https://github.com/tailscale/tailscale, and it has 36,587 GitHub stars.