# Renew a device's key seamlessly

Last validated Dec 19, 2025

> **Deprecation:**
>
> The instructions outlined in this topic are provided for versions of the Tailscale client earlier than v1.90, as a manual way to enable seamless key renewal. In Tailscale v1.90 and later, seamless key renewal is enabled by default. We recommend updating devices to the latest version of the client if you are using seamless key renewal.

Seamless key renewal lets you configure your Tailscale network (known as a tailnet) so that Transmission Control Protocol (TCP) connections remain active during renewal of [node keys][bl-tailscale-key-management-node-keys]. Without seamless key renewal, a device's TCP connections close and then reconnect. Seamless key renewal is useful when you need to maintain long-running connections for a device, particularly if the device's [key expiry][docs-key-expiry] has a short duration.

## Enable seamless key renewal

To enable seamless key renewal on devices running a version of the Tailscale client earlier than Tailscale v1.90, [edit][docs-edit-policies] the [`nodeAttrs`][docs-policy-syntax-node-attributes] section of your [tailnet policy file][docs-tailnet-policy-file] to add `seamless-key-renewal` as an attribute. This example adds the `seamless-key-renewal` attribute for devices with the `tag:prod` [tag][docs-tags]:

```json {2-7}
"nodeAttrs": [
  {
    "target": [
      "tag:prod",
    ],
    "attr": ["seamless-key-renewal"],
  },
]
```

> **Deprecation:**
>
> The `seamless-key-renewal` attribute will not have any effect on devices running Tailscale v1.90 and later.

For details about the syntax in this example, refer to [node attributes][docs-policy-syntax-node-attributes].

## Disable seamless key renewal

> **Deprecation:**
>
> Disabling seamless key renewal using this method will not affect devices running Tailscale v1.90 or later.

To disable seamless key renewal, remove the `seamless-key-renewal` attribute from the
[`nodeAttrs`][docs-policy-syntax-node-attributes] section in your [tailnet policy file][docs-tailnet-policy-file].

[bl-tailscale-key-management-node-keys]: /blog/tailscale-key-management#node-keys

[docs-edit-policies]: /docs/features/tailnet-policy-file/manage-tailnet-policies

[docs-key-expiry]: /docs/features/access-control/key-expiry

[docs-policy-syntax-node-attributes]: /docs/reference/syntax/policy-file#node-attributes

[docs-tags]: /docs/features/tags

[docs-tailnet-policy-file]: /docs/features/tailnet-policy-file
