Tailscale Fall Update Week is here! Follow along on the blog, and join the release webinar.Register →
Get started - it's free!
Log in
WireGuard is a registered trademark of Jason A. Donenfeld.
© 2025 Tailscale Inc. All rights reserved. Tailscale is a registered trademark of Tailscale Inc.

Fall Update Week

Simpler, smarter, more connected

Effortless tailnet administration

Simplify policy management and securely scale with independent team environments.

Tailscale lets you manage your tailnet’s access permissions, including which users are allowed to connect to which machines, using our powerful HuJSON (JSON for Humans) policy file. However, there may be times you prefer to use web forms instead of working with HuJSON directly. We've made this possible with our new visual policy editor. The visual policy editor gives you a tabular view of each section of your policy file, and allows you to add, edit, and delete individual policy entries using visual forms.

visual-policy-editor-screenshot

Organizations can now create and manage more than one tailnet, all backed by the same identity provider. But as some teams and products grow, they start to need more separation between tailnets, whether that's for testing new features, running development environments, or managing connectivity for their own customers. Now you can get that separation without setting up a new organization or identity system. It’s the same Tailscale experience, with more flexibility when you need it.

multiple-tailnets-diagram

Secure service connectivity

Securely connect internal services and cloud workloads with granular controls.

Services allow you to assign virtual tailscale IPv4 and IPv6 address pairs (TailVIPs) to any logical resource in their network, as long as it is reachable by a Tailscale client. Services get a unique human-readable MagicDNS name for ease of reference. Services are a unit of policy on which you can grant access. Maintaining services is entirely automatable via API.

services-screenshot

Workload identity federation is a better way for your infrastructure and CI/CD systems to securely authenticate to Tailscale without managing long-lived API keys, auth keys, or OAuth clients. It allows cloud-hosted infrastructure in providers like AWS Azure, Google Cloud, or GitHub Actions to authenticate to your tailnet with ephemeral, scoped OIDC-based tokens.

workload-identity-federation-diagram

Seamless end-user experience

Optimize connectivity with fast, private relays and boost efficiency with a windowed client.

Tailscale Peer Relays provides a customer-deployed and managed traffic relaying mechanism. By advertising itself as a peer relay, a Tailscale node can relay traffic for any peer nodes on the tailnet, even for traffic bound to itself. Peer relays can only relay traffic for nodes on your tailnet (unless you share them), and only for nodes that have access to the peer relay.

peer-relays-diagram

We're introducing a new macOS UI: a windowed app that gives us the real estate to provide things like search, better error handling, debugging, and feature discovery. The windowed app runs alongside the menu bar app, which is here to stay. This new UI is currently available on macOS for Tailscale v1.88 and later.

macos-client-screenshot

A platform built for seamless, secure connectivity

Enable secure, zero-click login for any app and identity-aware access for any web service.

We built a lightweight identity provider that's Tailscale-aware, and you can too. With tsnet, application capability grants, and Funnel, it's possible to quickly build and configure secure applications that work both inside and outside of a tailnet.

tsidp-diagram

Tailscale’s identity-based access controls allow for building powerful, secure applications on entirely private tailnets. You can already leverage user identity with our Go-based tsnet. Now we’re taking that a significant step further with app capabilities. With the latest version of Tailscale’s serve function, third-party applications can accept grants through standard HTTP headers, in whatever language suits your needs.

app-capabilities-screenshot

Ready to dive in?

Your tailnet is about to get so much better.

An alternative way to edit the human JSON syntax of the tailnet policy file with an interactive graphical user interface.

Tailscale allows multiple tailnets to be created under a single organization, using a common identity provider and domain.

A streamlined, secure alternative to traditional load balancers.

A better way for your infrastructure and CI/CD systems to securely authenticate to Tailscale.

A customer-deployed and managed traffic relaying mechanism.

A windowed app to provide things like search, better error handling, debugging, and feature discovery.

Quickly build and configure secure applications that work both inside and outside of a tailnet.

Third-party applications can now accept grants through standard HTTP headers, in whatever language suits your needs.

Try Tailscale for free

Schedule a demo
Contact sales
cta phone
mercury
instacrt
Retool
duolingo
Hugging Face