Legacy Pricing
These are pricing plans are no longer available.
This page is kept online as a reference for customers on legacy plans. See our current pricing plans.
Personal
For personal & hobby projects
Free
Use Tailscale
- 1 user
- 20 devices
- 1 subnet router
- Secure, peer-to-peer connections
- SSO and MFA
- Sharing, MagicDNS, and more
Team
For connecting your team’s devices
$5
Per user/month
Try for free
- 5 devices × number of users
- 5 subnet routers included
- 2 admin users
- 5 unique users in ACL policy
- Custom authentication periods
- Okta integration
Business
For enforcing access policies
$15
Per user/month
Try for free
- 10 devices × number of users
- 10 subnet routers included
- Unlimited admin users
- Unlimited users in ACL policy
- Subnet router failover
Enterprise
For large or unique deployments
Custom
Contact Sales
- Unlimited devices
- Unlimited subnet routers
- Unlimited admin users
- Unlimited named ACL users
- IoT pricing
- Priority support
For Team and Business plans, the maximum number of allowed devices increases with every user you add to your network. Device limits are pooled across your account, and do not need to be associated with any particular user. Need to add more devices without adding more users? See: How do device limits work?
Need more for your personal network? The Personal Pro plan expands your personal account with 100 devices, 2 subnet routers, and custom auth periods for $48 per year.
Using Tailscale for an open source or friends & family project? The Community on GitHub plan can get you up to 25 users, 5 devices per user, and 2 admins for free.
Compare plans and features
Compare plans | Personal | Personal Pro | Team | Business | Enterprise |
---|---|---|---|---|---|
Basics | |||||
Users | 1 | 1 | $5 per user per month | $15 per user per month | Unlimited |
Admin usersAdmin users have access to the admin console for overview of devices on the network and network settings. Includes Admin, IT admin, and Network admin. | 1 | 1 | 2 | Unlimited | Unlimited |
DevicesA device is any computer, phone, or server with Tailscale installed and connected to your network. Device limits are pooled across your network. | 20 | 100 | 5 × usersthen $4.20 per 10 | 10 × usersthen $4.20 per 10 | Unlimited |
Subnet routersSubnet routers allow you to connect devices you can't install Tailscale on directly. Devices connected by subnet routers don't count towards your device total. | 1 | 2 | 5then $20.83 each | 10then $20.83 each | Unlimited |
Features | |||||
Secure, peer-to-peer connectionsTraffic over Tailscale is end-to-end encrypted with WireGuard® and sent peer-to-peer between devices, for minimal latency and better privacy. | |||||
Desktop & mobile appsWe offer native clients for Windows, macOS, iOS, Android, and most popular Linux distros. | |||||
Split DNSSplit DNS lets you use a DNS server only for specific domains, such as internal applications. | |||||
MagicDNSMagicDNS automatically registers DNS names for devices on your network, making it even easier to access devices over Tailscale. | |||||
Node sharingSharing allows you to invite users outside your network to access your devices in a controlled way. | |||||
Tailscale FunnelRoute traffic from the wider internet to one or more of your Tailscale nodes. | |||||
Exit nodesExit nodes let you route all your internet traffic through a device on your network, like a traditional privacy VPN. | |||||
Auto approversAuthorize users to advertise subnet routes and exit nodes without further approval. | |||||
Tailscale SSHAuthenticate and encrypt SSH connections in your network using using Tailscale node keys instead of SSH keys. | |||||
Tailscale SSH ConsoleCreate a browser-based SSH session from the admin console to a node on your tailnet. | |||||
API accessUse our public API to manage your network's devices, ACLs, DNS settings, and more. | |||||
HTTPS certificatesAllow users to provision TLS certificates for their devices. | |||||
Configuration audit loggingConfiguration audit logs record actions that modify a tailnet’s configuration, including the type of action, the actor, the target resource, and the time. | |||||
OAuth clientsProvide fine-grained control on the access granted to clients that use the Tailscale API. | |||||
WebhooksSubscribe to certain events on your Tailscale network and process the event notifications through an integration or app. | |||||
Subnet router failoverExpose the same subnet on multiple routers to ensure availability even if one goes offline. | |||||
Additional user rolesIn addition to Admin, use IT admin, Network admin, and Auditor roles for separation of duties. | |||||
Access Controls | |||||
Unique users in ACLsTailscale's ACL (access control lists) policy lets you set rules for who can access resources on your network. Rules can apply to devices, tags, individual users, or wildcards.<br><br>We only charge for each unique user named in your ACL policy. | 1 | 1 | 5then $10 each | Unlimited | Unlimited |
ACL TagsACL Tags let you authenticate devices as part of a group, rather than a user. For example, you can use tag:production for production web servers, or tag:database for database servers.<br><br>ACL rules for tagged devices for free. | Unlimited | Unlimited | Unlimited | Unlimited | Unlimited |
Block incoming connectionsNative clients allow blocking all incoming connections, for simple access controls when managing servers or remote devices. | |||||
Authentication | |||||
Single Sign-On (SSO)Authenticate users to your network using your existing Single Sign-On (SSO) system. You can manage who has access to your network from your existing tools. | |||||
Multi-factor Auth (MFA)Enforce 2-factor or multi-factor authentication (MFA) policies using your Single Sign-On (SSO) provider. | |||||
Auth keysAuthenticate servers and ephemeral nodes like containers to your network. | |||||
Custom authentication periodsEnforce that users re-authenticate with your identity provider at an interval you choose. By default, this is every 6 months. | |||||
Custom OIDCIntegrate Tailscale with a custom OIDC provider. | |||||
Device approvalRequire new devices to be approved before they can access a network. | |||||
User approvalRequire new users to be approved before they can access a network. | |||||
Okta SSOIntegrate all your application access together by using Tailscale with Okta as your SSO provider. | |||||
User & group provisioning for OktaSync group membership and deactivated users from Okta. | |||||
Support | |||||
Community forumJoin our public community forum at forum.tailscale.com | |||||
Email supportReach out to us at support@tailscale.com for help using Tailscale. | Priority |