Legacy Pricing
These are pricing plans are no longer available.
This page is kept online as a reference for customers on legacy plans. See our current pricing plans.
Personal
For personal & hobby projects
Free
- 1 user
- 20 devices
- 1 subnet router
- Secure, peer-to-peer connections
- SSO and MFA
- Sharing, MagicDNS, and more
Team
For connecting your team’s devices
$5
Per user/month
- 5 devices × number of users
- 5 subnet routers included
- 2 admin users
- 5 unique users in ACL policy
- Custom authentication periods
- Okta integration
Business
For enforcing access policies
$15
Per user/month
- 10 devices × number of users
- 10 subnet routers included
- Unlimited admin users
- Unlimited users in ACL policy
- Subnet router failover
Enterprise
For large or unique deployments
Custom
- Unlimited devices
- Unlimited subnet routers
- Unlimited admin users
- Unlimited named ACL users
- IoT pricing
- Priority support
Compare plans and features
Compare plans | Personal | Personal Pro | Team | Business | Enterprise |
---|---|---|---|---|---|
Basics | |||||
Users | 1 | 1 | $5 per user per month | $15 per user per month | Unlimited |
Admin usersAdmin users have access to the admin console for overview of devices on the network and network settings. Includes Admin, IT admin, and Network admin. | 1 | 1 | 2 | Unlimited | Unlimited |
DevicesA device is any computer, phone, or server with Tailscale installed and connected to your network. Device limits are pooled across your network. | 20 | 100 | 5 × usersthen $4.20 per 10 | 10 × usersthen $4.20 per 10 | Unlimited |
Subnet routersSubnet routers allow you to connect devices you can't install Tailscale on directly. Devices connected by subnet routers don't count towards your device total. | 1 | 2 | 5then $20.83 each | 10then $20.83 each | Unlimited |
Features | |||||
Secure, peer-to-peer connectionsTraffic over Tailscale is end-to-end encrypted with WireGuard® and sent peer-to-peer between devices, for minimal latency and better privacy. | |||||
Desktop & mobile appsWe offer native clients for Windows, macOS, iOS, Android, and most popular Linux distros. | |||||
Split DNSSplit DNS lets you use a DNS server only for specific domains, such as internal applications. | |||||
MagicDNSMagicDNS automatically registers DNS names for devices on your network, making it even easier to access devices over Tailscale. | |||||
Node sharingSharing allows you to invite users outside your network to access your devices in a controlled way. | |||||
Tailscale FunnelRoute traffic from the wider internet to one or more of your Tailscale nodes. | |||||
Exit nodesExit nodes let you route all your internet traffic through a device on your network, like a traditional privacy VPN. | |||||
Auto approversAuthorize users to advertise subnet routes and exit nodes without further approval. | |||||
Tailscale SSHAuthenticate and encrypt SSH connections in your network using using Tailscale node keys instead of SSH keys. | |||||
Tailscale SSH ConsoleCreate a browser-based SSH session from the admin console to a node on your tailnet. | |||||
API accessUse our public API to manage your network's devices, ACLs, DNS settings, and more. | |||||
HTTPS certificatesAllow users to provision TLS certificates for their devices. | |||||
Configuration audit loggingConfiguration audit logs record actions that modify a tailnet’s configuration, including the type of action, the actor, the target resource, and the time. | |||||
OAuth clientsProvide fine-grained control on the access granted to clients that use the Tailscale API. | |||||
WebhooksSubscribe to certain events on your Tailscale network and process the event notifications through an integration or app. | |||||
Subnet router failoverExpose the same subnet on multiple routers to ensure availability even if one goes offline. | |||||
Additional user rolesIn addition to Admin, use IT admin, Network admin, and Auditor roles for separation of duties. | |||||
Access Controls | |||||
Unique users in ACLsTailscale's ACL (access control lists) policy lets you set rules for who can access resources on your network. Rules can apply to devices, tags, individual users, or wildcards.<br><br>We only charge for each unique user named in your ACL policy. | 1 | 1 | 5then $10 each | Unlimited | Unlimited |
ACL TagsACL Tags let you authenticate devices as part of a group, rather than a user. For example, you can use tag:production for production web servers, or tag:database for database servers.<br><br>ACL rules for tagged devices for free. | Unlimited | Unlimited | Unlimited | Unlimited | Unlimited |
Block incoming connectionsNative clients allow blocking all incoming connections, for simple access controls when managing servers or remote devices. | |||||
Authentication | |||||
Single Sign-On (SSO)Authenticate users to your network using your existing Single Sign-On (SSO) system. You can manage who has access to your network from your existing tools. | |||||
Multi-factor Auth (MFA)Enforce 2-factor or multi-factor authentication (MFA) policies using your Single Sign-On (SSO) provider. | |||||
Auth keysAuthenticate servers and ephemeral nodes like containers to your network. | |||||
Custom authentication periodsEnforce that users re-authenticate with your identity provider at an interval you choose. By default, this is every 6 months. | |||||
Custom OIDCIntegrate Tailscale with a custom OIDC provider. | |||||
Device approvalRequire new devices to be approved before they can access a network. | |||||
User approvalRequire new users to be approved before they can access a network. | |||||
Okta SSOIntegrate all your application access together by using Tailscale with Okta as your SSO provider. | |||||
User & group provisioning for OktaSync group membership and deactivated users from Okta. | |||||
Support | |||||
Community forumJoin our public community forum at forum.tailscale.com | |||||
Email supportReach out to us at support@tailscale.com for help using Tailscale. | Priority |
Pricing FAQs
What happens if I go over my limit?
We don’t apply hard limits that prevent you from using more devices, subnet routers, or ACL users than your plan allows. If you have a big burst of automated ephemeral nodes or want to explore additional ACL rules, feel free. If you exceed the limits of your plan for a short while, we’ll get in touch about upgrading to something more suited to your needs. Feel free to contact support if you have questions about your use-case.
How do device limits work?
Our Personal and Personal Pro plans offer a flat number of devices, but for our Team and Business plans, your total device count grows along with the number of paid users in your network. Devices limits are pooled: if you have a 50 device limit, one user can have 45 and five other users can have one device each. If you need to add more devices and do not need to add more users, you can add additional blocks of 10 devices for $5 per month. Devices shared with you don’t count toward your limit.
Does Tailscale support server-to-server connectivity?
Yes! Tailscale works the same whether you install it on two servers, a server and a client, or two clients. Every connection is always peer-to-peer and encrypted. And unlike other VPNs, there are no extra costs for which kind of devices you’re trying to connect.
How do access controls work?
You can define access control rules for your network using a simple JSON policy. Rules that target devices, ACL tags, or everyone are free. You can also target specific users by using their email address. Each unique email address in your ACL occupies a slot in your plan. For most teams, the included user counts should cover your needs. For more complex needs, you can buy additional unique users in your ACL, or use the Business plan, which provides an unlimited number of named users. On every plan, individual users can block incoming connections to their personal devices.
Who can see my traffic?
Only you. Tailscale devices connect directly with each other over encrypted WireGuard® connections. Your devices’ private keys are never shared, meaning your traffic can only be decrypted at its intended destination.
Can I use the Personal plan with my family?
Absolutely! We recommend using sharing to give members of your family access to shared devices. Shared devices don’t count towards your device limit.
Do you offer discounts for non-profits or educational institutions?
Charities, not-for-profit organizations, and educational institutions receive a 50% discount off of listed prices. Choose your billing plan in the admin console, and contact us to get the discount applied.