Skip to main content

Tailscale

Tailscale is a mesh VPN and zero-trust network. This connector brings in the devices enrolled in your tailnet, including ones that no other tool in your environment sees, such as a contractor’s laptop given network access without any device management.

Beta. This connector was built from Tailscale’s documentation and hasn’t been verified against a live account yet. It may return incomplete data or fail in ways we haven’t seen. If something looks wrong, contact support@chartingcyber.com.

At a glance

Data providedDevices, Users
AuthenticationOAuth client (Client ID + Client Secret)
Where to configureConnectors → Add a Connector → Tailscale

Required permissions

An OAuth client with only these two read scopes: devices:core:read (Devices → Core → Read) and users:read (Users → Read). Navigator never writes to your tailnet.

Why an OAuth client, not an API access token

Tailscale’s personal API access tokens expire after 1 to 90 days, so a sync using one silently stops working on a schedule, and they carry every permission of the person who created them. An OAuth client doesn’t expire, isn’t tied to an individual, and is limited to the scopes you grant, so the connection keeps working and can only read devices.

Setup

You need to be an Owner, Admin, or IT admin of the tailnet.

  1. Open the Trust credentials page of the Tailscale admin console.
  2. Select Credential, then OAuth.
  3. Grant only Devices → Core → Read and Users → Read.
  4. Select Generate credential.
  5. Copy the Client ID and Client secret. The secret can’t be shown again after you close the page.
  6. In Navigator, go to Connectors → Add a Connector → Tailscale.
  7. Enter the Client ID and Client Secret, then save. Navigator validates the credentials and enqueues a first sync immediately.

Tailscale’s own guide: OAuth clients.

What data this connector provides

  • Devices: every device in your tailnet, including hostname, operating system (with distribution and version for Linux), the device’s real network addresses as reported by its Tailscale client, when it joined the tailnet, and whether it is currently connected.
  • Users: every member of your tailnet, with login name, display name, and whether the account is active or suspended. Members are the people who sign in through your identity provider.
  • Serial numbers appear only if you have turned on Tailscale’s device posture identity collection and the device has opted in.

Known limitations

  • The Tailscale addresses (100.x.y.z) are network overlay addresses, not the device’s own, so they are not shown as its IP addresses.
  • Devices and users shared in from another tailnet are skipped: they belong to someone else’s organization. The sync notes how many were skipped.
  • A user’s Tailscale role (owner, admin, and so on), ACL tags and client version are not shown in Navigator yet.
  • If the users:read scope is missing, the device sync still succeeds but the user sync reports an error until you add it.
  • Tailscale returns every device in a single response, so a very large tailnet syncs in one request.