10 available actions

What your AI agent can do in Tailscale

Tailscale is a secure networking platform for managing tailnets, devices, users, DNS, access policies, services, and other network administration resources. This page lists every available action. Your agent only receives the actions and permissions required for the role you approve.

Common starting points

  • Get DeviceGet the full current record for one manageable Tailscale device by ID.
  • Get DNS ConfigurationReturn the selected tailnet's combined MagicDNS, nameserver, search-path, and split-DNS configuration.
  • Set Device AuthorizationApprove or revoke approval for one device when device approval is enabled on the tailnet.
  • Set Device RoutesReplace the enabled subnet routes for one device with an explicit list of routes.

Browse all 10 actions by capability

Open a capability to see every supported action and its description.

Find & reviewLook up and review existing recordsView 7 actionsHide actions
  • Get DeviceGet the full current record for one manageable Tailscale device by ID.
  • Get DNS ConfigurationReturn the selected tailnet's combined MagicDNS, nameserver, search-path, and split-DNS configuration.
  • Get Tailnet SettingsReturn current tailnet-wide approval, update, key-duration, HTTPS, routing, logging, and posture settings.
  • List Configuration Audit LogsReturn configuration audit events for an explicit RFC3339 time window in the selected tailnet, optionally filtered by actor, target, or event name.
  • List Device RoutesReturn the subnet routes advertised and currently enabled for a Tailscale device.
  • List Tailnet DevicesReturn all devices in the selected tailnet, including identifiers, names, addresses, tags, authorization state, and connectivity metadata.
  • List UsersReturn users in the selected tailnet, optionally filtered by membership type or role.
Update & manageChange and manage existing recordsView 3 actionsHide actions
  • Set Device AuthorizationApprove or revoke approval for one device when device approval is enabled on the tailnet.
  • Set Device RoutesReplace the enabled subnet routes for one device with an explicit list of routes.
  • Set Device TagsReplace all ACL tags assigned to one Tailscale device.

Connection record

A connection you can control.

Sign-in
Customer-managed key
Setup
Use a key you create and control. It is stored securely and limited to the work agreed for the role.
Boundaries
Only the approved role and actions.
Off switch
Revoke the connection from your account.

FAQ

Before you connect Tailscale

How does the agent connect to Tailscale?
With a key you create and control. It is stored securely, permissions are limited to what the agent needs, and you can revoke it at any time.
What can the agent actually do in Tailscale?
The page above lists the 10 actions currently available through the Tailscale connection. The role determines which of those actions the agent may use, and write access is only enabled when the workflow needs it.
Is Tailscale included in my plan?
Connections are priced per tool on top of the base plan. Some are included and some are premium. See pricing for how connection charges work.
How long until Tailscale is ready?
Timing depends on the sign-in method, permissions and workflow being connected. We confirm the scope and setup plan before enabling the connection.

Bring the workflow together

Ready to put Tailscale to work?

Start with the responsibility you want off your plate. We’ll map the connection and the boundaries around it.

All product names, logos, and brands are property of their respective owners and are used for identification only. ZeroToClaw is not affiliated with or endorsed by Tailscale.