Tailscale Pricing - Compare Free Personal Plan & Business Tiers for Teams

6 min read Original article ↗

Plans that work for everyone

Trusted by 10,000+ companies

Compare all plans

Have any questions? Check out our product FAQ, licensing FAQ, or contact our sales team.

Scroll to

Plans

Personal

Personal Plus

Starter

Premium

Enterprise

Users & Devices

UsersA user is any distinct email address in your account. Personal includes 3 free users. Starter and Premium offer unlimited users; you pay for the number of active users at the end of your billing cycle.

36UnlimitedUnlimitedUnlimited

DevicesA device is any computer, phone, or server with Tailscale installed that's connected to your network. Device limits are pooled across your network.

100100100 + 10/user100 + 20/userCustom based on use case
Add-on devices$0.50 each$0.50 each$0.50 each$0.50 eachCustom based on use case
Desktop & mobile apps
Virtual Private Networking

Peer-to-peer connectionsEstablish direct connections between nodes in your tailnet, to minimize latency.

End-to-end encryptionEncrypt all traffic end-to-end with WireGuard®.

IPv4 and IPv6Route both IPv4 and IPv6 traffic.

Split tunnellingSplit DNS traffic so only traffic to your internal network goes over Tailscale, and everything else goes directly to the internet.

Short DNS host names (MagicDNS)Automatically register human readable DNS names with MagicDNS to make it even easier to access devices and services on your network.

Exit nodesRoute Internet traffic through a designated egress point on your tailnet, like a traditional VPN.

Subnet routersRelay traffic from your tailnet through a gateway to a subnet of VPCs, corporate LANs, physical networks, and more.

App connectorsControl access to software as a service (SaaS) applications available over your tailnet.

HA failoverExpose the same subnet routers and app connectors on multiple routers to ensure availability even if one router goes offline.

IP space collision resolution (4via6 subnet routers)Route traffic to overlapping IPv4 subnets without renumbering with 4via6 subnet routers, by assigning unique IPv6 addresses for each subnet.

Regional routingRoute your traffic across distributed HA subnet routers or app connectors based on region.

Access control

Network-level access policies (ACLs)Precisely define access in your tailnet based on IP address, subnet, or port.

ACL testsTest ACLs to make sure they're properly scoped to avoid unnecessary exposure of critical systems on your network.

GitOps for ACLsUse a GitOps workflow to centralize management and version-control of your ACLs.

On-demand accessUse partner integrations to grant elevated privileges (e.g. on-call), including temporary access, using an approval workflow.

Resource-level access policiesUse ACL tags to assign identity to a device in order to enforce access based on roles and groups.

Restrict based on purpose (ACL tags)Assign an identity to a device that is separate from human users, and use that identity as part of an ACL to restrict access.

Restrict based on groupAllow specific ACL-defined groups to access tagged nodes.

autogroups only

Restrict based on individual userAllow specific ACL-defined users to access tagged nodes.

Just-in-time Access APIProvide temporary, time-bound, and audited elevated access to resources using the API or integrations with Slack and GitHub Actions.

Application Networking

Service accountsPre-authenticate services or nodes (e.g., servers and ephemeral containers) added to your network.

Service provisioningAssign an identity to a service or node and restrict access on your tailnet, using ACL tags.

Tailscale Kubernetes operatorProvide full ingress and egress connectivity from Kubernetes clusters to non-Kubernetes resources, as well as cross-cluster peering, via Tailscale.

Tailscale SSHAuthenticate and encrypt SSH connections between devices in your tailnet, using Tailscale instead of SSH basic auth, keys, certs, or a bastion.

Tailscale FunnelRoute traffic from the Internet to a node in your tailnet to publicly share it with anyone, even if they aren’t using Tailscale.

User Management

User approvalPrevent new users in your organization from joining a tailnet until they’ve been approved by an admin

Standard user rolesStandard user roles include owner, admin, and member

Advanced user rolesAdvanced user roles include billing admin, IT admin, network admin, and auditor

SSO with any IdPLog in to Tailscale and manage users with any OIDC identity provider.

Custom authentication periodsEnforce that users re-authenticate with your identity provider at an interval you choose. By default, this is every 6 months

User & group provisioning (Entra ID + SCIM)Sync group membership and new or deactivated users from Entra ID.

User & group provisioning (Okta + SCIM)Sync group membership and new or deactivated users from Okta.

Endpoint & Posture Management

Device approvalReview and approve new devices and nodes before adding them to your tailnet.

Tailnet LockPrevent new, and potentially malicious, nodes from joining your tailnet without first being signed by an already trusted node.

Device posture managementUse posture conditions to more granularly control access in your network policies.

Postures based on custom attributesAttach custom posture attributes to your devices and use them as part of posture conditions.

up to 2up to 2

Device posture integrationsAutomatically synchronize device trust information from third-party posture checking tools and use it as part of posture conditions.

Mobile Device Management Policies

Customize UI VisibilityChange the visibility of UI elements in Tailscale Client menu

Runtime configurationsConfigure Tailscale behavior in end user devices eg. Automatically start Tailscale when user logs in, force tailscale to be always on, route all traffic via a specific exit node, and more

Configure MDM ToolsConfigure and deploy Tailscale using MDM solutions like SimpleMDM, Iru, Microsoft Intune, Jamf

Monitoring & Compliance

WebhooksSubscribe to events on your tailnet, and forward those events to any integration or app — like Slack or Microsoft Teams.

Configuration audit loggingRecord actions that modify a tailnet's configuration, including type of action, actor, target resource, and time.

Network flow loggingRecord network traffic between nodes on your tailnet.

Tailscale SSH session recordingCapture and stream terminal sessions over Tailscale SSH for analysis or storage.

Tailscale Kubernetes Operator recordingCapture and stream kubectl sessions through the Tailscale Kubernetes Operator for analysis or storage.

Log streamingSend real-time network traffic information to any SIEM or observability tool for analysis, or to a bucket for long-term storage.

configuration logs onlyconfiguration logs only
Interfaces

UILog in to the tailscale.com admin console to manage users, nodes, and their permissions, on your tailnet.

CLIQuickly access information, manage devices or troubleshoot issues with a built-in command-line interface.

APIUse the API to manage your network's devices, ACLs, DNS settings, and more.

IaCConfigure your tailnet using Terraform or Pulumi.

Support

Customer supportUse the documentation or email us to get help with using Tailscale.

Priority supportIssue is prioritized based on severity.

Additional support optionsContact our sales team for information.

Payment Options
Pay by credit card
Pay by invoice
Annual billing

Cloud Marketplaces

Get started with Tailscale through your preferred cloud marketplace — consolidate billing, and speed up deployment.

AWS

Simplify procurement by purchasing Tailscale through AWS Marketplace. Enjoy flexible terms, consolidated billing, and utilize your existing AWS spend commitments and credits. Benefit from seamless AWS integration, automated deployment, and centralized vendor management.

Azure

Seamlessly deploy and manage Tailscale in your Azure infrastructure while consolidating billing and streamlining vendor management.

Mullvad

Browse the internet privately, and securely with Tailscale and Mullvad.

$5

Per month for Mullvad on up to 5 devices

Add-on devices

If you’ve run out of devices on your plan and you need to connect more, get more capacity with this add-on.

$0.50

Per device, per month

Optional Add-ons

Get more out of Tailscale with optional add-ons. Available on all plans. Head to the settings page to configure your add-ons.