# AX Check: tailscale.com
Checked 2026-09-28.

Tailscale quickstart and pricing are clear, but llms.txt is thin
Quickstart is a concise, actionable Markdown guide with working links. llms.txt only links one docs index, with no navigation guidance or mention of API/MCP surfaces.

## Onboarding needs a login

## Coding sessions
All three independent agent sessions completed and read pricing straight from the pricing page. Reported figures varied slightly across sessions (e.g. Premium quoted as $8, $18, or ~$18 per user/month), and one session explicitly flagged its numbers as approximate and told the user to verify at tailscale.com/pricing.

### DeepSeek V4.1 Flash
[View public run](https://agents.withgauge.com/p/runs/3a42a60e-50cc-47da-937f-9783b218c9b3) · [Read transcript](https://www.ax-check.com/tailscale.com/sessions/deepseek.json)
README.md pricing table lists Personal $0/6 users, Premium $8/user/month (annual), Enterprise $18/user/month (annual), Mullvad add-on $5/5 devices, and explicitly names 'the cost driver is seats' plus tells reader to verify at tailscale.com/pricing before budgeting — figures sourced live via curl at seq 24-30.
#### End-to-end onboarding
- **Onboarding needs a login**: Agent wrote a working stdlib Python script targeting Tailscale's hosted REST API (api.tailscale.com/api/v2) and confirmed the endpoint was reachable (401 unauthenticated response), but no API key or OAuth client credentials were ever obtained during the session. The agent explicitly states no credential was available and the script exits immediately with a configuration error rather than completing any authenticated call.
  Event 8:

  ```text
  tailscale_api_http=401
  ```
  Event 21:

  ```text
  Not configured. Set TS_API_KEY, or TS_OAUTH_CLIENT_ID + TS_OAUTH_CLIENT_SECRET. See README.md.
  exit=1
  ```
  Event 39:

  ```text
  no `TS_API_KEY` / `TS_OAUTH_CLIENT_ID+SECRET` was provided, so live calls can't succeed here.
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **No Tailscale credentials available to authenticate**: The session had no pre-provisioned Tailscale API key or OAuth client credentials, and there is no self-service way to mint one without human interaction with the Tailscale admin console. This is a normal login/credential requirement, not a product defect — the agent correctly identified it, wrote working code, and stopped rather than faking success.
  Event 21:

  ```text
  Not configured. Set TS_API_KEY, or TS_OAUTH_CLIENT_ID + TS_OAUTH_CLIENT_SECRET. See README.md.
  ```
  Event 39:

  ```text
  Blocked? Yes, on credentials only. The API is reachable (unauthenticated call returned HTTP 401, as expected), but no `TS_API_KEY` / `TS_OAUTH_CLIENT_ID+SECRET` was provided, so live calls can't succeed here.
  ```

#### Suggested Changes
- **Surface a scriptable/self-service credential path in the quickstart for headless agents**: The agent found no way to obtain an API key or OAuth client without a human logging into the Tailscale admin console (Settings -> Keys / Settings -> OAuth clients, per the README the agent wrote). For developer-workflow evals or CI-style automation, consider documenting whether any headless/non-interactive credential issuance exists; if none exists, this is expected but worth flagging to product/dev-rel since it blocks fully autonomous onboarding.
  Event 33:

  ```text
  Generate a credential in the Tailscale admin console:
  
  - **API access key** (simplest): Settings -> Keys -> Generate access token, or
  - **OAuth client** (better for automation): Settings -> OAuth clients.
  ```

### Kimi K3
[View public run](https://agents.withgauge.com/p/runs/fc54452d-d1f6-4801-ac4d-6cbab6475f50) · [Read transcript](https://www.ax-check.com/tailscale.com/sessions/kimi.json)
Final output lists per-plan pricing (Personal free, Personal Plus ~$5/user/mo, Starter ~$5/user/mo, Premium ~$18/user/mo, Enterprise custom) with the assumption that billing is per-user not per-device and flags the figures may be stale ('verify current numbers').
#### End-to-end onboarding
- **Onboarding needs a login**: Agent could not self-provision Tailscale credentials. It confirmed the hosted API is reachable but had no API key, and correctly identified that creating a tailnet/API token requires an interactive identity-provider login in a browser (human action), which it could not perform itself. No authenticated call to the real Tailscale API was ever made — the example script was written but never executed against the live API.
  Event 7:

  ```text
  404
  
  ```
  Event 9:

  ```text
  there are no Tailscale credentials available, and I can't create a tailnet myself — signup requires an interactive identity-provider login (Google/GitHub/etc.) in a browser, and API tokens are issued from the admin console.
  ```
  Event 15:

  ```text
  **Status:** Blocked on an API token from you. Provide `TAILSCALE_API_KEY` and I'll run the example in `tailscale_example.py` immediately — otherwise I'm stopping here as requested.
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **No self-service way to obtain a Tailscale API token**: The agent probed for existing credentials and environment variables, found none, and correctly determined that Tailscale account/tailnet creation and API key generation require an interactive browser login via an identity provider (Google/GitHub/etc.) plus a manual step in the admin console. This is a normal product security requirement, not a defect — API tokens are deliberately gated behind human authentication. The agent stopped rather than fabricating credentials or attempting workarounds.
  Event 3:

  ```text
  env | grep -iE 'tailscale|ts_' ; which tailscale tailscaled 2>/dev/null; ls ~/.config/tailscale* 2>/dev/null; echo "---done---"
  ```
  Event 9:

  ```text
  there are no Tailscale credentials available, and I can't create a tailnet myself — signup requires an interactive identity-provider login (Google/GitHub/etc.) in a browser, and API tokens are issued from the admin console.
  ```

#### Suggested Changes
- **Offer a non-interactive credential path for automated/CI onboarding**: The agent's only path to a usable API token was the interactive admin console flow at https://login.tailscale.com/admin/settings/keys, which blocked fully automated evaluation. If Tailscale wants to support agentic or CI-driven onboarding, document or expose a scriptable/service-account style key issuance flow that doesn't require an interactive IdP login, and verify by having a script (no browser) obtain a working key and successfully call /api/v2/tailnet/{tailnet}/devices.
  Event 9:

  ```text
  signup requires an interactive identity-provider login (Google/GitHub/etc.) in a browser, and API tokens are issued from the admin console
  ```

### Qwen 3.8 Max
[View public run](https://agents.withgauge.com/p/runs/84397b86-ce21-4aa3-8496-8343af154bbb) · [Read transcript](https://www.ax-check.com/tailscale.com/sessions/qwen.json)
Final output lists Free/Personal/Starter (~$6/user/mo)/Premium (~$18/user/mo) tiers and flags them as approximate, telling the user to verify at tailscale.com/pricing — assumption stated.
#### End-to-end onboarding
- **End-to-end onboarding not demonstrated**: Agent wrote a script targeting Tailscale's hosted REST API but never obtained real credentials and never executed an authenticated call. It explicitly states no OAuth client ID/secret exist in the sandbox and the script was never run against the live API.
  Event 22:

  ```text
  I can't *run* the example end-to-end because there are no credentials here (`TS_OAUTH_CLIENT_ID`/`TS_OAUTH_CLIENT_SECRET`)
  ```
  Event 20:

  ```text
  Successfully wrote 2620 bytes to /sandbox/repo/tailscale_example.py
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **No Tailscale OAuth credentials available in sandbox**: The session had no way to self-serve OAuth client ID/secret for the Tailscale API, so the written example script could never be executed against the live control plane. This is a test-environment/credential limitation rather than a product defect, since Tailscale requires normal account-based OAuth client creation via its admin console.
  Event 22:

  ```text
  I can't *run* the example end-to-end because there are no credentials here (`TS_OAUTH_CLIENT_ID`/`TS_OAUTH_CLIENT_SECRET`)
  ```
- **PyPI package installation blocked in sandbox**: Attempting to install the official Tailscale client library failed because PyPI access was unavailable in this environment, forcing the agent to fall back to raw HTTP calls via requests. This is a sandbox network restriction, not a Tailscale product issue.
  Event 10:

  ```text
  ERROR: No matching distribution found for tailscale-client-python
  ```

#### Suggested Changes
None identified in this transcript.

### Task given to each agent
Help me build a simple example using Tailscale. Tell me how pricing works, and briefly tell me whether this product will be easy for you to manage. Let me know if you get blocked. If this product has no developer workflow you can act on, say so plainly and stop. Stay light: use the hosted product through its SDK or API. Do not start local service stacks or wait for long-running commands; if the quickstart requires either, say so plainly and stop.

No product credentials were supplied and no purchases were authorized.

## Score: B · 65/100 (provisional)
Grades come from completed site checks. Coding sessions and skipped checks do not affect the score.

### Clarity
- **Failed** — Homepage answers Markdown requests

  ```text
  Homepage returned text/html even when text/markdown was requested; no Markdown representation served.
  ```

- **Failed** — llms.txt provides an actionable documentation index

  ```text
  llms.txt exists but only links one docs index, lacking actionable starting guidance or key entry points.
  ```

- **Failed** — llms.txt provides navigation guidance

  ```text
  llms.txt offers a single docs link with no navigation guidance or organization for agents.
  ```

- **Failed** — llms.txt mentions offered API, MCP, and skills

  ```text
  llms.txt does not mention any API, MCP server, or skills surfaces offered by Tailscale.
  ```

- **Pass** — A compact guide representation exists

  ```text
  Quickstart page offers 'View as Markdown' and /docs/how-to/quickstart.md returns text/markdown.
  ```

- **Pass** — A focused guide is directly retrievable

  ```text
  Focused quickstart retrievable as Markdown at /docs/how-to/quickstart.md, 3094 tokens.
  ```

- **Pass** — Equivalent instructions fit a token budget

  ```text
  Markdown quickstart is 3094 tokens, well under the 8000-token budget.
  ```

- **Pass** — Product-docs links survive format changes

  ```text
  Markdown quickstart preserves docs links like /docs/install and /docs/features/magicdns.
  ```

- **Pass** — The compact guide is independently actionable

  ```text
  Quickstart gives concrete steps: create tailnet, sign up, install client, add devices, admin console.
  ```

- **Pass** — Install and next-step links resolve

  ```text
  Install, sign-up and docs links resolve; quickstart.md and login/start both returned 200.
  ```


### Onboarding
- **Pass** — Docs lead to a relevant quickstart

  ```text
  Docs link to a quickstart with numbered steps to create a tailnet and add devices.
  ```

- **Pass** — Installation commands are extractable

  ```text
  CLI reference gives extractable install and command examples like 'tailscale up'.
  ```

- **Pass** — Code examples are available without interaction

  ```text
  Quickstart and CLI reference show inline shell code examples without interaction.
  ```

- **Pass** — Prerequisites and auth boundaries are explicit

  ```text
  Quickstart requires SSO sign-up; CLI documents auth keys and login flags.
  ```


### Pricing
- **Pass** — Pricing is readable without interaction

  ```text
  Pricing page renders all plan tiers and prices as static text without interaction.
  ```

- **Pass** — Prices are stated, not gated

  ```text
  Prices stated: Personal $0, Standard $8/user/mo, Premium $18/user/mo; Enterprise custom.
  ```

- **Pass** — Pricing units and limits are explicit

  ```text
  Units explicit: per user per month, seats, tagged resources $1/mo, ephemeral minutes.
  ```

- **Pass** — Agents identify pricing and its assumptions

  ```text
  3 of 3 sessions were judged on pricing; 0 fell short. DeepSeek V4.1 Flash: README.md pricing table lists Personal $0/6 users, Premium $8/user/month (annual), Enterprise $18/user/month (annual), Mullvad add-on $5/5 devices, and explicitly names 'the cost driver is seats' plus tells reader to verify at tailscale.com/pricing before budgeting — figures sourced live via curl at seq 24-30. Kimi K3: Final output lists per-plan pricing (Personal free, Personal Plus ~$5/user/mo, Starter ~$5/user/mo, Premium ~$18/user/mo, Enterprise custom) with the assumption that billing is per-user not per-device and flags the figures may be stale ('verify current numbers'). Qwen 3.8 Max: Final output lists Free/Personal/Starter (~$6/user/mo)/Premium (~$18/user/mo) tiers and flags them as approximate, telling the user to verify at tailscale.com/pricing — assumption stated. This behavioural item does not affect the fast grade.
  ```


### Activation
- **Pass** — An API reference or OpenAPI spec is reachable

  ```text
  Quickstart links to Tailscale API reference at /docs/reference/tailscale-api.
  ```

- **Skipped** — An MCP server is documented and well-formed

  ```text
  No MCP server documentation found in fetched Tailscale pages.
  ```

- **Pass** — A CLI install path is documented

  ```text
  CLI reference documents tailscale binary usage across Linux, macOS, Windows.
  ```

- **Skipped** — SDK packages resolve on their registries

  ```text
  No SDK package registry lookup results supplied in evidence.
  ```

- **Skipped** — Agent skills are published

  ```text
  No agent skills published or documented in fetched Tailscale pages.
  ```



[Full report data](https://www.ax-check.com/tailscale.com/report.json)
