Secure Tailscale with Mondoo
Continuously scan your Tailscale tailnet, devices, and users for misconfigurations and security issues.
Mondoo continuously scans your Tailscale tailnet for misconfigurations and security issues. Create a Tailscale integration to give Mondoo read-only access to the tailnet.
Mondoo adds the tailnet and its members to your space as assets:
- The Tailscale Organization asset represents the tailnet itself, including its access control policy, auth keys, tailnet settings such as device and user approval, log streaming, and webhooks.
- Each Tailscale Device asset covers a device's authorization, key expiry, client updates, and Tailnet Lock state.
- Each Tailscale User asset represents a member of the tailnet.
Prerequisites
- Editor or Owner access to the Mondoo space
- A Tailscale tailnet
- The Owner, Admin, Network admin, or IT admin role in the tailnet, to create an OAuth client
Create Tailscale credentials
Mondoo can authenticate with an OAuth client or an API access token. Tailscale recommends OAuth clients, because you can limit them to read-only scopes and they don't expire with a user's account.
Create an OAuth client (recommended)
-
Log in to the Tailscale admin console and go to Settings > Trust credentials.
-
Select Credential, then choose OAuth.
-
Grant read access only. The simplest choice is the
all:readscope, which covers every read endpoint, including any Tailscale adds later. To grant only what Mondoo uses today, give read access to:- Devices (
devices:core:read) - Users (
users:read) - Policy file (
policy_file:read) - Auth keys (
auth_keys:read) - Feature settings (
feature_settings:read) - Log streaming (
log_streaming:read) - Webhooks (
webhooks:read)
- Devices (
-
Select Generate credential.
-
Copy the client ID and the client secret. Tailscale shows the secret only once.
To learn more, see OAuth clients and trust credential scopes in the Tailscale documentation.
Generate an API access token
-
Log in to the Tailscale admin console and go to Settings > Keys.
-
Generate an API access token and copy it.
An API access token acts with the permissions of the user who created it and expires after at most 90 days. When it expires, Mondoo can't scan until you add a new token.
Treat the OAuth client secret or API access token like a password. Don't commit it to source control.
Add a Tailscale integration
In the Mondoo App, navigate to the space where you want to add the integration. In the side navigation bar, select Integrations. In the top right, select INSTALL. On the Install Integration page, find the integration you want by browsing a category or searching by name:
-
Under Network Security, select Tailscale.

-
In the Choose an integration name box, enter a name that identifies the tailnet.
-
Under Authentication, choose how Mondoo authenticates:
- On the OAuth (suggested) tab, enter the Client ID and Client Secret of the OAuth client.
- On the Token Authentication tab, enter the API access token.
-
(Optional) Under Enable security policies, review the policies that apply to Tailscale. The Mondoo Tailscale Security policy checks tailnet ACLs and device settings. If a policy isn't enabled in the space yet, select ENABLE. A policy you enable here applies to the whole space, not only this integration.
-
Select CREATE INTEGRATION.
Mondoo scans the tailnet that the credentials belong to, and starts the first scan as soon as the integration is created. To learn how policies work, read Manage Policies.
View results
Mondoo adds the tailnet, device, and user assets to the space inventory. To review them, navigate to the space and select Inventory > Assets. To see how the assets score against the policy, select Findings > Policies and choose Mondoo Tailscale Security.
Manage your integration
To open the integration, navigate to the space, select Integrations > Tailscale, and choose the integration.
From the integration detail page, you can:
- Scan now. Select RUN.
- Pause or resume scanning. Select the more actions menu, then Pause or Resume.
- Remove the integration. Select the trash can icon and confirm. Mondoo stops scanning the tailnet.
Mondoo doesn't support editing a Tailscale integration. To use different credentials, remove the integration and add a new one.
Scan Tailscale from the command line
The integration scans continuously from the Mondoo Platform. To scan a tailnet from your workstation or a CI pipeline instead, see Secure Tailscale with cnspec.