A simple OIDC / OAuth Identity Provider (IdP) server for your tailnet.
A simple OIDC / OAuth Identity Provider (IdP) server for your tailnet.
tsidp - Tailscale OpenID Connect (OIDC) Identity Provider[!CAUTION] This is an experimental update of tsidp. It is under active development and may experience breaking changes.
tsidpis an OIDC / OAuth Identity Provider (IdP) server that integrates with your Tailscale network. It allows you to use Tailscale identities for authentication into applications that support OpenID Connect as well as authenticated MCP client / server connections.
Docker images are automatically published at when releases are tagged.
[!TIP] Replace
YOUR_TAILSCALE_AUTHKEYwith your Tailscale authentication key in the following commands:Use an existing auth key or create a new auth key in the Keys page of the Tailscale admin console. Ensure you select an existing tag or create a new one.
Here is an example docker compose YAML file for tsidp:
…
yaml
environment:
- TS_AUTHKEY=tskey-client-xxxxx
- TS_ADVERTISE_TAGS=tag:tsidp
[!NOTE] Using Docker Secrets
Passing
TS_AUTHKEYas a plain environment variable puts the key indocker inspectoutput and the container's process environment. To avoid that, mount the key as a Docker secret and point tsidp at the mounted file withTS_AUTHKEY_FILEinstead:services: tsidp: image: ghcr.io/tailscale/tsidp:latest environment: - TAILSCALE_USE_WIP_CODE=1 - TS_STATE_DIR=/data - TS_AUTHKEY_FILE=/run/secrets/ts_authkey volumes: - tsidp-data:/data secrets: - ts_authkey secrets: ts_authkey: file: ./ts_authkey.txt volumes: tsidp-data:
Building your own container
$ make docker-image
Using Go directly
If you'd like to build tsidp and / or run it directly you can do the following:
# Clone the Tailscale repository
$ git clone https://github.com/tailscale/tsidp.git
$ cd tsidp
# run with default values for flags
$ TAILSCALE_USE_WIP_CODE=1 TS_AUTHKEY={YOUR_TAILSCALE_AUTHKEY} TSNET_FORCE_LOGIN=1 go run .
…
hujson
"grants": [
{
// Very permissive and suitable only for testing.
"src": ["*"],
"dst": ["*"],
// Example of a grant for tsidp:
"app": {
"tailscale.com/cap/tsidp": [
{
// allow access to UI
"allow_admin_ui": true,
// allow dynamic client registration
"allow_dcr": true,
// Secure Token Service (STS) controls
"users": ["*"],
"resources": ["*"],
// extraClaims are included in the id_token
// recommend: keep this small and simple
"extraClaims": {
"bools": true,
"strings": "Mon Jan 2 15:04:05 MST 2006",
"numbers": 180,
"array1": [1,2,3],
"array2": ["one", "two", "three"]
},
// include extraClaims data in /userinfo response
"includeInUserInfo": true,
},
],
},
},
],
The tsidp-server is configured by several command-line flags:
| Flag | Description | Default |
|---|---|---|
-dir |
Directory path to save tsnet and tsidp state. Recommend to be set. | "" |
-hostname |
hostname on tailnet. Will become .your-tailnet.ts.net |
idp |
-port |
Port to listen on | 443 |
-local-port |
Listen on localhost:. Useful for testing |
disabled |
-use-local-tailscaled |
Use local tailscaled instead of tsnet | false |
-funnel |
Use Tailscale Funnel to make tsidp available on the public internet so it works with SaaS products | disabled |
-enable-sts |
Enable OAuth token exchange using RFC 8693 | disabled |
-advertise-tags |
Comma-separated advertise tags (e.g. tag:tsidp). Required when using OAuth client secrets |
"" |
-log |
Set logging level: debug, info, warn, error |
info |
-debug-all-requests |
For development. Prints all requests and responses | disabled |
-debug-tsnet |
For development. Enables debug level logging with tsnet connection | disabled |
The tsidp-server binary is configured through the CLI flags above. However, there are several environment variables that configure the libraries tsidp-server uses to connect to the tailnet.
TAILSCALE_USE_WIP_CODE=1: required while tsidp is in development ( [!WARNING]Serverless/Stateless Deployment: tsidp requires persistent state storage to function properly in production. Without a persistent
-dir, the service will re-register with Tailscale on every restart, lose dynamic OIDC client registrations, and invalidate user sessions. Serverless environments without persistent storage are not recommended for production use.
TS_AUTHKEY=: Key for registering a tsidp as a new node on your tailnet. Can be a traditional auth key or OAuth client secret (tskey-client-xxx). If omitted, a link will be printed to manually register.TS_AUTHKEY_FILE= / -authkey-file : Same as TS_AUTHKEY, but reads the key from a file - useful when your key comes from a Docker/Kubernetes secret instead of an env var. Don't set this alongside TS_AUTHKEY; tsidp will refuse to start rather than guess which one you meant. If the file is missing, tsidp just logs a warning and carries on (it may already be registered from a previous boot). No effect with -use-local-tailscaled.TS_ADVERTISE_TAGS=: Comma-separated advertise tags (e.g., "tag:tsidp,tag:server"). Optional, but required when using OAuth client secrets.TSNET_FORCE_LOGIN=1: Force re-login of the node. Useful during development.The Docker image exposes the CLI flags through environment variables. If omitted the default values for the CLI flags will be used.
[!NOTE]
TS_STATE_DIRandTS_HOSTNAMEare legacy names. These will be replaced byTSIDP_STATE_DIRandTSIDP_HOSTNAMEin the future.
| Environment Variable | CLI flag |
|---|---|
TS_STATE_DIR= *note prefix |
-dir |
TS_HOSTNAME= *note prefix |
-hostname |
TSIDP_PORT= |
-port |
TSIDP_LOCAL_PORT= |
-local-port |
TSIDP_USE_LOCAL_TAILSCALED=1 |
-use-local-tailscaled |
TSIDP_USE_FUNNEL=1 |
-funnel |
TSIDP_ENABLE_STS=1 |
-enable-sts |
TSIDP_LOG= |
-log |
TSIDP_DEBUG_TSNET=1 |
-debug-tsnet |
TSIDP_DEBUG_ALL_REQUESTS=1 |
-debug-all-requests |
TS_AUTHKEY= |
(env var only) |
TS_AUTHKEY_FILE= |
-authkey-file |
TS_ADVERTISE_TAGS= |
-advertise-tags |
tsidp can be used as IdP server for any application that supports custom OIDC providers.
[!IMPORTANT] Note: If you'd like to use tsidp to login to a SaaS application outside of your tailnet rather than a self-hosted app inside of your tailnet, you'll need to run tsidp with
--funnelenabled.
tsidp supports all of the endpoints required & suggested by the MCP Authorization specification, including Dynamic Client Registration (DCR). More information can be found in the following examples:
This is an experimental, work in progress, community project. For issues or questions, file issues on the GitHub repository.
BSD-3-Clause License. See LICENSE for details.
No open issues yet, or sync has not completed.