Tailcat: Secure Tunnels in Seconds Without Tailscale's Control Plane
Tailcat: Secure Tunnels in Seconds (Tailscale)

Tailscale has released Tailcat, an open-source tool that reuses its encrypted data plane (WireGuard, magicsock, DERP) to create point-to-point tunnels without needing a Tailscale account or control plane. It works like netcat: one side runs a server and gets a short token, the other side uses it to connect, with end-to-end encryption and automatic NAT traversal. It can pipe stdin/stdout, expose local ports, run an auth-free SSH server, and more, all in userspace without root.
All traffic between the two is encrypted end-to-end with WireGuard.
- bradfitz
One fun use case: a coworker just whipped up this Minecraft mod using tailcat as its transport: https://github.com/tailscale/tailcat-for-minecraft
(just a cute demo, not intended for release or ongoing maintenance)
- megamorf
So this is somewhat similar to Iroh?
- Schlagbohrer
The Tor network and Onion protocols used to be used for this type of thing 10 or 15 years ago, exposing a home service with a .onion address and then gaining secure private access over the global internet infrastructure that way. But I haven't even seen any Tor related headlines for ages.
- mikepurvis
I enjoy that they supply a nix install/environment, similar to the main tailscale/tailscale repo. Is nix widespread or the standard dev environment at tailscale, or is it like a 10% option and most people just use Docker or whatever?
- pbohun
This is so cool! I mean, we really wouldn't need it if we had 100% ipv6 (no cgnat), but this is the next best thing. I think people underestimate the innovation that could happen if we had trivial p2p.
- stillpointlab
I've spent time finally learning what tailscale is and how it works and I'm impressed. It's a rare thing in the technology world but I'm glad I finally took the time.
I literally just figured out how tsnet fits into the picture (an in-process Go based entire network stack that gets the process to act as a node in the tailnet) and so that helps me understand this (everything in tsnet excepting the control plane). It's very impressive that they can do this in a reliable way.
- archietect
It looks like a direct competitor for the recently launched bitbang-cli
- aseipp
Just yesterday I was complaining that I wanted to SSH back to my homenet while at the office, on my office (not home) tailnet. I wrote something based on Iroh to do this, but it's one shot (ie not particularly generalized). Might be able to throw it away or redesign it with some inspiration from this! Thanks.