Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

datasette-auth-tailscale

PyPI Changelog Tests License

Configure access to a Datasette instance with Tailscale

[!WARNING] This is pre-alpha software that has not been thoroughly tested or reviewed yet!

Installation

Install this plugin in the same environment as Datasette.

datasette install datasette-auth-tailscale

Usage

This plugin authenticates Datasette users from the identity headers that Tailscale Serve injects when proxying tailnet traffic to a backend.

Run Datasette behind tailscale serve, listening only on localhost:

datasette mydata.db --host 127.0.0.1 --port 8001
tailscale serve --https=443 http://127.0.0.1:8001

[!WARNING] Bind Datasette to localhost. These headers are trusted unconditionally — Tailscale strips them from incoming requests before adding its own, but only for requests that actually arrive via Serve. If Datasette is reachable from your LAN or tailnet directly, anyone can spoof the headers and impersonate any user. Always bind to 127.0.0.1 (or the loopback interface) so the only path to Datasette is through Serve.

Tailscale Funnel does not include identity headers. Funnel users will be rejected by default (see require_tailscale below).

Actor shape

A request from alice@example.com produces an actor like:

{
  "id": "alice@example.com",
  "display": "Alice Architect",
  "picture": "https://example.com/alice.jpg",
}
  • id — Tailscale-User-Login
  • display — Tailscale-User-Name (omitted if not present)
  • picture — Tailscale-User-Profile-Pic (omitted if not present)

Configuration

Configure under plugins.datasette-auth-tailscale in datasette.yaml:

plugins:
  datasette-auth-tailscale:
    require_tailscale: true

Metadata

Release files for datasette-auth-tailscale 0.0.1a1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for datasette-auth-tailscale 0.0.1a1
File Size Uploaded
datasette_auth_tailscale-0.0.1a1.tar.gz 8.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for datasette-auth-tailscale 0.0.1a1
File Interpreter ABI Platform
datasette_auth_tailscale-0.0.1a1-py3-none-any.whl Python 3 none any Details

Total release size: 15.9 kB

Release files / datasette_auth_tailscale-0.0.1a1.tar.gz

Download URL datasette_auth_tailscale-0.0.1a1.tar.gz
Size 8.0 kB
Tags Source
SHA-256 checksum
How to use checksums
58914b19e1f747327578fb7ea5219ab573c38ab760440bf16792bd0a56d778a6
BLAKE2b-256 checksum
How to use checksums
0087fccef800408ad13a3aac06cc7ff6045210ece4f440d8c62577eb13161e14
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.11.11 {"installer":{"name":"uv","version":"0.11.11","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / datasette_auth_tailscale-0.0.1a1-py3-none-any.whl

Download URL datasette_auth_tailscale-0.0.1a1-py3-none-any.whl
Size 7.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
85042297cd01de8ade6816532b241a361796be086828ec50317cf190a1f6fed2
BLAKE2b-256 checksum
How to use checksums
52b7320e492ae6fb8c9250c9ddec04b8ac9549392f02153ca68a622009f19aa2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.11.11 {"installer":{"name":"uv","version":"0.11.11","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

This release

0.0.1a1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page