Skip to main content

Identity Aware MCP Server for Tailscale

TailscaleMCPIdentityHero

Create an identiy aware MCP server that runs inside your private Tailscale network (Tailnet). This example leverages identity headers that are passed through to applications running behind tailscale serve.

Using this as starting point you can create MCP servers that are identity aware (with access to the logged in user's email) and can access internal APIs or services on thier behalf.

Instructions

Starting the Server

  1. If you don't already have a Tailnet setup you'll need to signup for one.
  2. Create an API auth key and save it into a .env file in the root of this project with the following format: TS_AUTHKEY=tskey-auth-...
  3. With Docker already installed, run docker compose up to start the server.

This will spin up two containers. The MCP server and a Tailscale container running tailscale serve as a proxy to your tailnet.

Using the Server

If you have an MCP Client that supports direct access to Streaming HTTP MCP servers, then you should be able to connect to the server by pointing it to https://ts-mcp-echo.yourtailnetname.ts.net/mcp.

Claude Desktop

Claude desktop does not currently support remote MCP servers (only stdio), but you can use the mcp-remote tool (or any other proxy) to connect to it.

  1. Install mcp-remote with npm install -g mcp-remote

  2. Add the following configuration to your claude_desktop_config.json file:

        {
            "mcpServers": {
                "tailscale-remote-echo-example": {
                    "command": "npx",
                    "args": [
                        "mcp-remote",
                        "https://ts-mcp-echo.yourtailnetname.ts.net/mcp"
                    ]
                }
            }
        }
    

    You can find your tailnet name by visiting the Tailscale admin console DNS page.

  3. Restart Claude Desktop.

  4. You should now see a new MCP server called tailscale-remote-echo-example with a greet tool.

  5. Ask Claude Who am I logged into my tailnet as? allow the tool, and wait for the response!

Metadata

Release files for iflow-mcp-remyguercio-tailscale-mcp-echo 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for iflow-mcp-remyguercio-tailscale-mcp-echo 0.1.1
File Size Uploaded
iflow_mcp_remyguercio_tailscale_mcp_echo-0.1.1.tar.gz 3.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for iflow-mcp-remyguercio-tailscale-mcp-echo 0.1.1
File Interpreter ABI Platform
iflow_mcp_remyguercio_tailscale_mcp_echo-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 8.4 kB

Release files / iflow_mcp_remyguercio_tailscale_mcp_echo-0.1.1.tar.gz

Download URL iflow_mcp_remyguercio_tailscale_mcp_echo-0.1.1.tar.gz
Size 3.8 kB
Tags Source
SHA-256 checksum
How to use checksums
6be3749372f443ca0d50ca061333be6fe7e9a4e810f4a4092aa02d2922a2c5e1
BLAKE2b-256 checksum
How to use checksums
ba24dc5099ab98c837c7e2ec0c702feeb8c55ccf10a2cc3a0780d498cb1444b8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.9.28 {"installer":{"name":"uv","version":"0.9.28","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Debian GNU/Linux","version":"13","id":"trixie","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release files / iflow_mcp_remyguercio_tailscale_mcp_echo-0.1.1-py3-none-any.whl

Download URL iflow_mcp_remyguercio_tailscale_mcp_echo-0.1.1-py3-none-any.whl
Size 4.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
421f83cc88140e694b1714a96132eded1c69c474add4261877c33e883a82de89
BLAKE2b-256 checksum
How to use checksums
23582500497990c835e65c9ade84e1634347de387a70839e2224ba0a30aea545
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.9.28 {"installer":{"name":"uv","version":"0.9.28","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Debian GNU/Linux","version":"13","id":"trixie","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page