Tailscale
@swamp/tailscalev2026.10.02.2
01README
Tailscale tailnet management models
02Release Notes
- Updated: tailnet_key, oauth_client, federated_identity, webhook, posture_integration, oauth_app, user_invite, device_invite, service, log_stream
03Models
@swamp/tailscale/contactsv2026.10.02.1contacts.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| account? | object | The account contact |
| support? | object | The support contact |
| security? | object | The security contact |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Apply the contacts from the global arguments
fn get()
Read the current contacts into state
fn update()
Apply the contacts from the global arguments
fn delete()
Stop managing the contacts; Tailscale keeps the current values
fn sync()
Refresh the contacts from Tailscale
fn resend_verification_email(contactType: enum)
Resend the verification email for a contact
| Argument | Type | Description |
|---|---|---|
| contactType | enum | Type of contact. |
Resources
state(infinite)— Contacts state
@swamp/tailscale/devicev2026.10.02.1device.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn get(id: string)
Get a device by ID
| Argument | Type | Description |
|---|---|---|
| id | string | The device's ID |
fn delete(id: string)
Delete the device from the tailnet
| Argument | Type | Description |
|---|---|---|
| id | string | The device's ID |
fn list()
List devices in the tailnet and write each to state
fn adopt(id: string, expected_name?: string)
Adopt an existing device by ID into managed state
| Argument | Type | Description |
|---|---|---|
| id | string | The ID of the device to adopt |
| expected_name? | string | Expected name, checked before adopting |
fn expire(id: string)
Expire the device's node key, forcing it to re-authenticate
| Argument | Type | Description |
|---|---|---|
| id | string | The device's ID |
fn set_name(id: string, name: string)
Set the device's machine name
| Argument | Type | Description |
|---|---|---|
| id | string | The device's ID |
| name | string | The new name for the device.\n\nThis can be provided as either the fully qualified domain name for the device (e.g. "nodename.your-domain.ts.net")\nor just the base name (e.g. "nodename").\n\nIf `name` is unset or provided empty, the device\ |
fn set_ipv4_address(id: string, ipv4: string)
Set the device's Tailscale IPv4 address
| Argument | Type | Description |
|---|---|---|
| id | string | The device's ID |
| ipv4 | string | The new IPv4 address for the device. |
Resources
state(infinite)— Device state
@swamp/tailscale/device-authorizationv2026.10.02.1device_authorization.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| deviceId | string | ID of the device. Using the device's `nodeId` is preferred, but its numeric `id` value can also be used. |
| authorized? | boolean | - If `true`, authorize a new device or re-authorize a previously deauthorized device.\n- If `false`, deauthorize an authorized device. |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Apply the device authorization from the global arguments
fn get()
Read the current device authorization into state
fn update()
Apply the device authorization from the global arguments
fn delete()
Stop managing the device authorization; Tailscale keeps the current values
fn sync()
Refresh the device authorization from Tailscale
Resources
state(infinite)— Device authorization state
@swamp/tailscale/device-invitev2026.10.02.2device_invite.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| name | string | Instance name for this device invite, used as the unique identifier in the factory pattern |
| deviceId | string | ID of the device. Using the device's `nodeId` is preferred, but its numeric `id` value can also be used. |
| multiUse? | boolean | Whether the invite can be accepted more than once.\nWhen set to `true`, it results in an invite that can be accepted up to 1,000 times. |
| allowExitNode? | boolean | Whether the invited user can use the device as an exit node when it advertises as one. |
| email? | string | The email to send the created invite to.\nIf not set, the endpoint generates and returns an invite URL (but doesn't send it out). |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Create a device invite
fn get(id: string)
Get a device invite by ID
| Argument | Type | Description |
|---|---|---|
| id | string | The device invite's ID |
fn delete(id?: string)
Delete the device invite
| Argument | Type | Description |
|---|---|---|
| id? | string | The device invite's ID; defaults to the stored device invite |
fn sync()
Refresh the stored device invite from Tailscale
fn list()
List device invites and write each to state
fn adopt(id: string)
Adopt an existing device invite by ID into managed state
| Argument | Type | Description |
|---|---|---|
| id | string | The ID of the device invite to adopt |
fn resend()
Resend the invitation email
Resources
state(infinite)— Device invite state
@swamp/tailscale/device-keyv2026.10.02.1device_key.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| deviceId | string | ID of the device. Using the device's `nodeId` is preferred, but its numeric `id` value can also be used. |
| keyExpiryDisabled? | boolean | - If `true`, disable the device's key expiry. The original key expiry time is still maintained. Upon re-enabling, the key will expire at that original time.\n- If `false`, enable the device's key expiry. Sets the key to expire at the original expiry time prior to disabling. The key may already have expired. In that case, the device must be re-authenticated. |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Apply the device key from the global arguments
fn get()
Read the current device key into state
fn update()
Apply the device key from the global arguments
fn delete()
Clear the device key
fn sync()
Refresh the device key from Tailscale
Resources
state(infinite)— Device key state
@swamp/tailscale/device-posture-attributev2026.10.02.1device_posture_attribute.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| deviceId | string | ID of the device. Using the device's `nodeId` is preferred, but its numeric `id` value can also be used. |
| attributeKey | string | The name of the posture attribute to set.\nThis must be prefixed with `custom`:\n\nKeys have a maximum length of 128 characters including the namespace,\nand can only contain letters, numbers, underscores, and colon.\n\nKeys are case-sensitive. Keys must be unique,\nbut are checked for uniqueness in a case-insensitive manner.\nFor example, `custom:MyAttribute` and `custom:myattribute` cannot both be set within a single tailnet.\n\nAll values for a given key need to be of the same type,\nwhich is |
| value? | union | A value can be either a string, number or boolean.\n\nA string value can have a maximum length of 50 characters,\nand can only contain letters, numbers, underscores, and periods.\n\nA number value is an integer and must be a JSON safe number (up to 2^53 - 1). |
| expiry? | string | An optional expiry time for a given posture attribute. If set, Tailscale\nwill automatically remove the attribute within a few minutes after the specified\ntime. |
| comment? | string | An optional comment indicating a reason why an attribute is set,\nwhich will be added to the audit log. |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Apply the device posture attribute from the global arguments
fn get()
Read the current device posture attribute into state
fn update()
Apply the device posture attribute from the global arguments
fn delete()
Delete the device posture attribute
fn sync()
Refresh the device posture attribute from Tailscale
Resources
state(infinite)— Device posture attribute state
@swamp/tailscale/device-subnet-routesv2026.10.02.1device_subnet_routes.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| deviceId | string | ID of the device. Using the device's `nodeId` is preferred, but its numeric `id` value can also be used. |
| routes? | array | The new list of enabled subnet routes. |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Apply the device subnet routes from the global arguments
fn get()
Read the current device subnet routes into state
fn update()
Apply the device subnet routes from the global arguments
fn delete()
Clear the device subnet routes
fn sync()
Refresh the device subnet routes from Tailscale
Resources
state(infinite)— Device subnet routes state
@swamp/tailscale/device-tagsv2026.10.02.1device_tags.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| deviceId | string | ID of the device. Using the device's `nodeId` is preferred, but its numeric `id` value can also be used. |
| tags? | array | The new list of tags for the device. |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Apply the device tags from the global arguments
fn get()
Read the current device tags into state
fn update()
Apply the device tags from the global arguments
fn delete()
Clear the device tags
fn sync()
Refresh the device tags from Tailscale
Resources
state(infinite)— Device tags state
@swamp/tailscale/dns-configurationv2026.10.02.1dns_configuration.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| nameservers? | array | Global DNS resolvers to use. If `preferences.overrideLocalDNS` is true, these override the local OS configuration; otherwise they are used as fallback resolvers. |
| splitDNS? | record | Map of DNS name suffixes (domains) to lists of resolvers for Split DNS and advanced routing overlays. |
| searchPaths? | array | Search domain paths to apply. |
| preferences? | object | |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Apply the DNS configuration from the global arguments
fn get()
Read the current DNS configuration into state
fn update()
Apply the DNS configuration from the global arguments
fn delete()
Clear the DNS configuration
fn sync()
Refresh the DNS configuration from Tailscale
Resources
state(infinite)— DNS configuration state
@swamp/tailscale/dns-nameserversv2026.10.02.1dns_nameservers.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| dns? | array | DNS nameservers. |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Apply the DNS nameservers from the global arguments
fn get()
Read the current DNS nameservers into state
fn update()
Apply the DNS nameservers from the global arguments
fn delete()
Clear the DNS nameservers
fn sync()
Refresh the DNS nameservers from Tailscale
Resources
state(infinite)— DNS nameservers state
@swamp/tailscale/dns-preferencesv2026.10.02.1dns_preferences.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| magicDNS? | boolean | Whether MagicDNS is active for this tailnet. |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Apply the DNS preferences from the global arguments
fn get()
Read the current DNS preferences into state
fn update()
Apply the DNS preferences from the global arguments
fn delete()
Clear the DNS preferences
fn sync()
Refresh the DNS preferences from Tailscale
Resources
state(infinite)— DNS preferences state
@swamp/tailscale/dns-search-pathsv2026.10.02.1dns_search_paths.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| searchPaths? | array | The search domains for the given tailnet. |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Apply the DNS search paths from the global arguments
fn get()
Read the current DNS search paths into state
fn update()
Apply the DNS search paths from the global arguments
fn delete()
Clear the DNS search paths
fn sync()
Refresh the DNS search paths from Tailscale
Resources
state(infinite)— DNS search paths state
@swamp/tailscale/dns-split-nameserversv2026.10.02.1dns_split_nameservers.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| domain | string | The split-DNS domain this model manages |
| nameservers? | array | Nameservers that resolve the domain |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Apply the split DNS nameservers from the global arguments
fn get()
Read the current split DNS nameservers into state
fn update()
Apply the split DNS nameservers from the global arguments
fn delete()
Clear the split DNS nameservers
fn sync()
Refresh the split DNS nameservers from Tailscale
Resources
state(infinite)— Split DNS nameservers state
@swamp/tailscale/federated-identityv2026.10.02.2federated_identity.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| name | string | Instance name for this federated identity, used as the unique identifier in the factory pattern |
| description? | string | A short string specifying the purpose of the key. Can be a maximum of 50 alphanumeric characters. Hyphens and spaces are also allowed. |
| scopes? | array | A list of scopes to grant to the key. At least one scope is required for OAuth clients and federated identities.\nSee [trust credentials scopes](https://tailscale.com/docs/reference/trust-credentials#scopes) for a list of available scopes.\n\nOnly applies to OAuth clients and federated identities. |
| tags? | array | A list of tags associated to the trust credential. Auth keys created with this credential must have these exact tags, or tags owned by the credential\ |
| issuer? | string | The issuer of the OIDC identity token used in the token exchange. Must be a valid and publicly reachable https:// URL.\n\nOnly applies to federated identities. |
| subject? | string | The pattern used when matching against the `sub` claim from an OIDC identity token.\nPatterns can include `*` characters to match against any character.\n\nOnly applies to federated identities. |
| audience? | string | The value used when matching against the `aud` claim from an OIDC identity token.\n\nSpecifying the audience is optional as Tailscale will generate a secure audience at creation time by default.\nIt is recommended to let Tailscale generate the audience unless the identity provider you are integrating with\nrequires a specific audience format.\n\nOnly applies to federated identities. |
| customClaimRules? | record | A map of claim names to pattern strings used to match against arbitrary claims in the OIDC identity token.\nPatterns can include `*` characters to match against any character.\n\nOnly applies to federated identities. |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Create a federated identity
fn get(id: string)
Get a federated identity by ID
| Argument | Type | Description |
|---|---|---|
| id | string | The federated identity's ID |
fn update()
Update the federated identity from the global arguments
fn delete(id?: string)
Delete the federated identity
| Argument | Type | Description |
|---|---|---|
| id? | string | The federated identity's ID; defaults to the stored federated identity |
fn sync()
Refresh the stored federated identity from Tailscale
fn list()
List federated identitys and write each to state
fn adopt(id: string)
Adopt an existing federated identity by ID into managed state
| Argument | Type | Description |
|---|---|---|
| id | string | The ID of the federated identity to adopt |
Resources
state(infinite)— Federated identity state
@swamp/tailscale/log-streamv2026.10.02.2log_stream.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| destinationType? | enum | The type of system to which logs are being streamed. |
| url? | string | The URL to which log streams are being posted. If the DestinationType is `s3`, the URL may be (and often is) empty to use the official Amazon S3 endpoint. |
| user? | string | The username with which log streams to this endpoint are authenticated. |
| uploadPeriodMinutes? | number | An optional number of minutes to wait in between uploading new logs. If the quantity of logs does not fit within a single upload, multiple uploads will be made. |
| compressionFormat? | enum | The compression algorithm with which to compress logs. `none` disables compression. Defaults to `none`. |
| token? | string | The token/password with which log streams to this endpoint should be authenticated. |
| s3Bucket? | string | The S3 bucket name. Required if the destinationType is `s3`. |
| s3Region? | string | The region in which the S3 bucket is located. Required if the destinationType is `s3`. |
| s3KeyPrefix? | string | An optional S3 key prefix to prepend to the auto-generated S3 key name. |
| s3AuthenticationType? | enum | What type of authentication to use for S3. Required if the destinationType is `s3`. Tailscale recommends using `rolearn`. See [Amazon documentation](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_common-scenarios_third-party.html). |
| s3AccessKeyId? | string | The S3 access key ID. Required if the destinationType is `s3` and `authenticationType` is `accesskey`. |
| s3SecretAccessKey? | string | The S3 secret access key. Required if the destinationType is `s3` and `authenticationType` is `accesskey`. |
| s3RoleArn? | string | The Role ARN that Tailscale should supply to AWS when authenticating using role-based authentication. Required if the destinationType is `s3` and `authenticationType` is `rolearn`. |
| gcsBucket? | string | The GCS bucket name. Required if the destinationType is `gcs`. |
| gcsKeyPrefix? | string | An optional GCS key prefix to append to the GCS bucket name. |
| gcsScopes? | array | The GCS scopes needed to be able to write to the GCS bucket. |
| gcsCredentials? | string | The JSON workload identity credentials from GCS needed for accessing the GCS account. |
| logType | enum | The type of log. |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Create the log stream; fails if one already exists for logType
fn get()
Get the log stream for logType and write it to state
fn update()
Update the log stream from the global arguments
fn delete()
Delete the log stream
fn sync()
Refresh the log stream from Tailscale
Resources
state(infinite)— Log stream state
@swamp/tailscale/oauth-appv2026.10.02.2oauth_app.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| instanceName | string | Instance name for this OAuth app, used as the unique identifier in the factory pattern |
| name? | string | The name of the OAuth app.\nMust be between 3 and 50 characters and contain only alphanumeric characters, dashes, periods, and underscores. |
| description? | string | A human-readable description of the OAuth app.\nMust be at most 300 characters. |
| redirectURIs? | array | The list of permitted redirect URIs for the OAuth authorization code flow.\nAt least one redirect URI is required.\n\nEach URI must use the `https` scheme, except for `localhost`, `127.0.0.1`, and `::1`,\nwhich may use any scheme. Raw IP address hosts are not permitted. |
| scopes? | array | The list of OAuth scopes granted to the app.\nMust be non-empty.\nLearn more about [OAuth clients and scopes](/docs/features/oauth-clients). |
| allowedNodeAttributes? | array | The list of custom device attributes that the OAuth app is allowed to set. |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Create an OAuth app
fn get(id: string)
Get an OAuth app by ID
| Argument | Type | Description |
|---|---|---|
| id | string | The OAuth app's ID |
fn update()
Update the OAuth app from the global arguments
fn delete(id?: string)
Delete the OAuth app
| Argument | Type | Description |
|---|---|---|
| id? | string | The OAuth app's ID; defaults to the stored OAuth app |
fn sync()
Refresh the stored OAuth app from Tailscale
fn list()
List OAuth apps and write each to state
fn lookup()
Find an existing OAuth app by name and write it to state
fn adopt(id: string, expected_name?: string)
Adopt an existing OAuth app by ID into managed state
| Argument | Type | Description |
|---|---|---|
| id | string | The ID of the OAuth app to adopt |
| expected_name? | string | Expected name, checked before adopting |
Resources
state(infinite)— OAuth app state
secret(infinite)— Secrets returned only when the OAuth app is created (or its secret rotated). Stored in a vault.
@swamp/tailscale/oauth-clientv2026.10.02.2oauth_client.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| name | string | Instance name for this OAuth client, used as the unique identifier in the factory pattern |
| description? | string | A short string specifying the purpose of the key. Can be a maximum of 50 alphanumeric characters. Hyphens and spaces are also allowed. |
| scopes? | array | A list of scopes to grant to the key. At least one scope is required for OAuth clients and federated identities.\nSee [trust credentials scopes](https://tailscale.com/docs/reference/trust-credentials#scopes) for a list of available scopes.\n\nOnly applies to OAuth clients and federated identities. |
| tags? | array | A list of tags associated to the trust credential. Auth keys created with this credential must have these exact tags, or tags owned by the credential\ |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Create an OAuth client
fn get(id: string)
Get an OAuth client by ID
| Argument | Type | Description |
|---|---|---|
| id | string | The OAuth client's ID |
fn update()
Update the OAuth client from the global arguments
fn delete(id?: string)
Delete the OAuth client
| Argument | Type | Description |
|---|---|---|
| id? | string | The OAuth client's ID; defaults to the stored OAuth client |
fn sync()
Refresh the stored OAuth client from Tailscale
fn list()
List OAuth clients and write each to state
fn adopt(id: string)
Adopt an existing OAuth client by ID into managed state
| Argument | Type | Description |
|---|---|---|
| id | string | The ID of the OAuth client to adopt |
Resources
state(infinite)— OAuth client state
secret(infinite)— Secrets returned only when the OAuth client is created (or its secret rotated). Stored in a vault.
@swamp/tailscale/policy-filev2026.10.02.1policy_file.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| policy? | string | The policy file as HuJSON (JSON with comments and trailing commas) |
| overwriteExistingContent? | boolean | Let create replace a policy file that has been edited since the tailnet was created |
| resetOnDelete? | boolean | Reset the policy file to the default when the model is deleted |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Replace the policy file; refuses to overwrite an edited policy unless overwriteExistingContent is set
fn get()
Read the current policy file into state
fn update()
Replace the policy file; refuses if it changed since the last get or sync
fn delete()
Stop managing the policy file; resets it to the default only when resetOnDelete is set
fn sync()
Refresh the policy file from Tailscale
fn preview(type?: enum, previewFor?: string)
Preview which rules in the policy match a user or an IP:port
| Argument | Type | Description |
|---|---|---|
| type? | enum | Specify for which type of resource (user or IP port) matching rules are to be fetched.\nRead about [previewing changes in the admin console](https://tailscale.com/docs/features/tailnet-policy-file/manage-tailnet-policies#preview-changes).\n\nOAuth Scope: `policy_file:read`. |
| previewFor? | string | - If `type` is `user`, provide the email of a valid user with registered machines.\n- If `type` is `ipport`, provide an IP address + port: `10.0.0.1:80`.\n\nThe supplied policy file is queried with this parameter to determine which rules match. |
fn validate()
Validate the policy and run its tests without saving it
Resources
state(infinite)— Policy file state
result(infinite)— The response of the most recent run of each action that returns data
@swamp/tailscale/posture-integrationv2026.10.02.2posture_integration.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| name | string | Instance name for this posture integration, used as the unique identifier in the factory pattern |
| provider? | enum | The device posture provider.\n\nRequired on POST requests, ignored on PATCH requests. |
| cloudId? | string | Identifies which of the provider's clouds to integrate with.\n\n- For CrowdStrike Falcon, it will be one of `us-1`, `us-2`, `eu-1` or `us-gov`.\n- For Microsoft Intune, it will be one of `global` or `us-gov`. \n- For Jamf Pro, Kandji and Sentinel One, it is the FQDN of your subdomain, for example `mydomain.sentinelone.net`.\n- For Kolide, this is left blank. |
| clientId? | string | Unique identifier for your client.\n\n- For Microsoft Intune, it will be your application's UUID.\n- For CrowdStrike Falcon and Jamf Pro, it will be your client id.\n- For Kandji, Kolide and Sentinel One, this is left blank. |
| tenantId? | string | The Microsoft Intune directory (tenant) ID. For other providers, this is left blank. |
| clientSecret? | string | The secret (auth key, token, etc.) used to authenticate with the provider.\n\nRequired when creating a new integration, may be omitted when updating an existing integration, in which case we retain the existing password. |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Create a posture integration
fn get(id: string)
Get a posture integration by ID
| Argument | Type | Description |
|---|---|---|
| id | string | The posture integration's ID |
fn update()
Update the posture integration from the global arguments
fn delete(id?: string)
Delete the posture integration
| Argument | Type | Description |
|---|---|---|
| id? | string | The posture integration's ID; defaults to the stored posture integration |
fn sync()
Refresh the stored posture integration from Tailscale
fn list()
List posture integrations and write each to state
fn adopt(id: string)
Adopt an existing posture integration by ID into managed state
| Argument | Type | Description |
|---|---|---|
| id | string | The ID of the posture integration to adopt |
Resources
state(infinite)— Posture integration state
@swamp/tailscale/servicev2026.10.02.2service.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| addrs? | array | The IP addresses assigned to the Service: the IPv4 followed by the IPv6. |
| name | string | The unique name of the Service. |
| displayName? | string | An optional human-readable label for the Service, shown in the Tailscale admin console\nand to clients with access to the Service.\nMust be 64 characters or fewer. |
| comment? | string | An optional comment for the Service. |
| ports? | array | A list of protocol:port pairs to be exposed by the Service.\n\nThe only supported protocol is "tcp" at this time. "do-not-validate" can be used to skip validation. |
| tags? | array | A list of optional tags associated with the Service. |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Create the service; fails if one already exists for name
fn get()
Get the service for name and write it to state
fn update()
Update the service from the global arguments
fn delete()
Delete the service
fn sync()
Refresh the service from Tailscale
fn list()
List services and write each to state
fn list_devices()
List the devices hosting the service
fn get_device_approval(deviceId: string)
Get whether a device is approved to host the service
| Argument | Type | Description |
|---|---|---|
| deviceId | string | ID of the device. Using the device's `nodeId` is preferred, but its numeric `id` value can also be used. |
fn set_device_approval(deviceId: string, approved?: boolean)
Approve or unapprove a device to host the service
| Argument | Type | Description |
|---|---|---|
| deviceId | string | ID of the device. Using the device's `nodeId` is preferred, but its numeric `id` value can also be used. |
| approved? | boolean | Indicates whether to approve or revoke approval for the Service on the device. |
Resources
state(infinite)— Service state
result(infinite)— The response of the most recent run of each action that returns data
@swamp/tailscale/tailnet-keyv2026.10.02.2tailnet_key.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| name | string | Instance name for this auth key, used as the unique identifier in the factory pattern |
| description? | string | A short string specifying the purpose of the key. Can be a maximum of 50 alphanumeric characters. Hyphens and spaces are also allowed. |
| capabilities? | object | `capabilities` is a mapping of resources to permissible actions. |
| expirySeconds? | number | Specifies the duration in seconds until the key expires. Defaults to 90 days if not supplied.\n\nOnly applies to auth keys. |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Create an auth key
fn get(id: string)
Get an auth key by ID
| Argument | Type | Description |
|---|---|---|
| id | string | The auth key's ID |
fn delete(id?: string)
Delete the auth key
| Argument | Type | Description |
|---|---|---|
| id? | string | The auth key's ID; defaults to the stored auth key |
fn sync()
Refresh the stored auth key from Tailscale
fn list()
List auth keys and write each to state
fn adopt(id: string)
Adopt an existing auth key by ID into managed state
| Argument | Type | Description |
|---|---|---|
| id | string | The ID of the auth key to adopt |
Resources
state(infinite)— Auth key state
secret(infinite)— Secrets returned only when the auth key is created (or its secret rotated). Stored in a vault.
@swamp/tailscale/tailnet-settingsv2026.10.02.1tailnet_settings.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| aclsExternallyManagedOn? | boolean | Prevents users from editing policies in the admin console to avoid conflicts with external management workflows like GitOps or Terraform. |
| aclsExternalLink? | string | Link to the external tailnet policy definition or management solution for this tailnet. |
| devicesApprovalOn? | boolean | Whether [device approval](/docs/features/access-control/device-management/device-approval) is enabled for the tailnet. |
| devicesAutoUpdatesOn? | boolean | Whether [auto updates](/docs/features/client/update#auto-updates) are enabled for devices that belong to this tailnet. |
| devicesKeyDurationDays? | number | The [key expiry](/docs/features/access-control/key-expiry) duration for devices on this tailnet. |
| usersApprovalOn? | boolean | Whether [user approval](/docs/features/access-control/user-approval) is enabled for this tailnet. |
| usersRoleAllowedToJoinExternalTailnets? | enum | Which user roles are allowed to [join external tailnets](/docs/features/sharing/how-to/invite-any-user). |
| networkFlowLoggingOn? | boolean | Whether [network flog logs](/docs/features/logging/network-flow-logs) are enabled for the tailnet. |
| regionalRoutingOn? | boolean | Whether [regional routing](/docs/how-to/set-up-high-availability#regional-routing) is enabled for the tailnet. |
| postureIdentityCollectionOn? | boolean | Whether [identity collection](/docs/features/access-control/device-management/how-to/manage-identity) is enabled for [device posture](/docs/features/device-posture) integrations for the tailnet. |
| httpsEnabled? | boolean | Whether provisioning of [HTTPS certificates](/docs/how-to/set-up-https-certificates) is enabled for this tailnet. |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Apply the tailnet settings from the global arguments
fn get()
Read the current tailnet settings into state
fn update()
Apply the tailnet settings from the global arguments
fn delete()
Stop managing the tailnet settings; Tailscale keeps the current values
fn sync()
Refresh the tailnet settings from Tailscale
Resources
state(infinite)— Tailnet settings state
@swamp/tailscale/userv2026.10.02.1user.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn get(id: string)
Get an user by ID
| Argument | Type | Description |
|---|---|---|
| id | string | The user's ID |
fn delete(id: string)
Delete the user from the tailnet
| Argument | Type | Description |
|---|---|---|
| id | string | The user's ID |
fn list()
List users in the tailnet and write each to state
fn adopt(id: string, expected_name?: string)
Adopt an existing user by ID into managed state
| Argument | Type | Description |
|---|---|---|
| id | string | The ID of the user to adopt |
| expected_name? | string | Expected loginName, checked before adopting |
fn set_role(id: string, role?: enum)
Change the user's role
| Argument | Type | Description |
|---|---|---|
| id | string | The user's ID |
| role? | enum | The role of the user. Learn more about [user roles](/docs/reference/user-roles). |
fn approve(id: string)
Approve a user waiting for approval
| Argument | Type | Description |
|---|---|---|
| id | string | The user's ID |
fn suspend(id: string)
Suspend the user
| Argument | Type | Description |
|---|---|---|
| id | string | The user's ID |
fn restore(id: string)
Restore a suspended user
| Argument | Type | Description |
|---|---|---|
| id | string | The user's ID |
Resources
state(infinite)— User state
@swamp/tailscale/user-invitev2026.10.02.2user_invite.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| name | string | Instance name for this user invite, used as the unique identifier in the factory pattern |
| role? | enum | Optionally specifies a user role to assign the invited user. |
| email? | string | Optionally specifies the email to send the created invite.\nIf not set, the endpoint generates and returns an invite URL, but does not email it out. |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Create an user invite
fn get(id: string)
Get an user invite by ID
| Argument | Type | Description |
|---|---|---|
| id | string | The user invite's ID |
fn delete(id?: string)
Delete the user invite
| Argument | Type | Description |
|---|---|---|
| id? | string | The user invite's ID; defaults to the stored user invite |
fn sync()
Refresh the stored user invite from Tailscale
fn list()
List user invites and write each to state
fn adopt(id: string)
Adopt an existing user invite by ID into managed state
| Argument | Type | Description |
|---|---|---|
| id | string | The ID of the user invite to adopt |
fn resend()
Resend the invitation email
Resources
state(infinite)— User invite state
@swamp/tailscale/webhookv2026.10.02.2webhook.ts
Global Arguments
| Argument | Type | Description |
|---|---|---|
| name | string | Instance name for this webhook, used as the unique identifier in the factory pattern |
| endpointUrl? | string | The endpoint that events are sent to from Tailscale via POST requests. |
| providerType? | enum | The provider type for the webhook destination, or an empty string if none are applicable.\nOutgoing webhook events are sent in the format expected by the provider type if non-empty. |
| subscriptions? | array | The list of subscribed events that trigger POST requests to the configured endpoint URL.\nLearn more about [webhook events](/docs/features/webhooks#events). |
| apiKey? | string | Tailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression. |
| oauthClientId? | string | OAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID. |
| oauthClientSecret? | string | OAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression. |
| oauthScopes? | array | Scopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes. |
| tailnet? | string | Tailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use). |
| baseUrl? | string | Tailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com. |
fn create()
Create a webhook
fn get(id: string)
Get a webhook by ID
| Argument | Type | Description |
|---|---|---|
| id | string | The webhook's ID |
fn update()
Update the webhook from the global arguments
fn delete(id?: string)
Delete the webhook
| Argument | Type | Description |
|---|---|---|
| id? | string | The webhook's ID; defaults to the stored webhook |
fn sync()
Refresh the stored webhook from Tailscale
fn list()
List webhooks and write each to state
fn adopt(id: string)
Adopt an existing webhook by ID into managed state
| Argument | Type | Description |
|---|---|---|
| id | string | The ID of the webhook to adopt |
fn test()
Send a test event to the webhook endpoint
fn rotate_secret()
Rotate the webhook's signing secret and store the new secret
Resources
state(infinite)— Webhook state
secret(infinite)— Secrets returned only when the webhook is created (or its secret rotated). Stored in a vault.
04Previous Versions
2026.10.02.1
- Added: tailnet_key, oauth_client, federated_identity, webhook, posture_integration, oauth_app, user_invite, device_invite, service, log_stream, tailnet_settings, contacts, policy_file, dns_configuration, dns_nameservers, dns_preferences, dns_search_paths, dns_split_nameservers, device_tags, device_subnet_routes, device_key, device_authorization, device_posture_attribute, device, user
05Stats
A
100 / 100
Downloads
15
Archive size
69.8 KB
Verified by Swamp
- Has README or module doc2/2earned
- README has a code example1/1earned
- README is substantive1/1earned
- Most symbols documented1/1earned
- No slow types (deprecated)1/1earned
- Dependencies pass trust audit2/2earned
- Has description1/1earned
- Platform support declared (or universal)2/2earned
- License declared1/1earned
- Verified public repository2/2earned
06Platforms
07Labels