Skip to main content

Tailscale

@swamp/tailscalev2026.10.02.2· 5d agoMODELS
01README

Tailscale tailnet management models

02Release Notes
  • Updated: tailnet_key, oauth_client, federated_identity, webhook, posture_integration, oauth_app, user_invite, device_invite, service, log_stream
03Models25
@swamp/tailscale/contactsv2026.10.02.1contacts.ts

Global Arguments

ArgumentTypeDescription
account?objectThe account contact
support?objectThe support contact
security?objectThe security contact
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Apply the contacts from the global arguments
fn get()
Read the current contacts into state
fn update()
Apply the contacts from the global arguments
fn delete()
Stop managing the contacts; Tailscale keeps the current values
fn sync()
Refresh the contacts from Tailscale
fn resend_verification_email(contactType: enum)
Resend the verification email for a contact
ArgumentTypeDescription
contactTypeenumType of contact.

Resources

state(infinite)— Contacts state
@swamp/tailscale/devicev2026.10.02.1device.ts

Global Arguments

ArgumentTypeDescription
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn get(id: string)
Get a device by ID
ArgumentTypeDescription
idstringThe device's ID
fn delete(id: string)
Delete the device from the tailnet
ArgumentTypeDescription
idstringThe device's ID
fn list()
List devices in the tailnet and write each to state
fn adopt(id: string, expected_name?: string)
Adopt an existing device by ID into managed state
ArgumentTypeDescription
idstringThe ID of the device to adopt
expected_name?stringExpected name, checked before adopting
fn expire(id: string)
Expire the device's node key, forcing it to re-authenticate
ArgumentTypeDescription
idstringThe device's ID
fn set_name(id: string, name: string)
Set the device's machine name
ArgumentTypeDescription
idstringThe device's ID
namestringThe new name for the device.\n\nThis can be provided as either the fully qualified domain name for the device (e.g. "nodename.your-domain.ts.net")\nor just the base name (e.g. "nodename").\n\nIf `name` is unset or provided empty, the device\
fn set_ipv4_address(id: string, ipv4: string)
Set the device's Tailscale IPv4 address
ArgumentTypeDescription
idstringThe device's ID
ipv4stringThe new IPv4 address for the device.

Resources

state(infinite)— Device state
@swamp/tailscale/device-authorizationv2026.10.02.1device_authorization.ts

Global Arguments

ArgumentTypeDescription
deviceIdstringID of the device. Using the device's `nodeId` is preferred, but its numeric `id` value can also be used.
authorized?boolean- If `true`, authorize a new device or re-authorize a previously deauthorized device.\n- If `false`, deauthorize an authorized device.
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Apply the device authorization from the global arguments
fn get()
Read the current device authorization into state
fn update()
Apply the device authorization from the global arguments
fn delete()
Stop managing the device authorization; Tailscale keeps the current values
fn sync()
Refresh the device authorization from Tailscale

Resources

state(infinite)— Device authorization state
@swamp/tailscale/device-invitev2026.10.02.2device_invite.ts

Global Arguments

ArgumentTypeDescription
namestringInstance name for this device invite, used as the unique identifier in the factory pattern
deviceIdstringID of the device. Using the device's `nodeId` is preferred, but its numeric `id` value can also be used.
multiUse?booleanWhether the invite can be accepted more than once.\nWhen set to `true`, it results in an invite that can be accepted up to 1,000 times.
allowExitNode?booleanWhether the invited user can use the device as an exit node when it advertises as one.
email?stringThe email to send the created invite to.\nIf not set, the endpoint generates and returns an invite URL (but doesn't send it out).
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Create a device invite
fn get(id: string)
Get a device invite by ID
ArgumentTypeDescription
idstringThe device invite's ID
fn delete(id?: string)
Delete the device invite
ArgumentTypeDescription
id?stringThe device invite's ID; defaults to the stored device invite
fn sync()
Refresh the stored device invite from Tailscale
fn list()
List device invites and write each to state
fn adopt(id: string)
Adopt an existing device invite by ID into managed state
ArgumentTypeDescription
idstringThe ID of the device invite to adopt
fn resend()
Resend the invitation email

Resources

state(infinite)— Device invite state
@swamp/tailscale/device-keyv2026.10.02.1device_key.ts

Global Arguments

ArgumentTypeDescription
deviceIdstringID of the device. Using the device's `nodeId` is preferred, but its numeric `id` value can also be used.
keyExpiryDisabled?boolean- If `true`, disable the device's key expiry. The original key expiry time is still maintained. Upon re-enabling, the key will expire at that original time.\n- If `false`, enable the device's key expiry. Sets the key to expire at the original expiry time prior to disabling. The key may already have expired. In that case, the device must be re-authenticated.
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Apply the device key from the global arguments
fn get()
Read the current device key into state
fn update()
Apply the device key from the global arguments
fn delete()
Clear the device key
fn sync()
Refresh the device key from Tailscale

Resources

state(infinite)— Device key state
@swamp/tailscale/device-posture-attributev2026.10.02.1device_posture_attribute.ts

Global Arguments

ArgumentTypeDescription
deviceIdstringID of the device. Using the device's `nodeId` is preferred, but its numeric `id` value can also be used.
attributeKeystringThe name of the posture attribute to set.\nThis must be prefixed with `custom`:\n\nKeys have a maximum length of 128 characters including the namespace,\nand can only contain letters, numbers, underscores, and colon.\n\nKeys are case-sensitive. Keys must be unique,\nbut are checked for uniqueness in a case-insensitive manner.\nFor example, `custom:MyAttribute` and `custom:myattribute` cannot both be set within a single tailnet.\n\nAll values for a given key need to be of the same type,\nwhich is
value?unionA value can be either a string, number or boolean.\n\nA string value can have a maximum length of 50 characters,\nand can only contain letters, numbers, underscores, and periods.\n\nA number value is an integer and must be a JSON safe number (up to 2^53 - 1).
expiry?stringAn optional expiry time for a given posture attribute. If set, Tailscale\nwill automatically remove the attribute within a few minutes after the specified\ntime.
comment?stringAn optional comment indicating a reason why an attribute is set,\nwhich will be added to the audit log.
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Apply the device posture attribute from the global arguments
fn get()
Read the current device posture attribute into state
fn update()
Apply the device posture attribute from the global arguments
fn delete()
Delete the device posture attribute
fn sync()
Refresh the device posture attribute from Tailscale

Resources

state(infinite)— Device posture attribute state
@swamp/tailscale/device-subnet-routesv2026.10.02.1device_subnet_routes.ts

Global Arguments

ArgumentTypeDescription
deviceIdstringID of the device. Using the device's `nodeId` is preferred, but its numeric `id` value can also be used.
routes?arrayThe new list of enabled subnet routes.
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Apply the device subnet routes from the global arguments
fn get()
Read the current device subnet routes into state
fn update()
Apply the device subnet routes from the global arguments
fn delete()
Clear the device subnet routes
fn sync()
Refresh the device subnet routes from Tailscale

Resources

state(infinite)— Device subnet routes state
@swamp/tailscale/device-tagsv2026.10.02.1device_tags.ts

Global Arguments

ArgumentTypeDescription
deviceIdstringID of the device. Using the device's `nodeId` is preferred, but its numeric `id` value can also be used.
tags?arrayThe new list of tags for the device.
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Apply the device tags from the global arguments
fn get()
Read the current device tags into state
fn update()
Apply the device tags from the global arguments
fn delete()
Clear the device tags
fn sync()
Refresh the device tags from Tailscale

Resources

state(infinite)— Device tags state
@swamp/tailscale/dns-configurationv2026.10.02.1dns_configuration.ts

Global Arguments

ArgumentTypeDescription
nameservers?arrayGlobal DNS resolvers to use. If `preferences.overrideLocalDNS` is true, these override the local OS configuration; otherwise they are used as fallback resolvers.
splitDNS?recordMap of DNS name suffixes (domains) to lists of resolvers for Split DNS and advanced routing overlays.
searchPaths?arraySearch domain paths to apply.
preferences?object
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Apply the DNS configuration from the global arguments
fn get()
Read the current DNS configuration into state
fn update()
Apply the DNS configuration from the global arguments
fn delete()
Clear the DNS configuration
fn sync()
Refresh the DNS configuration from Tailscale

Resources

state(infinite)— DNS configuration state
@swamp/tailscale/dns-nameserversv2026.10.02.1dns_nameservers.ts

Global Arguments

ArgumentTypeDescription
dns?arrayDNS nameservers.
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Apply the DNS nameservers from the global arguments
fn get()
Read the current DNS nameservers into state
fn update()
Apply the DNS nameservers from the global arguments
fn delete()
Clear the DNS nameservers
fn sync()
Refresh the DNS nameservers from Tailscale

Resources

state(infinite)— DNS nameservers state
@swamp/tailscale/dns-preferencesv2026.10.02.1dns_preferences.ts

Global Arguments

ArgumentTypeDescription
magicDNS?booleanWhether MagicDNS is active for this tailnet.
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Apply the DNS preferences from the global arguments
fn get()
Read the current DNS preferences into state
fn update()
Apply the DNS preferences from the global arguments
fn delete()
Clear the DNS preferences
fn sync()
Refresh the DNS preferences from Tailscale

Resources

state(infinite)— DNS preferences state
@swamp/tailscale/dns-search-pathsv2026.10.02.1dns_search_paths.ts

Global Arguments

ArgumentTypeDescription
searchPaths?arrayThe search domains for the given tailnet.
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Apply the DNS search paths from the global arguments
fn get()
Read the current DNS search paths into state
fn update()
Apply the DNS search paths from the global arguments
fn delete()
Clear the DNS search paths
fn sync()
Refresh the DNS search paths from Tailscale

Resources

state(infinite)— DNS search paths state
@swamp/tailscale/dns-split-nameserversv2026.10.02.1dns_split_nameservers.ts

Global Arguments

ArgumentTypeDescription
domainstringThe split-DNS domain this model manages
nameservers?arrayNameservers that resolve the domain
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Apply the split DNS nameservers from the global arguments
fn get()
Read the current split DNS nameservers into state
fn update()
Apply the split DNS nameservers from the global arguments
fn delete()
Clear the split DNS nameservers
fn sync()
Refresh the split DNS nameservers from Tailscale

Resources

state(infinite)— Split DNS nameservers state
@swamp/tailscale/federated-identityv2026.10.02.2federated_identity.ts

Global Arguments

ArgumentTypeDescription
namestringInstance name for this federated identity, used as the unique identifier in the factory pattern
description?stringA short string specifying the purpose of the key. Can be a maximum of 50 alphanumeric characters. Hyphens and spaces are also allowed.
scopes?arrayA list of scopes to grant to the key. At least one scope is required for OAuth clients and federated identities.\nSee [trust credentials scopes](https://tailscale.com/docs/reference/trust-credentials#scopes) for a list of available scopes.\n\nOnly applies to OAuth clients and federated identities.
tags?arrayA list of tags associated to the trust credential. Auth keys created with this credential must have these exact tags, or tags owned by the credential\
issuer?stringThe issuer of the OIDC identity token used in the token exchange. Must be a valid and publicly reachable https:// URL.\n\nOnly applies to federated identities.
subject?stringThe pattern used when matching against the `sub` claim from an OIDC identity token.\nPatterns can include `*` characters to match against any character.\n\nOnly applies to federated identities.
audience?stringThe value used when matching against the `aud` claim from an OIDC identity token.\n\nSpecifying the audience is optional as Tailscale will generate a secure audience at creation time by default.\nIt is recommended to let Tailscale generate the audience unless the identity provider you are integrating with\nrequires a specific audience format.\n\nOnly applies to federated identities.
customClaimRules?recordA map of claim names to pattern strings used to match against arbitrary claims in the OIDC identity token.\nPatterns can include `*` characters to match against any character.\n\nOnly applies to federated identities.
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Create a federated identity
fn get(id: string)
Get a federated identity by ID
ArgumentTypeDescription
idstringThe federated identity's ID
fn update()
Update the federated identity from the global arguments
fn delete(id?: string)
Delete the federated identity
ArgumentTypeDescription
id?stringThe federated identity's ID; defaults to the stored federated identity
fn sync()
Refresh the stored federated identity from Tailscale
fn list()
List federated identitys and write each to state
fn adopt(id: string)
Adopt an existing federated identity by ID into managed state
ArgumentTypeDescription
idstringThe ID of the federated identity to adopt

Resources

state(infinite)— Federated identity state
@swamp/tailscale/log-streamv2026.10.02.2log_stream.ts

Global Arguments

ArgumentTypeDescription
destinationType?enumThe type of system to which logs are being streamed.
url?stringThe URL to which log streams are being posted. If the DestinationType is `s3`, the URL may be (and often is) empty to use the official Amazon S3 endpoint.
user?stringThe username with which log streams to this endpoint are authenticated.
uploadPeriodMinutes?numberAn optional number of minutes to wait in between uploading new logs. If the quantity of logs does not fit within a single upload, multiple uploads will be made.
compressionFormat?enumThe compression algorithm with which to compress logs. `none` disables compression. Defaults to `none`.
token?stringThe token/password with which log streams to this endpoint should be authenticated.
s3Bucket?stringThe S3 bucket name. Required if the destinationType is `s3`.
s3Region?stringThe region in which the S3 bucket is located. Required if the destinationType is `s3`.
s3KeyPrefix?stringAn optional S3 key prefix to prepend to the auto-generated S3 key name.
s3AuthenticationType?enumWhat type of authentication to use for S3. Required if the destinationType is `s3`. Tailscale recommends using `rolearn`. See [Amazon documentation](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_common-scenarios_third-party.html).
s3AccessKeyId?stringThe S3 access key ID. Required if the destinationType is `s3` and `authenticationType` is `accesskey`.
s3SecretAccessKey?stringThe S3 secret access key. Required if the destinationType is `s3` and `authenticationType` is `accesskey`.
s3RoleArn?stringThe Role ARN that Tailscale should supply to AWS when authenticating using role-based authentication. Required if the destinationType is `s3` and `authenticationType` is `rolearn`.
gcsBucket?stringThe GCS bucket name. Required if the destinationType is `gcs`.
gcsKeyPrefix?stringAn optional GCS key prefix to append to the GCS bucket name.
gcsScopes?arrayThe GCS scopes needed to be able to write to the GCS bucket.
gcsCredentials?stringThe JSON workload identity credentials from GCS needed for accessing the GCS account.
logTypeenumThe type of log.
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Create the log stream; fails if one already exists for logType
fn get()
Get the log stream for logType and write it to state
fn update()
Update the log stream from the global arguments
fn delete()
Delete the log stream
fn sync()
Refresh the log stream from Tailscale

Resources

state(infinite)— Log stream state
@swamp/tailscale/oauth-appv2026.10.02.2oauth_app.ts

Global Arguments

ArgumentTypeDescription
instanceNamestringInstance name for this OAuth app, used as the unique identifier in the factory pattern
name?stringThe name of the OAuth app.\nMust be between 3 and 50 characters and contain only alphanumeric characters, dashes, periods, and underscores.
description?stringA human-readable description of the OAuth app.\nMust be at most 300 characters.
redirectURIs?arrayThe list of permitted redirect URIs for the OAuth authorization code flow.\nAt least one redirect URI is required.\n\nEach URI must use the `https` scheme, except for `localhost`, `127.0.0.1`, and `::1`,\nwhich may use any scheme. Raw IP address hosts are not permitted.
scopes?arrayThe list of OAuth scopes granted to the app.\nMust be non-empty.\nLearn more about [OAuth clients and scopes](/docs/features/oauth-clients).
allowedNodeAttributes?arrayThe list of custom device attributes that the OAuth app is allowed to set.
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Create an OAuth app
fn get(id: string)
Get an OAuth app by ID
ArgumentTypeDescription
idstringThe OAuth app's ID
fn update()
Update the OAuth app from the global arguments
fn delete(id?: string)
Delete the OAuth app
ArgumentTypeDescription
id?stringThe OAuth app's ID; defaults to the stored OAuth app
fn sync()
Refresh the stored OAuth app from Tailscale
fn list()
List OAuth apps and write each to state
fn lookup()
Find an existing OAuth app by name and write it to state
fn adopt(id: string, expected_name?: string)
Adopt an existing OAuth app by ID into managed state
ArgumentTypeDescription
idstringThe ID of the OAuth app to adopt
expected_name?stringExpected name, checked before adopting

Resources

state(infinite)— OAuth app state
secret(infinite)— Secrets returned only when the OAuth app is created (or its secret rotated). Stored in a vault.
@swamp/tailscale/oauth-clientv2026.10.02.2oauth_client.ts

Global Arguments

ArgumentTypeDescription
namestringInstance name for this OAuth client, used as the unique identifier in the factory pattern
description?stringA short string specifying the purpose of the key. Can be a maximum of 50 alphanumeric characters. Hyphens and spaces are also allowed.
scopes?arrayA list of scopes to grant to the key. At least one scope is required for OAuth clients and federated identities.\nSee [trust credentials scopes](https://tailscale.com/docs/reference/trust-credentials#scopes) for a list of available scopes.\n\nOnly applies to OAuth clients and federated identities.
tags?arrayA list of tags associated to the trust credential. Auth keys created with this credential must have these exact tags, or tags owned by the credential\
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Create an OAuth client
fn get(id: string)
Get an OAuth client by ID
ArgumentTypeDescription
idstringThe OAuth client's ID
fn update()
Update the OAuth client from the global arguments
fn delete(id?: string)
Delete the OAuth client
ArgumentTypeDescription
id?stringThe OAuth client's ID; defaults to the stored OAuth client
fn sync()
Refresh the stored OAuth client from Tailscale
fn list()
List OAuth clients and write each to state
fn adopt(id: string)
Adopt an existing OAuth client by ID into managed state
ArgumentTypeDescription
idstringThe ID of the OAuth client to adopt

Resources

state(infinite)— OAuth client state
secret(infinite)— Secrets returned only when the OAuth client is created (or its secret rotated). Stored in a vault.
@swamp/tailscale/policy-filev2026.10.02.1policy_file.ts

Global Arguments

ArgumentTypeDescription
policy?stringThe policy file as HuJSON (JSON with comments and trailing commas)
overwriteExistingContent?booleanLet create replace a policy file that has been edited since the tailnet was created
resetOnDelete?booleanReset the policy file to the default when the model is deleted
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Replace the policy file; refuses to overwrite an edited policy unless overwriteExistingContent is set
fn get()
Read the current policy file into state
fn update()
Replace the policy file; refuses if it changed since the last get or sync
fn delete()
Stop managing the policy file; resets it to the default only when resetOnDelete is set
fn sync()
Refresh the policy file from Tailscale
fn preview(type?: enum, previewFor?: string)
Preview which rules in the policy match a user or an IP:port
ArgumentTypeDescription
type?enumSpecify for which type of resource (user or IP port) matching rules are to be fetched.\nRead about [previewing changes in the admin console](https://tailscale.com/docs/features/tailnet-policy-file/manage-tailnet-policies#preview-changes).\n\nOAuth Scope: `policy_file:read`.
previewFor?string- If `type` is `user`, provide the email of a valid user with registered machines.\n- If `type` is `ipport`, provide an IP address + port: `10.0.0.1:80`.\n\nThe supplied policy file is queried with this parameter to determine which rules match.
fn validate()
Validate the policy and run its tests without saving it

Resources

state(infinite)— Policy file state
result(infinite)— The response of the most recent run of each action that returns data
@swamp/tailscale/posture-integrationv2026.10.02.2posture_integration.ts

Global Arguments

ArgumentTypeDescription
namestringInstance name for this posture integration, used as the unique identifier in the factory pattern
provider?enumThe device posture provider.\n\nRequired on POST requests, ignored on PATCH requests.
cloudId?stringIdentifies which of the provider's clouds to integrate with.\n\n- For CrowdStrike Falcon, it will be one of `us-1`, `us-2`, `eu-1` or `us-gov`.\n- For Microsoft Intune, it will be one of `global` or `us-gov`. \n- For Jamf Pro, Kandji and Sentinel One, it is the FQDN of your subdomain, for example `mydomain.sentinelone.net`.\n- For Kolide, this is left blank.
clientId?stringUnique identifier for your client.\n\n- For Microsoft Intune, it will be your application's UUID.\n- For CrowdStrike Falcon and Jamf Pro, it will be your client id.\n- For Kandji, Kolide and Sentinel One, this is left blank.
tenantId?stringThe Microsoft Intune directory (tenant) ID. For other providers, this is left blank.
clientSecret?stringThe secret (auth key, token, etc.) used to authenticate with the provider.\n\nRequired when creating a new integration, may be omitted when updating an existing integration, in which case we retain the existing password.
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Create a posture integration
fn get(id: string)
Get a posture integration by ID
ArgumentTypeDescription
idstringThe posture integration's ID
fn update()
Update the posture integration from the global arguments
fn delete(id?: string)
Delete the posture integration
ArgumentTypeDescription
id?stringThe posture integration's ID; defaults to the stored posture integration
fn sync()
Refresh the stored posture integration from Tailscale
fn list()
List posture integrations and write each to state
fn adopt(id: string)
Adopt an existing posture integration by ID into managed state
ArgumentTypeDescription
idstringThe ID of the posture integration to adopt

Resources

state(infinite)— Posture integration state
@swamp/tailscale/servicev2026.10.02.2service.ts

Global Arguments

ArgumentTypeDescription
addrs?arrayThe IP addresses assigned to the Service: the IPv4 followed by the IPv6.
namestringThe unique name of the Service.
displayName?stringAn optional human-readable label for the Service, shown in the Tailscale admin console\nand to clients with access to the Service.\nMust be 64 characters or fewer.
comment?stringAn optional comment for the Service.
ports?arrayA list of protocol:port pairs to be exposed by the Service.\n\nThe only supported protocol is "tcp" at this time. "do-not-validate" can be used to skip validation.
tags?arrayA list of optional tags associated with the Service.
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Create the service; fails if one already exists for name
fn get()
Get the service for name and write it to state
fn update()
Update the service from the global arguments
fn delete()
Delete the service
fn sync()
Refresh the service from Tailscale
fn list()
List services and write each to state
fn list_devices()
List the devices hosting the service
fn get_device_approval(deviceId: string)
Get whether a device is approved to host the service
ArgumentTypeDescription
deviceIdstringID of the device. Using the device's `nodeId` is preferred, but its numeric `id` value can also be used.
fn set_device_approval(deviceId: string, approved?: boolean)
Approve or unapprove a device to host the service
ArgumentTypeDescription
deviceIdstringID of the device. Using the device's `nodeId` is preferred, but its numeric `id` value can also be used.
approved?booleanIndicates whether to approve or revoke approval for the Service on the device.

Resources

state(infinite)— Service state
result(infinite)— The response of the most recent run of each action that returns data
@swamp/tailscale/tailnet-keyv2026.10.02.2tailnet_key.ts

Global Arguments

ArgumentTypeDescription
namestringInstance name for this auth key, used as the unique identifier in the factory pattern
description?stringA short string specifying the purpose of the key. Can be a maximum of 50 alphanumeric characters. Hyphens and spaces are also allowed.
capabilities?object`capabilities` is a mapping of resources to permissible actions.
expirySeconds?numberSpecifies the duration in seconds until the key expires. Defaults to 90 days if not supplied.\n\nOnly applies to auth keys.
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Create an auth key
fn get(id: string)
Get an auth key by ID
ArgumentTypeDescription
idstringThe auth key's ID
fn delete(id?: string)
Delete the auth key
ArgumentTypeDescription
id?stringThe auth key's ID; defaults to the stored auth key
fn sync()
Refresh the stored auth key from Tailscale
fn list()
List auth keys and write each to state
fn adopt(id: string)
Adopt an existing auth key by ID into managed state
ArgumentTypeDescription
idstringThe ID of the auth key to adopt

Resources

state(infinite)— Auth key state
secret(infinite)— Secrets returned only when the auth key is created (or its secret rotated). Stored in a vault.
@swamp/tailscale/tailnet-settingsv2026.10.02.1tailnet_settings.ts

Global Arguments

ArgumentTypeDescription
aclsExternallyManagedOn?booleanPrevents users from editing policies in the admin console to avoid conflicts with external management workflows like GitOps or Terraform.
aclsExternalLink?stringLink to the external tailnet policy definition or management solution for this tailnet.
devicesApprovalOn?booleanWhether [device approval](/docs/features/access-control/device-management/device-approval) is enabled for the tailnet.
devicesAutoUpdatesOn?booleanWhether [auto updates](/docs/features/client/update#auto-updates) are enabled for devices that belong to this tailnet.
devicesKeyDurationDays?numberThe [key expiry](/docs/features/access-control/key-expiry) duration for devices on this tailnet.
usersApprovalOn?booleanWhether [user approval](/docs/features/access-control/user-approval) is enabled for this tailnet.
usersRoleAllowedToJoinExternalTailnets?enumWhich user roles are allowed to [join external tailnets](/docs/features/sharing/how-to/invite-any-user).
networkFlowLoggingOn?booleanWhether [network flog logs](/docs/features/logging/network-flow-logs) are enabled for the tailnet.
regionalRoutingOn?booleanWhether [regional routing](/docs/how-to/set-up-high-availability#regional-routing) is enabled for the tailnet.
postureIdentityCollectionOn?booleanWhether [identity collection](/docs/features/access-control/device-management/how-to/manage-identity) is enabled for [device posture](/docs/features/device-posture) integrations for the tailnet.
httpsEnabled?booleanWhether provisioning of [HTTPS certificates](/docs/how-to/set-up-https-certificates) is enabled for this tailnet.
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Apply the tailnet settings from the global arguments
fn get()
Read the current tailnet settings into state
fn update()
Apply the tailnet settings from the global arguments
fn delete()
Stop managing the tailnet settings; Tailscale keeps the current values
fn sync()
Refresh the tailnet settings from Tailscale

Resources

state(infinite)— Tailnet settings state
@swamp/tailscale/userv2026.10.02.1user.ts

Global Arguments

ArgumentTypeDescription
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn get(id: string)
Get an user by ID
ArgumentTypeDescription
idstringThe user's ID
fn delete(id: string)
Delete the user from the tailnet
ArgumentTypeDescription
idstringThe user's ID
fn list()
List users in the tailnet and write each to state
fn adopt(id: string, expected_name?: string)
Adopt an existing user by ID into managed state
ArgumentTypeDescription
idstringThe ID of the user to adopt
expected_name?stringExpected loginName, checked before adopting
fn set_role(id: string, role?: enum)
Change the user's role
ArgumentTypeDescription
idstringThe user's ID
role?enumThe role of the user. Learn more about [user roles](/docs/reference/user-roles).
fn approve(id: string)
Approve a user waiting for approval
ArgumentTypeDescription
idstringThe user's ID
fn suspend(id: string)
Suspend the user
ArgumentTypeDescription
idstringThe user's ID
fn restore(id: string)
Restore a suspended user
ArgumentTypeDescription
idstringThe user's ID

Resources

state(infinite)— User state
@swamp/tailscale/user-invitev2026.10.02.2user_invite.ts

Global Arguments

ArgumentTypeDescription
namestringInstance name for this user invite, used as the unique identifier in the factory pattern
role?enumOptionally specifies a user role to assign the invited user.
email?stringOptionally specifies the email to send the created invite.\nIf not set, the endpoint generates and returns an invite URL, but does not email it out.
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Create an user invite
fn get(id: string)
Get an user invite by ID
ArgumentTypeDescription
idstringThe user invite's ID
fn delete(id?: string)
Delete the user invite
ArgumentTypeDescription
id?stringThe user invite's ID; defaults to the stored user invite
fn sync()
Refresh the stored user invite from Tailscale
fn list()
List user invites and write each to state
fn adopt(id: string)
Adopt an existing user invite by ID into managed state
ArgumentTypeDescription
idstringThe ID of the user invite to adopt
fn resend()
Resend the invitation email

Resources

state(infinite)— User invite state
@swamp/tailscale/webhookv2026.10.02.2webhook.ts

Global Arguments

ArgumentTypeDescription
namestringInstance name for this webhook, used as the unique identifier in the factory pattern
endpointUrl?stringThe endpoint that events are sent to from Tailscale via POST requests.
providerType?enumThe provider type for the webhook destination, or an empty string if none are applicable.\nOutgoing webhook events are sent in the format expected by the provider type if non-empty.
subscriptions?arrayThe list of subscribed events that trigger POST requests to the configured endpoint URL.\nLearn more about [webhook events](/docs/features/webhooks#events).
apiKey?stringTailscale API access token. Overrides the TAILSCALE_API_KEY environment variable. Wire with a vault.get(...) expression.
oauthClientId?stringOAuth client ID, used with oauthClientSecret instead of an API key. Overrides TAILSCALE_OAUTH_CLIENT_ID.
oauthClientSecret?stringOAuth client secret. Overrides TAILSCALE_OAUTH_CLIENT_SECRET. Wire with a vault.get(...) expression.
oauthScopes?arrayScopes to request when exchanging the OAuth client credentials; defaults to all of the client's scopes.
tailnet?stringTailnet ID. Defaults to TAILSCALE_TAILNET, then '-' (the tailnet of the credential in use).
baseUrl?stringTailscale API base URL. Defaults to TAILSCALE_BASE_URL, then https://api.tailscale.com.
fn create()
Create a webhook
fn get(id: string)
Get a webhook by ID
ArgumentTypeDescription
idstringThe webhook's ID
fn update()
Update the webhook from the global arguments
fn delete(id?: string)
Delete the webhook
ArgumentTypeDescription
id?stringThe webhook's ID; defaults to the stored webhook
fn sync()
Refresh the stored webhook from Tailscale
fn list()
List webhooks and write each to state
fn adopt(id: string)
Adopt an existing webhook by ID into managed state
ArgumentTypeDescription
idstringThe ID of the webhook to adopt
fn test()
Send a test event to the webhook endpoint
fn rotate_secret()
Rotate the webhook's signing secret and store the new secret

Resources

state(infinite)— Webhook state
secret(infinite)— Secrets returned only when the webhook is created (or its secret rotated). Stored in a vault.
04Previous Versions1
2026.10.02.1
  • Added: tailnet_key, oauth_client, federated_identity, webhook, posture_integration, oauth_app, user_invite, device_invite, service, log_stream, tailnet_settings, contacts, policy_file, dns_configuration, dns_nameservers, dns_preferences, dns_search_paths, dns_split_nameservers, device_tags, device_subnet_routes, device_key, device_authorization, device_posture_attribute, device, user
05Stats
A
100 / 100
Downloads
15
Archive size
69.8 KB
Verified by Swamp
  • Has README or module doc2/2earned
  • README has a code example1/1earned
  • README is substantive1/1earned
  • Most symbols documented1/1earned
  • No slow types (deprecated)1/1earned
  • Dependencies pass trust audit2/2earned
  • Has description1/1earned
  • Platform support declared (or universal)2/2earned
  • License declared1/1earned
  • Verified public repository2/2earned
06Platforms
07Labels