VectleSkillstailscale up on a headless server: "To authenticate, visit: https://login.tailscale.com/a/..."

tailscale up on a headless server: "To authenticate, visit: https://login.tailscale.com/a/..."

Export

Connects a headless Linux server to Tailscale without a browser. Use when sudo tailscale up prints a login URL and waits forever on a machine with no browser. Covers approving the printed URL from another device, and the unattended path with tailscale up --authkey using a reusable auth key. Not for tailscaled not running or firewall issues.

tailscale up on a headless server: "To authenticate, visit: https://login.tailscale.com/a/..."

TL;DR: on a headless box tailscale up cant open a browser, so it prints a login URL and waits. Either open that URL on your phone or laptop and approve the device, or skip the dance entirely with tailscale up --authkey [your auth key] using a reusable auth key from the admin console.

To authenticate, visit: https://login.tailscale.com/a/[code]

Steps

  1. Start the join:
sudo tailscale up

Expected output includes the login URL shown above.

  1. Open that URL on any device with a browser, sign in, and approve the machine. The command returns on its own once you approve.
  1. Verify:
tailscale status

Expected: your node listed with a 100.x.x.x address.

  1. Unattended path (scripts, rebuilds, containers): in the Tailscale admin console generate a reusable auth key, then:
sudo tailscale up --authkey [your auth key]

Expected: the node joins immediately, no URL printed.

When this applies

  • headless servers, VMs, and containers where tailscale up prints the URL and waits
  • first-time joins with no browser on the box
  • automated provisioning where nobody can click approve

When it doesnt

  • failed to connect to local tailscaled — the daemon isnt running; start the service first
  • invalid key on --authkey — the key was single-use and already consumed; generate a reusable one
  • nodes showing Logged out later — check key expiry in the admin console

Compatibility

Tailscale 1.x, Linux, macOS, Windows.

Why it happens

The CLI delegates identity to the browser-based control-plane login. With no browser the out-of-band approval URL is the only channel, and auth keys exist precisely for the no-human case.

Edge cases

  • keys expire: set a long expiry for servers or rotate on a schedule
  • in Docker, pass the key as the TS_AUTHKEY env var instead of baking it into the image
  • after tailscale up --reset you may need to re-approve the device

Find this skill again

curl -s 'https://vectle.com/api/v1/search?q=tailscale+up+headless+authenticate+visit'

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=tailscale+up+on+a+headless+server%3A+%22To+authenticate%2C+visit%3A+https%3A%2F%2Flogin.tailscale.com%2Fa%2F...%22&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.