tailscale up on a headless server: "To authenticate, visit: https://login.tailscale.com/a/..."
Connects a headless Linux server to Tailscale without a browser. Use when sudo tailscale up prints a login URL and waits forever on a machine with no browser. Covers approving the printed URL from another device, and the unattended path with tailscale up --authkey using a reusable auth key. Not for tailscaled not running or firewall issues.
tailscale up on a headless server: "To authenticate, visit: https://login.tailscale.com/a/..."
TL;DR: on a headless box tailscale up cant open a browser, so it prints a login URL and waits. Either open that URL on your phone or laptop and approve the device, or skip the dance entirely with tailscale up --authkey [your auth key] using a reusable auth key from the admin console.
To authenticate, visit: https://login.tailscale.com/a/[code]Steps
- Start the join:
sudo tailscale upExpected output includes the login URL shown above.
- Open that URL on any device with a browser, sign in, and approve the machine. The command returns on its own once you approve.
- Verify:
tailscale statusExpected: your node listed with a 100.x.x.x address.
- Unattended path (scripts, rebuilds, containers): in the Tailscale admin console generate a reusable auth key, then:
sudo tailscale up --authkey [your auth key]Expected: the node joins immediately, no URL printed.
When this applies
- headless servers, VMs, and containers where
tailscale upprints the URL and waits - first-time joins with no browser on the box
- automated provisioning where nobody can click approve
When it doesnt
failed to connect to local tailscaled— the daemon isnt running; start the service firstinvalid keyon --authkey — the key was single-use and already consumed; generate a reusable one- nodes showing Logged out later — check key expiry in the admin console
Compatibility
Tailscale 1.x, Linux, macOS, Windows.
Why it happens
The CLI delegates identity to the browser-based control-plane login. With no browser the out-of-band approval URL is the only channel, and auth keys exist precisely for the no-human case.
Edge cases
- keys expire: set a long expiry for servers or rotate on a schedule
- in Docker, pass the key as the TS_AUTHKEY env var instead of baking it into the image
- after
tailscale up --resetyou may need to re-approve the device
Find this skill again
curl -s 'https://vectle.com/api/v1/search?q=tailscale+up+headless+authenticate+visit'Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.