mrkeyoor.com_
Fri 02 Oct 17:16 UTC
Dev Toolsevaluationupdated 02 Oct 2026

tailcat review

Tailcat connects two machines through an encrypted Tailscale data path without requiring a Tailscale account or control plane. You exchange a one-time address out of band, then use it to pipe data, forward ports, open an SSH session, transfer files, or reach services on the other machine.

Verdict

Our tailcat run built successfully but only 10 of 15 test outcomes passed, so the project is useful for supervised one-off tunnels rather than a clean production gate today. Use it when two people can exchange a secret address privately and need ports, files, or SSH without enrolling devices in a control plane. Choose a managed mesh for persistent access, policy, and service guarantees.

We ran it

Lab card: what happened when we ran tailcatScreenshot of tailcat (tailscale.com/tailcat)
Install✓ · 69s675 packages
Build✓ · 181s
Tests✗ · 87s10 passed · 5 failed of 15 (go test)
Repo101 files~19,818 lines of source · 0.7 MB · 5 CI workflows

Answers from our run

Does tailcat build from source?

Dependencies installed in 69 seconds (675 packages), and the build succeeded in 181 seconds. We cloned commit b4dc28e into a clean Debian container with 3 CPUs and no project-specific setup.

Do tailcat's tests pass?

Not all of them: 10 of 15 passed and 5 failed when we ran the project's own test command (go test). Some failures need services or credentials a bare container does not have.

Who should not use tailcat?

Teams that require a clean test gate: our run reported 10 passed and 5 failed, including SSH, receive drop-box, and copy round-trip cases.

What are the alternatives to tailcat?

Tailscale, Magic Wormhole, croc. Our tailcat run built successfully but only 10 of 15 test outcomes passed, so the project is useful for supervised one-off tunnels rather than a clean production gate today.

Setup4/5Many install paths, no account or root, but addresses need care
Docs5/5Commands, key handling, security, relays, and limits are explicit
Community4/57,990 stars and active issues after a September release
Maturity2/5Five test failures and no stability or relay SLA promises

Who it’s for

Developers who need an encrypted one-off tunnel without changing routes or creating a Tailscale account.
Support engineers moving a file or exposing a temporary local port to one known peer.
Go developers who want Tailscale's userspace networking pieces as an embeddable library.
Self-hosters willing to run their own DERP relay when public relay limits or availability are unacceptable.

Who it’s NOT for

Teams that require a clean test gate: our run reported 10 passed and 5 failed, including SSH, receive drop-box, and copy round-trip cases.
Organizations seeking a stable managed network: the README promises no API, CLI, or wire-format stability, and the public DERP relays have no uptime or throughput target.
Anyone likely to paste connection addresses into logs or public chat: a default tailcat address contains the pre-shared key and acts as a bearer credential.
Browser users who need direct peer connections: the WebAssembly demo stays on DERP until WebRTC support tracked in issue 4 exists.
Mosh or other UDP-forwarding users relying on the CLI: issue 122 says UDP exists in the library and exit-node path but is missing from serve and forward.

Setup reality

Our fresh Debian sandbox installed commit b4dc28e in 69 seconds, resolving 675 Go packages. The build succeeded in 181 seconds. Tests failed after 87 seconds: 10 passed and 5 failed out of 15.

Using the default service needs no Tailscale account, root access, or secret stored in an environment variable. It does need both peers to exchange a tailcat address privately and reach a DERP relay. You can use the free rate-limited relays or operate your own.

Prebuilt packages cover major desktop systems, while source builds need Go 1.24. The browser build is experimental and relay-only. Public DNS names and saved addresses require separate client authentication because the address itself normally grants access.

A secret address replaces the account and control plane

Tailcat takes Tailscale's encrypted data path and removes device enrollment. One machine starts a listener and prints a tailcat address. The other receives that string through some private channel and connects. Both peers begin through a DERP relay, then try to establish a direct UDP path. If hole punching fails, traffic can remain on the relay. No Tailscale account, administrator access, route change, or DNS change is required.

That address carries the server's WireGuard public key, a separate path-discovery key, DERP information, and by default a 256-bit pre-shared key. It is therefore a bearer credential, not a harmless hostname. An ephemeral server discards its key when it exits, which makes the address good for one run. A saved key creates a stable address, but everyone who received it can try future servers using that key unless you add --allow.

One binary covers pipes, ports, SSH, files, and tests

The simplest mode behaves like netcat: stdin on one machine becomes stdout on the other. The same CLI can expose or forward TCP ports, open a browser through a local forward, proxy through SOCKS5, run an SSH service, execute a fixed command per connection, and offer an exit node. It can also report whether traffic is direct or passing through DERP. That is a wide toolbox for an executable with no system routing changes.

File handling is more considered than a raw socket copy. recv creates a write-only drop box, while serve files offers a directory over SFTP in read-only or read-write mode. Paths stay inside the selected directory through Go's os.Root. Transfers are not compressed, so a large compressible folder should be packed first. tailcat cp also depends on the system scp, while tailcat ls speaks SFTP itself.

What happened when we ran it

Our sandbox installed commit b4dc28e in 69 seconds and resolved 675 Go packages. The build then succeeded in 181 seconds. We used an unprivileged Debian container with 3 CPUs, 8 GB of RAM, Go 1.24, and no secrets. The checkout held 101 files, about 19,818 lines of source, and occupied 0.7 MB before installation.

The tests failed after 87 seconds. The supplied result counted 10 passed and 5 failed out of 15. Its final lines named TestServeSSHExec, TestServeNoAuthSSHExec, TestRecvDropBox, and TestCPRoundTrip, then marked github.com/tailscale/tailcat/cmd/tailcat as failed after 51.336 seconds. The log tail did not name the fifth failed outcome or show causes, so attributing the failures to networking, missing tools, or the sandbox would be guesswork.

Other packages did finish cleanly in that same log. internal/buildtags, internal/localhostdns, internal/perf, web, and webdemo each reported ok. The repository scan found 5 CI workflow files, no Dockerfile, and no dedicated tests directory. Those signals do not cancel the failed command. They show that most of the reported trouble was concentrated in the CLI package during our run.

Public DNS turns the address into public information

Tailcat can resolve an address from a DNS TXT record, but DNS is world-readable. Publishing the address removes possession as an authentication test. The README tells operators to restrict the tunnel with known client keys or require SSH public keys, and it warns never to publish a no-auth-ssh address. Version 0.7.0 added a probe that refuses a DNS-named SSH destination if a stranger can obtain a shell, unless the user bypasses the check.

The unauthenticated SSH mode deserves the blunt warning. Anyone holding its tailcat address gets a shell as the user running the server. For a private, single-use support session that may be an acceptable trade. For a saved address, ticket attachment, CI log, or DNS record, it is dangerous. Public-key SSH and tunnel-level allowlists exist for the cases where the endpoint must outlive one private exchange.

Browser traffic remains relayed, and CLI UDP forwarding is absent

The experimental WebAssembly demo can exchange files or text with the CLI, but browser traffic stays on DERP. Issue 4 tracks WebRTC support for direct browser connections. Public tailcat DERP relays are rate-limited, so that distinction affects more than network elegance. A browser transfer cannot currently upgrade to the direct path that desktop peers usually attempt.

UDP support is uneven. Version 0.7.0 added UDP forwarding for exit-node servers, and the Go library exposes UDP pieces. Open issue 122 says the ordinary serve and forward commands still lack the UDP route needed by tools such as mosh. If your workload is DNS or QUIC through an exit node, the release covers it. If it is a locally forwarded UDP port, the requested CLI interface is still open.

Version 0.7.0 is active, but stability is explicitly best effort

GitHub showed 7,990 stars and 25 open issues and pull requests on October 2, 2026, split into 14 issues and 11 pull requests. The last push was September 29, nine days after v0.7.0 was published. That release added UDP exit-node flows, Windows loopback fixes, older OpenSSH compatibility, browser forwarding, fixed-command services, Android work, and the DNS SSH safety probe.

The project still promises no stability for its Go API, CLI flags, output, or wire format. Its free public relays have no uptime agreement or throughput target and may be withdrawn. You can run a DERP relay yourself, which removes dependence on the shared service but makes availability your job. Tailcat is a sharp tool for temporary, supervised access. Our 5 failed test outcomes are the reason to validate the exact command you plan to trust before handing it a shell or deployment path.

Alternatives

ProjectWhat it isPick it when
Tailscale gh↗A managed WireGuard mesh with device identity, policy, DNS, and persistent networks.pick this instead when the connection should persist and central device management is useful.
Magic WormholeA command-line tool for sending files and directories with short human-readable codes.pick this instead when you only need a simple file handoff rather than ports, SSH, or a Go networking library.
croc gh↗A relay-assisted encrypted file-transfer tool built around a shared code.pick this instead when cross-platform file transfer is the whole job and tunnel services would be extra machinery.

What people are saying

  1. [github-trending] tailscale/tailcat

Sources

  1. Tailcat repository and README
  2. Tailcat installation guide
  3. Tailcat v0.7.0 release
  4. WebRTC support issue
  5. Tailcat address secrecy discussion
  6. CLI UDP forwarding issue

More dev tools reviews

touchHLE · effect · SwitchHosts · Duo-animation · DuoLikeAnimation · team-Omzo · the whole board →