Tailscale dey free? See wetin each plan cover
Tailscale Personal plan free for up to 6 users with unlimited user devices. See wetin seat, device and tagged resource mean, plus when Headscale better.
Tailscale dey free? Yes, for Personal plan
Tailscale dey free for Personal plan. The free tier no get expiry date, and e include most of the product. E limit how many people fit join your network, no be how many machines you fit connect. As dem check am on 17 August 2026, Tailscale pricing page give Personal six users, unlimited user devices, 50 tagged resources, and access to nearly every feature.
Make we explain two words first. A tailnet na your private network: one account, one user list, and one policy file. A seat na one person inside that tailnet. Tailscale dey bill per seat, so na people dem dey count. This one fact decide whether your setup go free.
Every figure below na published number with the date wey dem check am. Prices and allowances fit change, so confirm dem for the pricing page before you plan budget around dem. The structure dey change much slower, and na the structure dey useful: dem dey count people and tagged infrastructure, while the paid tiers dey sell capabilities instead of bigger device allowance. WireGuard, wey na the tunnel protocol underneath, dey the same for every plan, and wetin Tailscale add on top plain WireGuard explain that split.
Wetín count as user, and wetín count as device
Every machine for a tailnet get owner. If you log in with your own identity, na you own the machine. Tailscale call am user device, and the pricing FAQ talk am clear: "User devices are free and unlimited." Your laptop, phone, desktop, and tablet together na one seat, no be four.
If you register machine with tag instead, na the tag own am. Tailscale call am tagged resource, and na tagged resources the plan dey count. Servers and routers suppose get tags, because shared machine no suppose belong to whoever run the login command for am. As of 17 August 2026, Personal plan get 50 tagged resources. The pricing page list extra ones as 1 US dollar per month each, and you fit buy dem self-serve. VPS wey dey do work for everybody belong for this category, whether na subnet router wey dey advertise private range or exit node wey dey carry outbound traffic.
Tag server as e dey join, because if you change ownership later, you go need authenticate the node again:
curl -fsSL https://tailscale.com/install.sh | sh
sudo tailscale up --advertise-tags=tag:servertailscale statustailscale status list the node together with the owner wey register am. The tag must already dey inside your tailnet policy file under tagOwners, because tag na ownership grant, and node no fit claim tag wey nobody grant. If tag no dey inside the policy, command go fail and node no go join.
Na why free plan dey surprise people for both sides. Homelab wey get thirty machines and all of dem sign in as you na one seat, and e free. Four-person team wey everybody sign in na four seats out of six, and e still free. Twelve people no be free again, no matter how many devices dem get, because the limit dey count people.
Ephemeral resources na the third category. Node wey register with ephemeral auth key, like continuous integration runner or Kubernetes pod, go delete itself when e stop. E dey use monthly pool of minutes instead of holding resource slot. Personal get 1,000 of those minutes every month on 17 August 2026, while Premium get 10,000. If node stay up pass four hours, e stop counting as ephemeral and become normal tagged resource.
One more billing detail: invited user no occupy seat until e use the tailnet. The pricing FAQ talk say user "does not occupy a seat until they first log in to the admin console or when they first authenticate a device". You fit send invitations early without paying for people wey never show.
Wetin paid plans cost
The data behind this chart
[
{
"plan": "Personal",
"usd_per_user_month": 0
},
{
"plan": "Standard",
"usd_per_user_month": 8
},
{
"plan": "Premium",
"usd_per_user_month": 18
}
]Personal free. Standard na 8 US dollars for each user every month, while Premium na 18, as dem publish am on 17 August 2026. Sales team go give Enterprise price based on custom number of users and limits. Standard and Premium remove user cap, so for most teams, na when seventh person join dem go start pay, no be when dem reach fortieth server.
Wetin dey behind paid tier
These na capability gates. Adding more machines no go move you enter higher tier. Writing access policy wey more complex fit do am.
Access control lists (ACLs), wey be rules wey decide which user fit reach which machine, show this well. The policy file dey for every plan. But the number of groups wey you fit define inside am no dey.
The data behind this chart
[
{
"plan": "Personal",
"acl_groups": 3
},
{
"plan": "Standard",
"acl_groups": 10
},
{
"plan": "Premium",
"acl_groups": 300
}
]Personal allow 3 groups, Standard 10, and Premium 300. Group na named set of users, so this really mean say na the limit on how finely you fit divide people. Three groups fit cover "me", "family" and "guests". E no fit cover company wey get departments.
The other gates wey dey listed for the same page and checked the same day be these:
- Bringing your own identity provider (IdP), meaning single sign-on (SSO) with any provider wey you already run, starts for Standard. Personal dey sign you in with the consumer identity providers wey Tailscale support directly.
- Network flow logs, device approval and device posture checks start for Standard.
- Advanced user roles start for Premium. Advanced Tailscale SSH start there too. Basic Tailscale SSH for Personal get limit of 5 hosts.
SSH session recording na the case wey worth careful reading, because e prove say dem set these gates per feature, no be by tier order. Tailscale session recording documentation list the feature for Personal and Enterprise plans, while the pricing page group am under separately purchased Privileged Access Management extension. E also need recorder node wey you run and store the recordings on. Check the current page before you build compliance requirement on top of am.
Why free tailnet dey talk say "Reached use limit"
Admin console dey show "Reached use limit" when tailnet reach plan limit. For Personal plan, the common cause na the seventh person, because plan dey count people. Another possible cause na tagged resources wey pass the allowance wey plan include. None of these dey depend on how many laptops and phones connect, so counting devices when you see this message na wasted time. Open admin console and count human accounts first, then tagged machines.
Custom DERP relay use you need paid plan?
DERP (Designated Encrypted Relay for Packets) na Tailscale relay network. When two nodes no fit open direct connection through NAT (network address translation), dem encrypted traffic go DERP server as fallback. To run your own DERP relay, you configure am inside the tailnet policy file. As of 17 August 2026, Tailscale documentation for custom DERP servers no list any plan restriction.
Custom relay dey change specific things, so make you no confuse relaying with self-hosting. A custom DERP server dey move fallback data path go machine wey you own. The control path no dey move. Tailscale coordination server still dey keep your node keys, your policy file, and your user list. E never dey keep private keys wey dey decrypt your traffic. So wetin attacker actually gain if dem take over that coordination server na narrower question than e first sound. If you want that part for your own hardware, relay no be the correct tool. You need another control plane.
When self-hosted Headscale control plane dey make sense?
Headscale, the open source Tailscale control server dey replace coordination server with one wey you run for VPS (virtual private server). Tailscale clients no change. Dem go point to your server instead of Tailscale own, so you no get seats to buy and no user cap.
Start with the money, because the difference small pass wetin people expect. One Standard seat na 8 US dollars per month. Small VPS wey fit run control plane cost about wetin one or two seats cost. So e no become cheaper until you dey pay for several people, and e never become cheaper for solo homelab, wey free already. Self-hosting to save money for network with five devices no go work out.
The real trade-off na control against work. Headscale put your user list and policy file for machine wey you own, for country wey you choose, without vendor account for the path. According to project documentation wey dem check on 17 August 2026, e support ACLs and grants, tags, subnet routers, exit nodes, MagicDNS, Taildrop, Tailscale SSH, node registration over OpenID Connect (OIDC), and embedded DERP server. Funnel and Serve dey listed as work in progress, so publishing service with Serve or Funnel still dey use Tailscale own control plane for now. Network flow logs no dey available too, OIDC groups no fit dey used inside ACL rules, and project design limit am to one tailnet.
Na the work wey you go carry be this:
- Na you own control plane availability. Existing tunnels go continue to pass traffic for some time, because the peers don already hold each other's keys. Anything wey need coordination go stop: new nodes no fit register, expiring keys no fit renew, and policy changes no go reach the nodes.
- Na you own upgrades. Headscale implement protocol wey Tailscale clients dey change continuously, so your upgrade schedule dey follow their client releases, not your calendar.
- Na you own the database and backups. If you lose that state, every node must register again.
- Na you own TLS (transport layer security) for server public endpoint, because clients dey reach control server over HTTPS.
Na the honest cost be that. Choose am when the reason na control or user count wey per-seat pricing no handle well. No choose am just to save eight dollars.
A self-hosted NetBird server na the other answer wey you fit self-host. E ship with its own control plane, identity handling, and web interface, and dem build am as product instead of reimplementing another person's control server. Both options leave you running service wey your network depend on. First decide say you want run one, then choose.
FAQ
Personal free plan for Tailscale na trial?
No. Personal na free tier wey no get expiry. As dem check am on 17 August 2026, e cover six users, unlimited user devices, and 50 tagged resources. E still include almost all the features. Wetin e no cover na capabilities wey paid tiers dey sell, like more ACL groups and single sign-on with your own identity provider. Confirm today's numbers for Tailscale pricing page, because dem fit revise the allowances.
How many devices I fit add for Tailscale free plan?
Your own devices unlimited. Tailscale pricing FAQ talk say user devices, meaning any node wey no be tagged, dey free and unlimited. Na tagged resources dem dey count: servers and routers wey you register with a tag. Personal include 50 of dem on 17 August 2026. Older guides wey talk say limit na 20 devices or 100 devices dey describe old pricing model wey no longer apply.
Why my tailnet dey talk say "Reached use limit"?
The tailnet don reach the limit for its plan. For Personal, the usual cause na seventh person, because the plan dey count people, no be machines. Another possible cause na tagged resources wey pass the included allowance. First count human accounts for admin console, then count tagged machines. Untagged laptops and phones no be the cause.
Headscale cheaper pass to pay for Tailscale?
Only when paid seats don pass small number. VPS wey fit run Headscale dey cost roughly wetin one or two Standard seats cost every month. So small tailnet no go save money, and solo tailnet don free from the beginning. Headscale make sense when you want make control plane dey hardware wey you own, or when your user count make per-seat pricing hard to manage. The cost na operational work: upgrades wey follow Tailscale client releases, database backups, TLS certificate wey you need renew, and say na only you fit fix outage.