Tailscale pricing after free plan: wetin you go pay
Tailscale bills per user, no be per device. See wetin household and five-person team go pay, which limit go hit first, and when Headscale make sense.
Tailscale pricing dey summarized for one paragraph
Tailscale pricing na per user, no be per device. User devices dey unlimited for every plan, including the free one, so free plan no go finish because you buy another laptop. E go finish because you add person, or because you need admin feature wey only paid plan get. Tailscale na VPN (virtual private network) wey build on WireGuard, and wetin you dey pay for na the control plane around the tunnels: identity and policy.
The data behind this chart
[
{
"plan": "Personal",
"usd_per_user_month": 0
},
{
"plan": "Standard",
"usd_per_user_month": 8
},
{
"plan": "Premium",
"usd_per_user_month": 18
}
]Tailscale dey sell 3 self-serve plans plus one plan wey dem dey price by quote. Personal cost $0 and e cover up to six users. Standard cost $8 per user per month. Premium cost $18 per user per month. Enterprise price dey depend on each case, so e no get public figure to plot. Na the published list prices as of August 2026, wey we read from the Tailscale pricing page. Tailscale don change its plans several times, so check that page before you prepare budget.
Tailscale change its plans on 8 April 2026. Dem retire Personal Plus and move its six-user allowance enter the free Personal plan, while the old Starter plan become Standard. Tailscale talk say if you dey pay already, your current plan go continue to work for the same price for at least another twelve months from that announcement. Because of that, an existing invoice fit no match the current page.
Wetin Tailscale dey actually meter
Four things get number for your tailnet (the single Tailscale network wey your devices share), and only one of dem na people. The figures below na as dem publish am for August 2026.
- Seats. Seat na user. Standard and Premium dey bill per seat every month, and the seat count na the whole invoice.
- User devices. Unlimited for every plan. Machine wey belong to person no cost anything, no matter how many machines that person get.
- Tagged resources. Every plan include 50. Extra ones na $1 every month each, and you fit add dem yourself from billing console. Tagged resource na machine wey carry tag instead of user identity. Na so server or another non-human node dey join.
- ACL groups. ACL (access control list) group na named set of users wey your policy rules dey refer to. The number wey you get dey differ well-well by plan, and that difference get im own section below.
Dem meter ephemeral resources separately, in minutes: 1,000 minutes every month for Personal and Standard, 10,000 for Premium. Ephemeral node na short-lived node, like CI (continuous integration) runner wey join for one build and then comot. Node wey stay for the tailnet pass four hours no longer count against that pool, so ordinary server no go drain am. The comparison table no get row for exit nodes, subnet routers or MagicDNS, so dem no dey meter the network structure itself. Na why one machine wey dey advertise private subnet from VPS fit make whole network of devices reach your tailnet without adding one billable line to the invoice. Serve and Funnel no dey inside am too, so publishing HTTPS service no cost anything for any plan, although policy setting dey hold Funnel back instead of price, as serve against funnel explain. For the exact limit of the free tier, see where free Tailscale plan dey stop.
How dem dey count seat, so invoice go match your headcount
Tailscale billing documentation talk am clearly: you dey pay for some number of seats for your tailnet, and user dey occupy seat once dem join. For real use, user go take seat the first time dem sign in to admin console, or the first time dem authenticate device. Person wey you invite but never accept yet no dey occupy seat, and dem no go charge you for that person. If all seats don full and new user sign in, seat count go increase automatically by 1, and dem go charge seat wey dem add during monthly billing period with prorated rate. You fit free seat, for example by deleting user, and the next person fit reuse am. For annual subscription, Tailscale sales team dey handle those changes instead of console, so e good make you know this before you commit to one year.
Two scenarios, wey we work finish from start to end
Seats na the only thing wey dey change, so annual amount na seat count multiply by monthly price multiply by twelve. Here be four examples for list price.
The data behind this chart
[
{
"label": "Household of 4, Personal",
"usd_per_year": 0
},
{
"label": "Household of 7, Standard",
"usd_per_year": 672
},
{
"label": "Team of 5, Standard",
"usd_per_year": 480
},
{
"label": "Team of 5, Premium",
"usd_per_year": "1,080"
}
]Scenario one: household wey get four people
This na the easy case, and answer na $0. Personal plan cover up to six users, and user devices no get limit. Four people wey each carry phone and laptop, plus home server, network video recorder, and VPS, all fit enter the free plan. VPS wey dey act as Tailscale exit node for VPS na one more free device, because the plan dey count people, no be roles.
Two things still fit end household free plan. The first na seventh user. Housemates, partner parents, or friend wey want access to your media server: once users pass six, the whole tailnet go move to Standard, and you go pay for every seat, no be only the new one. Seven seats at $8 each na $672 per year. The second na tags. If you tag your servers so tag own dem instead of you, the first 50 dey included, and every one after that go cost $1 per month. Most households no dey reach 50.
Scenario two: team wey get five people
Five people fit enter the free allowance wey cover six users, so company wey get five people fit run Tailscale for $0 every year, and plenty companies dey do am. Headcount hardly dey stop dem. Na the admin side of the product dey push small team enter paid plan, and e dey happen well before the sixth person join.
When una move, the calculation simple because na seats alone dey count. Five seats for Standard na $480 every year. The same five seats for Premium na $1,080 every year. New person wey join for month seven go add one prorated seat, no be new plan.
Why the bill dey show for identity side
The login itself free for every plan. The charge dey for the machinery around am: who fit administer wetin, and how detailed you fit describe access. Na the same pattern we describe for SSO tax for self-hosted apps, and Tailscale show this matter clearly.
Start with user roles, because na this row dey move small teams enter paid plan. Tailscale documentation divide roles into two. "Basic roles are available for all pricing plans", and those roles na Owner, Admin and Member. "Advanced roles are available for the Standard, Premium, and Enterprise pricing plans", and those roles na Billing admin, IT admin, Network admin and Auditor. For free plan, you no fit allow your networking person own the policy file without also giving dem power to delete the tailnet, and no read-only role dey at all. The first time colleague ask for audit access, you don reach Standard.
SCIM (system for cross-domain identity management) na the second row. SCIM na protocol wey dey push users and groups from your identity provider enter service, so person wey leave company go disappear from tailnet when HR disable their account. E start for Standard. For Personal, na hand you go use remove people. This dey okay for four people, but e become real risk for twenty. Forgotten account na also realistic way person fit enter tailnet, instead of anything related to encryption. Na the point wey Tailscale trust model dey explain.
The data behind this chart
[
{
"plan": "Personal",
"groups_included": 3
},
{
"plan": "Standard",
"groups_included": 10
},
{
"plan": "Premium",
"groups_included": 300
}
]Then ACL groups. Personal allow 3 groups. Standard allow 10. Premium allow 300. Three fit sound workable until you write the policy file: one group for staff and one for contractors go leave you with only one group for every other person. So any further structure go need individual users. This one stop scaling immediately somebody change job.
Two other rows dey worth mention, so you no upgrade for wrong reason. Device posture integrations with MDM (mobile device management), EDR (endpoint detection and response) and XDR (extended detection and response) start for Standard. Network flow logs and log streaming start for Premium, while session recording come with the Enterprise privileged access management extension. Device approval, wey dey hold new machine for waiting state until admin allow am enter, documentation say e dey available for all plans. So e no be reason to pay.
Discount wey you fit really get
Tailscale document several discounts, and e good make you check dem before you pay list price. Charities, not-for-profit organisations, and educational institutions get "50% discount off of list prices": first select plan for billing console, then contact Tailscale Support make dem apply the discount. Open source projects wey dey inside GitHub organisation and get OSI (Open Source Initiative) licence fit use Tailscale free, as long as the tailnet dey use GitHub for authentication. Promo codes fit show for conferences and marketing emails, and dem apply when you upgrade.
Headscale, the self-hosted escape hatch
Headscale na open source implementation of Tailscale control server, and official Tailscale clients dey connect to am. E no dey associated with Tailscale Inc. The documentation restrict the scope clearly: na one tailnet, “suitable for personal use, or small open-source organisation”, and e target self-hosters and hobbyists. The feature list complete pass wetin most people expect. MagicDNS, Taildrop, tags, subnet routers, exit nodes, ephemeral nodes, embedded DERP (designated encrypted relay for packets) server, ACLs, and Tailscale SSH all dey listed as supported.
The trade-off dey work for both directions, and e good make we talk am honestly. Headscale remove per-seat bill completely: users, devices, and ACL groups become your own numbers, and per-person charge disappear. But you go operate the control plane yourself. Control server na e dey issue node keys and distribute peer map, so when e offline, you no fit add device or re-authenticate device wey key don expire. This mean say database need backups, version need upgrade plan, and host need monitoring, just like any other production service. Identity na also where e weak pass: Headscale support OIDC (OpenID Connect) logins, but documentation note say OIDC groups no fit dey used for ACLs. Na exactly this capability team fit dey pay Tailscale for.
So accept the trade if you dey run one tailnet, you already dey maintain and back up Linux server, and per-seat price na your only reason for checking am. No accept am if wetin you wan buy na SCIM, auditor access, or group-based policy, because Headscale no dey try solve that part. The install na normal server setup, and running Headscale as your own Tailscale control server cover am. If you want neither the bill nor the control plane, read plain WireGuard against Tailscale for comparison, because hand-managed WireGuard get no per-user cost and no coordination server at all. If group-based policy na the thing wey dey push you toward paid plan, running your own NetBird server fit you better, because e ship with identity provider alongside control plane and e write access rules against groups wey you define yourself.
Count your own users and devices first
Before you model anything, first get the two real numbers. For any machine wey already dey inside the tailnet:
tailscale statusE go print one line for each machine:
100.101.102.103 laptop-alice alice@ linux active; direct 203.0.113.9:41641, tx 1116 rx 1124
100.101.102.104 phone-bob bob@ iOS active; relay "fra", tx 1351 rx 4262
100.101.102.105 vps-frankfurt alice@ linux idle; tx 1214 rx 50The columns na Tailscale IP address, machine name, owner, operating system, and connection state. Na the third column dey decide your bill. Count the different logins there instead of counting the lines, because three machines wey alice@ own na one seat and three free devices.
For the whole tailnet, instead of the view from one machine, the API go return the complete device list:
curl -s "https://api.tailscale.com/api/v2/tailnet/example.com/devices" -u "$TS_API_KEY:"Replace example.com with your tailnet name, and generate the access token for the Keys page of the admin console. You need to be Owner, Admin, or IT admin before that call go succeed. The number wey settle the invoice still dey for the Users page of the admin console, because seat na user wey don sign in, and na that one Tailscale dey count.
FAQ
Tailscale dey free for personal use?
Yes, for up to six users. Personal plan cost $0 and e include unlimited user devices, 50 tagged resources, 3 ACL groups, and 1,000 ephemeral resource minutes every month, as dem publish am for August 2026. Six na the user count for the whole tailnet, so if person number seven join, the whole tailnet go move enter paid plan and every existing user go become billed seat.
My devices dey count for Tailscale bill?
Devices wey belong to person no dey count. User devices unlimited for every plan, so one person wey get twenty machines still be one seat. The device number wey fit cost money na tagged resources, meaning machines wey carry tag instead of user identity. Every plan include 50 of dem, and extra ones cost $1 every month each. You fit add dem by yourself from the billing console.
Wetin be the cheapest way to run Tailscale for team of five people?
Remain for Personal, because five people dey within the free allowance of six users. Move go Standard at $8 per user every month, wey be $480 every year for five seats, when you need something wey the free plan no include: advanced user roles, SCIM provisioning, device posture checks, or more than 3 ACL groups. If you be registered charity or educational institution, ask Tailscale Support for the 50% discount before you subscribe.
Self-hosting Headscale really dey save money?
E remove the per-seat charge and replace am with server wey you go operate. This trade make sense when na the bill alone dey make you consider am, when you run one tailnet, and when you already dey maintain Linux host with backup and patches. E no work well when you plan to pay for identity governance, because Headscale documentation note say OIDC groups no fit work inside its ACLs. So the group-based policy wey you want na the part wey no go carry over.