Tailcat: Tailscale's netcat for encrypted tunnels between two machines, no account required
This post was translated from Chinese by AI. If anything reads oddly, the Chinese original is authoritative. 中文原文
Tailscale has released a small tool called Tailcat: it works like netcat, but uses Tailscale's data plane underneath (WireGuard encryption, NAT hole punching, and DERP relays as a fallback), with no Tailscale account, no root access, and no changes to routing or DNS. One end starts a service and gets a short address; the other connects using that address, creating an end-to-end encrypted tunnel.
For "use it and forget it" tasks like sending a friend a file, remotely accessing a port on a private network, or letting someone temporarily troubleshoot your machine, it's much lighter than setting up a VPN or opening a public port.
How it works
Tailscale has two main components: the control plane (accounts, ACLs, key distribution) and the data plane (peer-to-peer WireGuard tunnels plus DERP relays). Tailcat uses only the data plane, packing the metadata needed for a connection into an address starting with tc. You share that address out of band yourself (via WeChat, email, or even reading it aloud). The connection is first bootstrapped through a DERP server, then attempts UDP hole punching. If that succeeds, it connects directly; otherwise, it keeps using the relay.
By default, it uses the official free, rate-limited DERP relays. You can also run your own derper as a relay.
What it can do
At its simplest, it pipes data like netcat:
// Machine A
tailcat
// Prints a tcXXXX address, then waits
// Machine B
echo hello | tailcat tcXXXX
There are plenty of subcommands on top of that:
tailcat serve 8080,8443: expose local ports; the peer usestailcat forward <地址> 18080:8080to map them to local ports for browsers or database clients to use directly;tailcat browseopens a browser directlyserve 5555:10.2.200.213:5555: forward a port to another device on the private network without exposing the entire subnetserve exit-node: act as an exit node, letting the peer access any IP:port on the server's networkserve ssh/tailcat ssh: a built-in SSH server that can authenticate usingauthorized_keysor fetch GitHub public keys directly with用户名@github; there's alsono-auth-sshfor access without authentication, but then the address is effectively the password, so don't share it publiclyserve exec -- 命令: like inetd, run a command for each connectionrecv ~/inbox/cp: a file drop box; the sender usestailcat cp report.pdf tcXXXX:. The drop box is write-only, with no directory listing or overwriting existing filesserve files: share a directory as read-only or read-write; paths are confined to that directory, and neither..nor symlinks can escape itperf: iperf-like throughput and latency tests that run only over direct connections, refusing to consume shared relay bandwidthping --until-direct: check whether the connection is relayed or directsocks: start a SOCKS5 proxy over the tunnel
There's also an experimental browser version (compiled to WebAssembly) that can exchange files and text with the command-line version, though the browser currently supports only DERP relays, not direct connections.
Installation
Linux and Windows have static binaries and deb / rpm packages, macOS uses Homebrew, and Windows also has Scoop. Snap, Nix, AUR, conda-forge, and container images are available too. With the Go toolchain:
go install github.com/tailscale/tailcat/cmd/tailcat@latest
Who it's for and what to watch out for
It's useful for anyone who frequently needs a temporary connection between two machines, such as for operations work, debugging across NAT, or sending large files to remote colleagues. It's also a Go library you can embed directly in your own programs to add a "peer-to-peer channel without a public IP."
A few things to keep in mind:
- The address is a credential, so don't post it publicly. For services you plan to keep open long-term, use
--allowto restrict allowed peers, or configure SSH public-key authentication - The official free relays are rate-limited. For large transfers, it's best to wait for a direct connection or host your own DERP
- The project is still very new (the latest version is v0.7.0, 2026-09-20), and its interfaces may still change
- It's not a replacement for Tailscale: no private network setup, no ACLs, no fixed addresses, and a new address every time it starts
Project information
- Language: Go
- License: BSD-3-Clause
- Star: approximately 8100 as of 2026-10-04
- GitHub: https://github.com/tailscale/tailcat
- Official website: https://tailscale.com/tailcat
- Browser Demo: https://tailscale.github.io/tailcat/
Originally published on the SunAI forum. Versions, star counts, and relative dates in this article reflect the time of the original post.
Last updated 2026-10-09
Comments 0