Wood Chen

Tailcat: Tailscale's netcat for encrypted tunnels between two machines, no account required

0 comments2 views766 words

This post was translated from Chinese by AI. If anything reads oddly, the Chinese original is authoritative. 中文原文

Tailscale has released a small tool called Tailcat: it works like netcat, but uses Tailscale's data plane underneath (WireGuard encryption, NAT hole punching, and DERP relays as a fallback), with no Tailscale account, no root access, and no changes to routing or DNS. One end starts a service and gets a short address; the other connects using that address, creating an end-to-end encrypted tunnel.

For "use it and forget it" tasks like sending a friend a file, remotely accessing a port on a private network, or letting someone temporarily troubleshoot your machine, it's much lighter than setting up a VPN or opening a public port.

How it works

Tailscale has two main components: the control plane (accounts, ACLs, key distribution) and the data plane (peer-to-peer WireGuard tunnels plus DERP relays). Tailcat uses only the data plane, packing the metadata needed for a connection into an address starting with tc. You share that address out of band yourself (via WeChat, email, or even reading it aloud). The connection is first bootstrapped through a DERP server, then attempts UDP hole punching. If that succeeds, it connects directly; otherwise, it keeps using the relay.

By default, it uses the official free, rate-limited DERP relays. You can also run your own derper as a relay.

What it can do

At its simplest, it pipes data like netcat:

// Machine A
tailcat
// Prints a tcXXXX address, then waits

// Machine B
echo hello | tailcat tcXXXX

There are plenty of subcommands on top of that:

  • tailcat serve 8080,8443: expose local ports; the peer uses tailcat forward <地址> 18080:8080 to map them to local ports for browsers or database clients to use directly; tailcat browse opens a browser directly
  • serve 5555:10.2.200.213:5555: forward a port to another device on the private network without exposing the entire subnet
  • serve exit-node: act as an exit node, letting the peer access any IP:port on the server's network
  • serve ssh / tailcat ssh: a built-in SSH server that can authenticate using authorized_keys or fetch GitHub public keys directly with 用户名@github; there's also no-auth-ssh for access without authentication, but then the address is effectively the password, so don't share it publicly
  • serve exec -- 命令: like inetd, run a command for each connection
  • recv ~/inbox / cp: a file drop box; the sender uses tailcat cp report.pdf tcXXXX:. The drop box is write-only, with no directory listing or overwriting existing files
  • serve files: share a directory as read-only or read-write; paths are confined to that directory, and neither .. nor symlinks can escape it
  • perf: iperf-like throughput and latency tests that run only over direct connections, refusing to consume shared relay bandwidth
  • ping --until-direct: check whether the connection is relayed or direct
  • socks: start a SOCKS5 proxy over the tunnel

There's also an experimental browser version (compiled to WebAssembly) that can exchange files and text with the command-line version, though the browser currently supports only DERP relays, not direct connections.

Installation

Linux and Windows have static binaries and deb / rpm packages, macOS uses Homebrew, and Windows also has Scoop. Snap, Nix, AUR, conda-forge, and container images are available too. With the Go toolchain:

go install github.com/tailscale/tailcat/cmd/tailcat@latest

Who it's for and what to watch out for

It's useful for anyone who frequently needs a temporary connection between two machines, such as for operations work, debugging across NAT, or sending large files to remote colleagues. It's also a Go library you can embed directly in your own programs to add a "peer-to-peer channel without a public IP."

A few things to keep in mind:

  • The address is a credential, so don't post it publicly. For services you plan to keep open long-term, use --allow to restrict allowed peers, or configure SSH public-key authentication
  • The official free relays are rate-limited. For large transfers, it's best to wait for a direct connection or host your own DERP
  • The project is still very new (the latest version is v0.7.0, 2026-09-20), and its interfaces may still change
  • It's not a replacement for Tailscale: no private network setup, no ACLs, no fixed addresses, and a new address every time it starts

Project information


Originally published on the SunAI forum. Versions, star counts, and relative dates in this article reflect the time of the original post.

Last updated 2026-10-09

Related posts

Comments 0