Skip to main content
Connect Tailscale to add your tailnet’s devices, users, groups, and access relationships to your Asset Map.

What it maps

Agents can use these relationships to understand which identities can reach a service and which devices belong to them.

Access required

Create a Tailscale OAuth credential with read-only access. The all:read scope covers the devices, users, policy, services, and posture information used by the integration. You’ll need a tailnet role that can create OAuth credentials with those scopes. See Tailscale OAuth clients.

Connect your tailnet

1. Create an OAuth credential

In the Tailscale admin console, open Trust credentials, select Credential, then OAuth. Select read access to all resources, corresponding to all:read, and generate the credential. Copy the client ID and client secret. Tailscale displays the secret only when it is created.

2. Complete the connection

Open Settings → Integrations → Tailscale in Antigen and enter: Select Connect. Your tailnet’s resources and access relationships appear in the Asset Map as discovery progresses.

Troubleshooting

Access is denied

Check that the credential belongs to the tailnet you entered and includes the required read scopes. The client ID and secret are case-sensitive.

A device or group is missing

Confirm that it belongs to the connected tailnet. Groups and access relationships come from the tailnet’s policy configuration.