What it maps
Agents can use these relationships to understand which identities can reach a service and which devices belong to them.
Access required
Create a Tailscale OAuth credential with read-only access. Theall:read scope covers the devices, users, policy, services, and posture information used by the integration.
You’ll need a tailnet role that can create OAuth credentials with those scopes. See Tailscale OAuth clients.
Connect your tailnet
1. Create an OAuth credential
In the Tailscale admin console, open Trust credentials, select Credential, then OAuth. Select read access to all resources, corresponding toall:read, and generate the credential. Copy the client ID and client secret. Tailscale displays the secret only when it is created.
2. Complete the connection
Open Settings → Integrations → Tailscale in Antigen and enter:
Select Connect. Your tailnet’s resources and access relationships appear in the Asset Map as discovery progresses.