Headscale
A self-hosted, open-source replacement for the Tailscale control server, built for personal networks, labs and small organizations.
- GitHub stars
- 44k
- Last commit
- yesterday
- Latest release
- v0.29.4
- Licence
- BSD-3-Clause
- Self-hosted
- Yes
Headscale is a self-hosted, open-source take on the Tailscale control server. Tailscale is a VPN built on WireGuard that works as an overlay network between your computers using NAT traversal, and the control server is the piece that exchanges WireGuard public keys, assigns IP addresses, separates users and shares routes. Headscale replaces that coordination role with software you run yourself. It is written in Go under the BSD-3-Clause license.
The project has a deliberately narrow scope. It implements a single Tailscale network, called a tailnet, which is suitable for personal use or a small open-source organization, and it aims to give self-hosters and hobbyists a server for their projects and labs. The README explains that Tailscale's own clients and control server are not all open source, which is the gap Headscale fills.
Documentation is published for both stable and development versions, and the maintainers advise using the same Git tag as the release you run so the example configuration matches. A Discord server offers community chat. Headscale suits homelab users and small teams who want private mesh networking without relying on a hosted coordination service.
Key features
- Self-hosted Tailscale control server
- Key exchange and IP address assignment for nodes
- Single tailnet for personal or small-team use
- User separation and machine sharing
- Advertised route support
- Documentation for stable and development versions
Pricing: Free and open source under the BSD-3-Clause license.


