# Features

Last validated Jan 29, 2026

* [Access control](/docs/features/access-control) — Understand the options available for access control in Tailscale.

* [Client](/docs/features/client) — Client documentation index.

* [Containers](/docs/features/containers) — Containers documentation index.

* [Customize Tailscale using system policies](/docs/features/tailscale-system-policies) — A list of configuration keys you can use to customize the Tailscale client using system policies, including MDM.

* [Device posture management](/docs/features/device-posture) — Use device posture for enforcing device rules in your tailnet.

* [Ephemeral nodes](/docs/features/ephemeral-nodes) — Use ephemeral nodes in Tailscale for managing short-lived devices like containers and CI/CD systems.

* [Exit nodes (route all traffic)](/docs/features/exit-nodes) — Route all internet traffic through a specific device on your network.

* [Firewall mode in tailscaled](/docs/features/firewall-mode) — Understand the different firewall modes supported by Tailscale on Linux devices.

* [Group devices with tags](/docs/features/tags) — Use Tailscale tags to authenticate and identify non-user devices, such as a server.

* [Group visibility on Tailscale clients](/docs/features/group-visibility-clients) — Get group membership information for applications running in your Tailscale network.

* [How app connectors work](/docs/features/app-connectors) — Route SasS application traffic in your tailnet using app connectors.

* [Logging overview](/docs/features/logging) — Understand Tailscale's logging infrastructure.

* [macOS and iOS shortcuts](/docs/features/mac-ios-shortcuts) — Understand how Tailscale works with the Shortcuts app, allowing you to automate tasks.

* [MagicDNS](/docs/features/magicdns) — Find out how to automatically register DNS names for devices in your Tailscale network.

* [Manage multiple tailnets](/docs/features/multiple-tailnets) — Manage multiple tailnets under a single organization.

* [OAuth apps](/docs/features/oauth-apps) — Build internal tools that act on behalf of individual users through a standard OAuth 2.0 authorization code flow, so each action carries the consenting user's identity.

* [OAuth clients](/docs/features/oauth-clients) — Use OAuth clients to provide ongoing access to the Tailscale API.

* [Secure node state storage](/docs/features/secure-node-state-storage) — Encrypt Tailscale node state at rest.

* [Share your machines with other users](/docs/features/sharing) — Give a Tailscale user on another tailnet access to a private machine within your tailnet, without exposing the machine publicly.

* [Site-to-site networking](/docs/features/site-to-site) — Connect two subnets in your tailnet with each other.

* [Subnet routers](/docs/features/subnet-routers) — Use subnet routers to give devices outside your local network access to services within specific subnets. Extend your private network with Tailscale.

* [Taildrive](/docs/features/taildrive) — Share folders securely between devices on your Tailscale network.

* [Taildrop](/docs/features/taildrop) — Send files between your personal devices on a Tailscale network.

* [Tailnet Lock](/docs/features/tailnet-lock) — Ensure that no node joins your tailnet unless trusted nodes in your tailnet sign the new node.

* [Tailnet policy file](/docs/features/tailnet-policy-file) — Understand the tailnet policy file.

* [Tailscale Funnel](/docs/features/tailscale-funnel) — Securely route internet traffic to local services using Tailscale Funnel.

* [Tailscale Peer Relays](/docs/features/peer-relay) — Use Tailscale Peer Relays for client-to-client connections when direct connections aren't possible.

* [Tailscale Serve](/docs/features/tailscale-serve) — Explore the Tailscale Serve service.

* [Tailscale Services](/docs/features/tailscale-services) — Securely connect to and manage access to your internal resources using Tailscale Services.

* [Tailscale SSH](/docs/features/tailscale-ssh) — Use Tailscale SSH to manage the authentication and authorization of SSH connections in your tailnet.

* [tsidp](/docs/features/tsidp) — Use tsidp to secure any service that supports OIDC/OAuth with no additional login while on a tailnet, including self-hosted apps like Grafana and MCP servers.

* [tsnet](/docs/features/tsnet) — Use the tsnet package to embed Tailscale inside a Go program.

* [tsrecorder](/docs/features/tsrecorder) — Use tsrecorder for session recording with Tailscale SSH and the Tailscale Kubernetes Operator.

* [Use device posture for just-in-time access](/docs/features/tailscale-accessbot-jit) — Use device posture for just-in-time access to resources in your tailnet.

* [User & group provisioning](/docs/features/user-group-provisioning) — Learn about the System for Cross-domain Identity Management (SCIM) identity providers that Tailscale supports.

* [Viewing the list of endpoints on your network](/docs/features/services) — Find out how to monitor and easily connect to the endpoints running on machines in your Tailscale network.

* [Visual policy editor](/docs/features/visual-editor) — Update your tailnet policy file with the visual policy editor.

* [Webhooks](/docs/features/webhooks) — Set up a webhook to receive notification of events on your Tailscale network.

* [Workload identity federation](/docs/features/workload-identity-federation) — Use federated OIDC workload identities from third-party providers to authenticate requests to the Tailscale API.
