tailscale/tailcat

like netcat, but over Tailscale's data plane, without Tailscale's control plane

View on GitHub ↗Jump to charts ↓

Summary Information

Updated 24 minutes ago
Added to GitGenius on August 28th, 2026
Created on October 29th, 2024
Open Issues & Pull Requests: 9 (+0)
GitHub issues: Enabled
Number of forks: 111
Total Stargazers: 3,668 (+3)
Total Subscribers: 16 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 6.8 hours
Mean response time: 22.2 days
90th percentile: 166.8 days
Tracked items: 8

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 9
New in 7 days: 9
Closed in 7 days: 2
Avg open age: 2 days
Stale 30+ days: 0
Stale 90+ days: 0

Recent activity

Opened in 7 days: 9
Closed in 7 days: 2
Comments in 7 days: 5
Events in 7 days: 9

Top labels

No label distribution available yet.

Detailed Description

Tailcat is a command-line tool and Go library that provides netcat-like connectivity over Tailscale's data plane without requiring Tailscale's control plane infrastructure.

The tool solves the problem of establishing secure point-to-point connections between machines without needing a Tailscale account or control plane dependency. It reuses Tailscale's open source data plane components, specifically magicsock, which provides WireGuard-encrypted tunnels between peers. Connection metadata is exchanged out of band through a short connection token rather than through Tailscale's servers. The initial connection bootstraps through a DERP relay server for NAT hole-punching, then magicsock attempts to upgrade to a direct peer-to-peer UDP connection when possible. All traffic is encrypted end-to-end with WireGuard, and the tool runs entirely in userspace without requiring root access or modifying system routing tables or DNS.

Tailcat suits developers and operators who need secure inter-machine communication without the overhead of a full Tailscale deployment or account. It works well for temporary connections, file transfers, remote command execution, and exposing local services through encrypted tunnels. The tool includes a web-based demo compiled to WebAssembly for in-browser file and text transfer. Users can rely on free rate-limited DERP relays provided by default or run their own DERP infrastructure for complete independence.

The project maintains active development with regular commits addressing core functionality and experimental features. The codebase includes a command-line interface alongside an importable Go library, allowing both direct tool usage and integration into other applications. The maintainers actively track connectivity issues and are working toward WebRTC support for browser-based direct connections. The project accepts community contributions and maintains comprehensive documentation covering installation, usage patterns, and configuration options including custom DERP relay setup.