tailcat

A netcat-like tool that connects two machines over Tailscale's encrypted peer-to-peer network without a Tailscale account. Connection details are exchanged by any method you choose.

Share on XLicense: BSD-3-Clause

Overview

Tailcat is a netcat-like tool built from open source parts of Tailscale. It uses Tailscale's data plane, which gives WireGuard-encrypted point-to-point tunnels, but not its control plane, so no Tailscale account is needed. One side runs a listener and gets a short address; the other side connects with that address. The connection details are shared by whatever means you like. It is a Go library and CLI that runs in userspace.

Key features

  • Listener returns a short address that a client uses to connect
  • Traffic is encrypted end to end with WireGuard
  • Uses DERP relays for setup and as a fallback when NAT traversal fails
  • Needs no root access and does not change routing or DNS
  • Available as both a CLI and a Go library

Best for

Developers who want to pipe data between two machines behind NAT without setting up an account or VPN. The default DERP relays are free but rate limited, and you can run your own.

Upstream
tailscale/tailcat
Fork on GitHub
Guo-astro/tailcat
Upstream stars
7.8k
Category
Security and networking
Language
Go
License
BSD-3-Clause
Forked
2026-08-29
Sync status
In syncLast synced 2026-09-29