{
  "slug": "headscale",
  "category": "mesh-vpns",
  "name": "Headscale",
  "description": "Self-hosted, open-source implementation of the Tailscale coordination server, letting official Tailscale clients join a private network without using Tailscale's hosted service.",
  "website": "https://headscale.net",
  "source": "https://github.com/juanfont/headscale",
  "license": "BSD-3-Clause",
  "platforms": [
    "linux"
  ],
  "jurisdiction": null,
  "pick": true,
  "pick_reason": "The open-source, self-hosted replacement for Tailscale's coordination server. The official Tailscale clients connect to it unchanged, so the whole network runs on your own server with no account at Tailscale.",
  "disclosure": null,
  "grade": "B",
  "score": 82,
  "coverage": 100,
  "summary": "Headscale scores 82 out of 100 (grade B) on the mesh VPNs and private networks criteria. It meets 5 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, keys stay on devices and self-hosted coordination server. It partly meets no connection logs by default. It does not meet independent audit.",
  "url": "https://privacyratings.com/mesh-vpns/headscale/",
  "markdown": "https://privacyratings.com/mesh-vpns/headscale/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/juanfont/headscale/blob/main/LICENSE",
      "note": "BSD-3-Clause."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/juanfont/headscale",
      "note": "No telemetry or analytics in the source code, and the website loads no trackers."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://github.com/juanfont/headscale",
      "note": "Free community project with no ads or data sales."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "device_keys": {
      "title": "Keys stay on devices",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/juanfont/headscale#readme",
      "note": "Works with the official Tailscale clients, which create WireGuard keys on each device. The control server only exchanges public keys."
    },
    "self_hosted_control": {
      "title": "Self-hosted coordination server",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://github.com/juanfont/headscale/blob/main/LICENSE",
      "note": "The whole control server is open source and self-hosted."
    },
    "no_connection_logs": {
      "title": "No connection logs by default",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://github.com/juanfont/headscale/issues/2793",
      "note": "Headscale tells clients not to upload logs by default, but official Tailscale clients still contact log.tailscale.com at startup until TS_NO_LOGS_NO_SUPPORT is set."
    }
  },
  "tests": {
    "ssllabs": null,
    "observatory": null,
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T06:38:30.666Z"
  },
  "last_modified": "2026-10-01T06:56:31Z"
}