No developer tunnel setup
A stable authenticated MCP endpoint replaces the current need to configure and supervise a private tunnel client yourself.
We are exploring a hosted edition for people who want controlled AI access to private infrastructure without assembling MCP tunnels, runtime credentials, connector lifecycle, and team policy by hand. The self-hosted Community product remains independently usable.
The customer Edge keeps its Tailscale identity and final policy decision in the customer environment. Cloud routes requests through an already connected Edge; it does not join or directly dial the customer's tailnet.
Authenticates to the hosted MCP endpoint.
Checks user/workspace policy and routes requests through an already connected Edge.
Edge holds tailnet state, enforces local policy, and reaches admitted hosts over the customer's private network.
A stable authenticated MCP endpoint replaces the current need to configure and supervise a private tunnel client yourself.
Pair an Edge connector, see its health, rotate credentials, and manage upgrades without losing its customer-side policy boundary.
Map users to hosts and access modes, retain audit metadata, and separate broad Operator delegation from narrower capabilities.
The hosted product is not intended to become another general-purpose private network. Tailscale continues to provide private connectivity and machine identity; TetherBound Cloud adds AI-user identity, routing, governance, and audit while the customer Edge performs the final local authorization decision.
People operating real private fleets: homelabs, VPSs, self-hosted services, remote development machines, agency/client environments, GPU boxes, or small production infrastructure. Mixed Linux/Windows/macOS fleets are especially useful.
Community is already public and self-hosted. Tell us what plumbing or team controls would make an optional hosted layer valuable. Please do not include passwords, private keys, private IP addresses, customer data, logs, or other secrets.