Integrations

Tailscale

Configure the widget with OAuth and distinguish between the widget, remote access, and auth key.

Three different use cases are often confused:

Use caseRequired identifierWhere to configure
Display tailnet devices in the widgetOAuth Client ID + OAuth Client SecretNasDash, widget settings
Access NasDash remotely via TailscaleNo secret in NasDashTailscale client on each machine
Automatically enroll a new machineTailscale auth keyOn that machine, not in the widget

Create the widget identifier

  1. Open the Tailscale admin console — OAuth clients.
  2. Select Generate OAuth client.
  3. Grant only read access to devices, for example the devices:core:read scope suggested by Tailscale.
  4. Immediately copy the Client ID and Client secret: the secret is displayed only once.
  5. In NasDash, open Settings → Widgets → Tailscale.
  6. Enter the tailnet, Client ID, and Client Secret.

The tailnet can be its DNS name or the identity shown in your console. OAuth clients and their scopes are explained in the official Tailscale documentation.

Do not paste an auth key into the widget

A key typically starting with tskey-auth- is used to connect a machine to the tailnet. The widget expects an OAuth client secret, usually presented as tskey-client-..., along with its Client ID.

Access NasDash via Tailscale

  1. Install Tailscale on the host running NasDash and on the client machine.
  2. Connect both to the same tailnet.
  3. Keep the NasDash port accessible on the Tailscale IP or use a private reverse proxy.
  4. Open http://IP_TAILSCALE:2504.

This method does not require enabling the widget. Still, protect NasDash with strong passwords and appropriate Tailscale ACLs.

Rotation

Create a new OAuth client, replace the secret in NasDash, verify the widget, and then revoke the old client. A backup of /app/data contains the encrypted configuration; protect it as a secret.