Tailscale
Configure the widget with OAuth and distinguish between the widget, remote access, and auth key.
Three different use cases are often confused:
| Use case | Required identifier | Where to configure |
|---|---|---|
| Display tailnet devices in the widget | OAuth Client ID + OAuth Client Secret | NasDash, widget settings |
| Access NasDash remotely via Tailscale | No secret in NasDash | Tailscale client on each machine |
| Automatically enroll a new machine | Tailscale auth key | On that machine, not in the widget |
Create the widget identifier
- Open the Tailscale admin console — OAuth clients.
- Select Generate OAuth client.
- Grant only read access to devices, for example the
devices:core:readscope suggested by Tailscale. - Immediately copy the Client ID and Client secret: the secret is displayed only once.
- In NasDash, open Settings → Widgets → Tailscale.
- Enter the tailnet, Client ID, and Client Secret.
The tailnet can be its DNS name or the identity shown in your console. OAuth clients and their scopes are explained in the official Tailscale documentation.
Do not paste an auth key into the widget
A key typically starting with tskey-auth- is used to connect a machine to the tailnet. The widget expects an OAuth client secret, usually presented as tskey-client-..., along with its Client ID.
Access NasDash via Tailscale
- Install Tailscale on the host running NasDash and on the client machine.
- Connect both to the same tailnet.
- Keep the NasDash port accessible on the Tailscale IP or use a private reverse proxy.
- Open
http://IP_TAILSCALE:2504.
This method does not require enabling the widget. Still, protect NasDash with strong passwords and appropriate Tailscale ACLs.
Rotation
Create a new OAuth client, replace the secret in NasDash, verify the widget, and then revoke the old client. A backup of /app/data contains the encrypted configuration; protect it as a secret.