You cannot self-host Tailscale's own control server, but you can get a self-hosted Tailscale setup with Headscale, an open-source (BSD-3-Clause) reimplementation of the coordination server that works with the official Tailscale clients. If you want a fully open-source mesh VPN instead, NetBird is the strongest option: WireGuard-based, with its own clients, web dashboard and a self-hosted control plane that runs on a 2 GB VM. For simpler needs, wg-easy gives you a plain WireGuard server with a web UI, and Pangolin publishes internal services without opening ports.
How Tailscale works, and what you can self-host
Tailscale builds a peer-to-peer mesh of WireGuard tunnels between your devices. The data plane is the clients themselves: traffic flows directly between devices, or through DERP relays when a direct connection is impossible. The control server hands out keys, applies access rules and tells devices how to find each other.
Most of Tailscale is open source, but not the control server or the GUI clients for Windows, macOS and iOS. So "self-hosted Tailscale" really means replacing the coordination server, which is exactly what Headscale does.
The options at a glance
| Licence | What it is | Clients | Web UI | Best for | |
|---|---|---|---|---|---|
| Headscale | BSD-3-Clause | Open-source Tailscale control server | Official Tailscale clients | No official UI; community projects | Personal and small-team tailnets |
| NetBird | BSD-3 clients; AGPL-3.0 server | Complete mesh VPN platform | NetBird clients | Yes, built in | Teams, fully open-source stack |
| wg-easy | AGPL-3.0 | WireGuard server with web UI | Standard WireGuard apps | Yes | Simple remote access to home |
| Pangolin | AGPL-3.0 | Tunnelled reverse proxy with access control | Browser, plus tunnel agent | Yes | Publishing services without port forwarding |
| Firezone | Apache-2.0 | Zero-trust access gateway | Firezone clients | Yes | Managed service; self-hosting unsupported |
Headscale: keep the Tailscale clients, own the server
Headscale aims to be "a self-hosted, open source alternative to the Tailscale control server" for a single tailnet, suitable for personal use or a small organisation. It has about 44,400 GitHub stars and over 1,000 commits in the past year, and one of its active maintainers is employed by Tailscale, although the project is independent.
You point the standard Tailscale apps at your Headscale URL, and most everyday features work. According to its documentation, supported features include MagicDNS and split DNS, ACLs and grants, subnet routers and exit nodes, ephemeral nodes, an embedded DERP server, OIDC login, Taildrop, Taildrive and Tailscale SSH. Funnel, Serve and network flow logs are not supported, and OIDC groups cannot be used in ACLs.
Headscale is a single Go binary with SQLite or PostgreSQL, so it runs comfortably on a small VPS. Management is through the CLI; there is no official web interface, though community front ends exist. It needs a public HTTPS endpoint, so put it behind a reverse proxy with a valid certificate.
NetBird: a complete open-source mesh VPN
NetBird is a WireGuard-based mesh network with everything included: clients for desktop and mobile, a management service, signal and relay servers, and a web dashboard for peers, groups, access policies and DNS. Client code is BSD-3-Clause, while the management, signal and relay components are AGPL-3.0. It has about 29,800 GitHub stars and more than 1,000 commits in the past year.
Its self-hosting quickstart asks for a VM with at least 1 CPU and 2 GB of RAM, a public domain, and open TCP ports 80 and 443 plus UDP 3478. A single script deploys the management, signal and relay servers, a STUN service, the dashboard, an embedded Dex identity provider for local users and a reverse proxy with automatic Let's Encrypt certificates. You can also connect an external identity provider for SSO.
NetBird's cloud has a Free plan for up to 5 users and 100 machines, with Team at €6 and Business at €12 per user per month as of October 2026, so you can trial it before self-hosting.
Simpler options
wg-easy is not a mesh. It runs a single WireGuard server with a clean web UI for creating clients and QR codes. If all you need is to reach your home network from your phone, it is the lightest option, and the standard WireGuard apps work with it.
Pangolin solves a different problem: exposing self-hosted web apps to the internet through a tunnel, with authentication in front, without opening ports at home. It is an alternative to Cloudflare Tunnel and ngrok rather than to a device mesh.
Firezone is Apache-2.0 and well engineered, but its README states that production self-hosting is not officially supported, so treat it as a managed service.
wg-easy
The easiest way to run WireGuard VPN with a web UI.
Pangolin
Identity-aware tunneled reverse proxy with dashboard UI, access control, and WireGuard-based tunnels (alternative to Cloudflare Tunnel, Tailscale).
When the free Tailscale plan is the better choice
Self-hosting the control plane gives you control and removes a third-party dependency, but it also makes you responsible for the piece that every device relies on to connect. As of October 2026, Tailscale's Personal plan is free for up to 6 users with unlimited user devices, and paid plans start at $8 per user per month for Standard and $18 for Premium. If you have a small homelab, are happy with a Tailscale account, and want features like Funnel, the free plan is hard to beat.
Self-host when you need the coordination server inside your own infrastructure for compliance or privacy, want no external accounts, have more users than the free tier allows, or simply want to understand and own every layer.
Which should you choose?
- Choose Headscale if you love the Tailscale apps and want a self-hosted control server for yourself, family or a small team.
- Choose NetBird if you want a fully open-source platform with a web dashboard, user management and policies for a team.
- Choose wg-easy if you only need remote access to your home network.
- Choose Pangolin if you want to publish web services securely without port forwarding.
Browse every open-source Tailscale alternative and ngrok alternative, or explore the VPN and proxy and remote access categories. A private mesh is also a safe way to reach services like Jellyfin from outside your home.