Redock Embedded Tailscale lets your phone connect directly to remote hosts in your Tailnet without opening the Tailscale app.
It avoids occupying the phone's system VPN slot. Some VPN or proxy apps can still intercept Tailscale control-plane traffic, so temporarily disable them if registration or startup times out.
Note: Embedded Tailscale only replaces the phone-side connection method. The target Mac or server must still have Tailscale installed and be signed in.
Prerequisites
Before you begin, make sure:
- Tailscale is installed on the target Mac or server.
- The device status is Connected.
- The SSH service is enabled.
Setup
- Open the Tailscale Admin Console.
- Create an Auth Key.
- In Redock's Host settings, enter the target device's Tailscale IP or MagicDNS name.
- Enable “Use Embedded Tailscale.”
- Enter the Auth Key to complete registration.
- Save the Host and connect.
After registration, other Embedded Tailscale Hosts on this device can reuse the connection.
Security Recommendations
- Use a dedicated Auth Key.
- Delete the corresponding key when you no longer need it.
- Do not share your Auth Key.
Auth Key Storage
- The Auth Key is used only for initial registration. Redock does not store it.
- After registration, Redock uses the registered device identity to connect to the Tailnet.
- If you delete the app or clear its data, you will need to register again.
Troubleshooting
Cannot Connect to a Tailscale Host
Check that:
- The target device is online.
- Tailscale shows Connected.
- The Host address is correct.
- If Redock shows “Registration may be invalid” and the embedded device was removed from the Tailscale admin console, create a new Auth Key and choose “Clear identity and register again.”
Tailscale Does Not Work While Another VPN Is Active
You do not need to open the Tailscale app. If registration or startup times out, temporarily disable the other VPN or proxy, retry in Redock, and re-enable it after the embedded node reaches Running.