Back to guides
Network access

Redock Embedded Tailscale

Connect directly to remote hosts in your Tailnet without opening the Tailscale app on your phone.

Redock Embedded Tailscale lets your phone connect directly to remote hosts in your Tailnet without opening the Tailscale app.

It avoids occupying the phone's system VPN slot. Some VPN or proxy apps can still intercept Tailscale control-plane traffic, so temporarily disable them if registration or startup times out.

Note: Embedded Tailscale only replaces the phone-side connection method. The target Mac or server must still have Tailscale installed and be signed in.

Prerequisites

Before you begin, make sure:

  • Tailscale is installed on the target Mac or server.
  • The device status is Connected.
  • The SSH service is enabled.

Setup

  1. Open the Tailscale Admin Console.
  2. Create an Auth Key.
  3. In Redock's Host settings, enter the target device's Tailscale IP or MagicDNS name.
  4. Enable “Use Embedded Tailscale.”
  5. Enter the Auth Key to complete registration.
  6. Save the Host and connect.

After registration, other Embedded Tailscale Hosts on this device can reuse the connection.

Security Recommendations

  • Use a dedicated Auth Key.
  • Delete the corresponding key when you no longer need it.
  • Do not share your Auth Key.

Auth Key Storage

  • The Auth Key is used only for initial registration. Redock does not store it.
  • After registration, Redock uses the registered device identity to connect to the Tailnet.
  • If you delete the app or clear its data, you will need to register again.

Troubleshooting

Cannot Connect to a Tailscale Host

Check that:

  • The target device is online.
  • Tailscale shows Connected.
  • The Host address is correct.
  • If Redock shows “Registration may be invalid” and the embedded device was removed from the Tailscale admin console, create a new Auth Key and choose “Clear identity and register again.”

Tailscale Does Not Work While Another VPN Is Active

You do not need to open the Tailscale app. If registration or startup times out, temporarily disable the other VPN or proxy, retry in Redock, and re-enable it after the embedded node reaches Running.

Try Redock while following this guide

Steer terminal coding agents on your own host, right from your phone.