How to connect Tailscale MCP with ChatGPT Work

Connect ChatGPT Work to Tailscale MCP. List all devices in your tailnet, create a new access policy rule, and more using natural language, with authentication handled for you.

Tailscale logoTailscale
Api Key

Tailscale is a secure networking platform to manage tailnets, devices, users, DNS, and access policies. It simplifies secure connectivity and centralized access control across distributed infrastructure.

10 Tools

How to connect Tailscale MCP with ChatGPT Work

ChatGPT Work is an agent inside ChatGPT built for your most ambitious work. It takes action across your apps and files, stays with a project for hours, and turns a goal into finished materials like sheets, slides, and docs - not just answers.

In this guide, I will explain the easiest and most secure way to connect your Tailscale account to ChatGPT Work via Composio Connect, so it can list tailnets, inspect your devices, update access policies, manage DNS records, and register services through natural language commands without ever putting your account credentials at risk.

Also integrate Tailscale with

Why use Composio over default connectors?

  • Apps with read and write access. Default connectors mostly can read your data. Composio's Tailscale integration lets ChatGPT Work take actions like creating drafts, sending updates, labeling records, and more.
  • 1,500+ SaaS toolkits out of the box. Composio gives you instant access to a vast catalog of pre-built connectors, from Gmail and Slack to Notion, Linear, and Salesforce.
  • One MCP server for every app. Connect any of your applications on demand through a single endpoint, rather than juggling a separate server for each app.
  • Smart, context-aware tool loading. Unlike traditional MCP servers that dump every available tool into the LLM context window, Composio searches for and loads only the tools relevant to the task at hand.
  • Cross-app automation. Chain actions across multiple apps in a single run - fetch a thread, summarize it in Notion, and post highlights to Slack without leaving the conversation.

Prerequisites

  • A ChatGPT account with access to ChatGPT Work (rolling out across Pro, Enterprise, Edu, Plus, and Business plans). We will use the ChatGPT desktop app, which is available on every plan.
  • Access to the Tailscale workspace you want to connect.
  • Composio MCP.

Note: Composio connects through OAuth. You will be asked to sign in and approve specific permissions. Review the permission screen carefully if you are using a work account.

Step-by-step: Connect Tailscale to ChatGPT Work

1. Open the MCP settings

In ChatGPT Work, go to Settings and open the Plugins section. Inside the Plugins page, click the MCP tab.

ChatGPT Work settings showing the Plugins page with the MCP tab selected

2. Add the server

Click Add server. In the Name field enter Composio, for Type select Streamable HTTP, and in the URL field paste the Composio MCP server URL:

bash
https://connect.composio.dev/mcp
ChatGPT Work Add server dialog with the name Composio, type Streamable HTTP, and the Composio MCP URL

Then click Save. The Composio server now appears in your MCP plugins list.

ChatGPT Work Plugins page showing the Composio MCP server added to the list

3. Authenticate

Click Authenticate, log in via Composio, and click Allow access to authorize ChatGPT Work to use your Composio account.

Composio login and Allow access screen for ChatGPT Work MCP setup

4. Start using Composio

That is it - Composio tools are now available in ChatGPT Work. Ask it to work with your Tailscale account and it will run the actions you authorize.

What you can do after connecting Tailscale

  • List all devices in your tailnet
  • Create a new access policy rule
  • Add DNS entry for service on tailnet

Security + privacy notes (important)

  • Use least-privilege access: Only grant permissions you actually need.
  • Review OAuth permissions before approving: Make sure requested scopes match what you expect Composio and ChatGPT Work to do.
  • Keep write actions human-reviewed: For actions like sending messages, creating labels, or editing drafts, keep manual confirmation enabled.
  • Be careful with sensitive data: Avoid using this setup with highly sensitive information unless allowed by your personal, company, or client policies.
TOOLS

Supported Tools

Every Tailscale action and event your agent gets out of the box.

Get Device

Get the full current record for one manageable Tailscale device by ID.

Get DNS Configuration

Return the selected tailnet's combined MagicDNS, nameserver, search-path, and split-DNS configuration.

Get Tailnet Settings

Return current tailnet-wide approval, update, key-duration, HTTPS, routing, logging, and posture settings.

List Configuration Audit Logs

Return configuration audit events for an explicit RFC3339 time window in the selected tailnet, optionally filtered by actor, target, or event name.

List Device Routes

Return the subnet routes advertised and currently enabled for a Tailscale device.

List Tailnet Devices

Return all devices in the selected tailnet, including identifiers, names, addresses, tags, authorization state, and connectivity metadata.

List Users

Return users in the selected tailnet, optionally filtered by membership type or role.

Set Device Authorization

Approve or revoke approval for one device when device approval is enabled on the tailnet.

Set Device Routes

Replace the enabled subnet routes for one device with an explicit list of routes.

Set Device Tags

Replace all ACL tags assigned to one Tailscale device.

FRAMEWORKS

How to build Tailscale MCP Agent with another framework

FAQ

Frequently asked questions

With a standalone Tailscale MCP server, the agents and LLMs can only access a fixed set of Tailscale tools tied to that server. However, with the Composio Tool Router, agents can dynamically load tools from Tailscale and many other apps based on the task at hand, all through a single MCP endpoint.

Yes, you can. ChatGPT Work fully supports MCP integration. You get structured tool calling, message history handling, and model orchestration while Tool Router takes care of discovering and serving the right Tailscale tools.

Yes, absolutely. You can configure which Tailscale scopes and actions are allowed when connecting your account to Composio. You can also bring your own OAuth credentials or API configuration so you keep full control over what the agent can do.

All sensitive data such as tokens, keys, and configuration is fully encrypted at rest and in transit. Composio is SOC 2 Type 2 compliant and follows strict security practices so your Tailscale data and credentials are handled as safely as possible.

Start with Tailscale.It takes 30 seconds.

Managed auth, hosted MCP servers, and every Tailscale tool your agent needs.Free to start.

Start building