How to integrate Tailscale MCP with Hermes

Connect Hermes to Tailscale MCP. List all devices in your tailnet, create a new access policy rule, and more using natural language, with authentication handled for you.

Tailscale logoTailscale
Api Key

Tailscale is a secure networking platform to manage tailnets, devices, users, DNS, and access policies. It simplifies secure connectivity and centralized access control across distributed infrastructure.

10 Tools

Introduction

Hermes is a 24/7 autonomous agent that lives on your computer or server — it remembers what it learns and evolves as your usage grows.

This guide explains the easiest and most robust way to connect your Tailscale account to Hermes. You can do this through either Composio Connect CLI or Composio Connect MCP. For personal use we recommend the CLI, but you won't go wrong with MCP either.

Also integrate Tailscale with

What is Composio Connect?

Composio Connect is a consumer offering that lets anyone plug 1,500+ applications directly into their agent harness — including Hermes. It can:

  • Search and load tools from relevant toolkits on-demand, reducing context usage.
  • Chain multiple tools to accomplish complex workflows via a remote workbench, without excessive back-and-forth with the LLM.
  • Manage app authentication end-to-end with zero manual overhead.

Integrating Tailscale with Hermes

Using Composio Connect CLI

1. Install the Composio CLI

Run the install script directly, or paste https://composio.dev/hermes into your Hermes chat box to have it installed for you.

bash
curl -fsSL https://composio.dev/install | bash
Hermes authenticating with Composio

2. Authenticate

Once the CLI is installed, ask Hermes to authenticate with Composio.

3. Connect to Tailscale

Ask your agent to connect to Tailscale, or simply request any Tailscale-related task. Hermes will prompt you to authenticate and authorize access.

4. Done. You're all set with a new Tailscale connection.


Using Composio Connect MCP

1. Get your MCP URL and API Key

Go to dashboard.composio.dev and copy your Connect MCP URL and API key.

Copy MCP URL and API key from Composio dashboard

2. Open the Hermes config file

bash
nano ~/.hermes/config.yaml

3. Add the Composio Connect MCP server

bash
mcp_servers:
  composio:
    url: "https://connect.composio.dev/mcp"
    headers:
      x-consumer-api-key: "YOUR_COMPOSIO_API_KEY"
    connect_timeout: 60
    timeout: 180

Save with Ctrl + O, Enter, then exit with Ctrl + X.

4. Restart your Hermes agent

Once restarted, ask your agent to connect to Tailscale or request any Tailscale-related task. It will prompt you to authenticate and authorize access.

5. Done!

What is the Tailscale MCP server, and what's possible with it?

The Tailscale MCP server is an implementation of the Model Context Protocol that connects your AI agent and assistants like Claude, Cursor, etc directly to your Tailscale account. It provides structured and secure access so your agent can perform Tailscale operations on your behalf.

Way Forward

With Tailscale connected, Hermes can now act on your behalf whenever it detects a relevant task or you ask it to.

From here, you can extend Hermes further:

  • Connect more apps: Calendar, Slack, Notion, Linear, and hundreds of others are available through the same Composio Connect setup. Each new integration compounds what Hermes can do for you.
  • Build workflows across tools: Once multiple apps are connected, Hermes can chain actions together — turn an email into a calendar invite, a Slack message into a Linear ticket, or a meeting note into a follow-up draft.
  • Let it learn your patterns: The more you use Hermes, the better it gets at anticipating how you'd handle recurring tasks. Give it feedback on drafts and decisions, and it will adapt.

If you run into trouble or want to share what you've built, join the community or check out the Docs for deeper configuration options.

TOOLS

Supported Tools

Every Tailscale action and event your agent gets out of the box.

Get Device

Get the full current record for one manageable Tailscale device by ID.

Get DNS Configuration

Return the selected tailnet's combined MagicDNS, nameserver, search-path, and split-DNS configuration.

Get Tailnet Settings

Return current tailnet-wide approval, update, key-duration, HTTPS, routing, logging, and posture settings.

List Configuration Audit Logs

Return configuration audit events for an explicit RFC3339 time window in the selected tailnet, optionally filtered by actor, target, or event name.

List Device Routes

Return the subnet routes advertised and currently enabled for a Tailscale device.

List Tailnet Devices

Return all devices in the selected tailnet, including identifiers, names, addresses, tags, authorization state, and connectivity metadata.

List Users

Return users in the selected tailnet, optionally filtered by membership type or role.

Set Device Authorization

Approve or revoke approval for one device when device approval is enabled on the tailnet.

Set Device Routes

Replace the enabled subnet routes for one device with an explicit list of routes.

Set Device Tags

Replace all ACL tags assigned to one Tailscale device.

FRAMEWORKS

How to build Tailscale MCP Agent with another framework

FAQ

Frequently asked questions

With a standalone Tailscale MCP server, the agents and LLMs can only access a fixed set of Tailscale tools tied to that server. However, with the Composio Tool Router, agents can dynamically load tools from Tailscale and many other apps based on the task at hand, all through a single MCP endpoint.

Yes, you can. Hermes fully supports MCP integration. You get structured tool calling, message history handling, and model orchestration while Tool Router takes care of discovering and serving the right Tailscale tools.

Yes, absolutely. You can configure which Tailscale scopes and actions are allowed when connecting your account to Composio. You can also bring your own OAuth credentials or API configuration so you keep full control over what the agent can do.

All sensitive data such as tokens, keys, and configuration is fully encrypted at rest and in transit. Composio is SOC 2 Type 2 compliant and follows strict security practices so your Tailscale data and credentials are handled as safely as possible.

Start with Tailscale.It takes 30 seconds.

Managed auth, hosted MCP servers, and every Tailscale tool your agent needs.Free to start.

Start building