Everything in the admin console is scriptable. Generate an API key, point at the endpoint below, and manage your tailnet as code.
API keys are bearer tokens with granular scopes — read-only, devices, ACLs, or keys. A CI pipeline gets a key that can enroll nodes and nothing else; your Terraform runner gets one that can push policy. Both expire on a schedule you set.
Nothing reaches your tailnet half-parsed. PUT a malformed or over-permissive ACL and the API rejects it with the offending line — the dry-run endpoint lets your CI test a policy change the same way it tests code.
| Method | Path | Description |
|---|---|---|
| GET | /v1/devices | List nodes; filter by user, tag, or online state |
| GET | /v1/devices/{id} | Node detail: addresses, routes, last-seen |
| DELETE | /v1/devices/{id} | Remove a node and revoke its keys |
| POST | /v1/devices/{id}/tags | Apply or replace tags |
| GET | /v1/users | List tailnet users and their roles |
| GET | /v1/acl | Fetch the current ACL policy |
| PUT | /v1/acl | Replace the policy (validated before applying) |
| POST | /v1/acl/validate | Dry-run a policy without applying it |
| GET | /v1/keys | List auth keys |
| POST | /v1/keys | Create a scoped, expiring auth key |
| GET | /v1/routes | List advertised subnet routes and approval state |
| POST | /v1/routes/{id}/approve | Approve a pending subnet route |
| GET | /v1/logs/connections | Paginated connection audit log |
Copy, paste, adjust the variables.