Support

We answer, quickly

In-app chat for admins, a public KB, and humans who run tailnets themselves.

The KB and forum are free for everyone

Support isn't a paywall. The public knowledge base, the forum, and the docs cover the majority of issues on every plan — including free. Paid plans buy response-time commitments and named humans, not hidden answers.

  • ✓Every KB article, doc, and changelog: public, always
  • ✓Paid tiers add response targets, not gated content
  • ✓Sev-1 on Enterprise: one hour, 24×7, humans on the hook
what each tier adds
freekb + forum, community pacebest effortPUBLIC
starteremail queue2 bdEMAIL
premiumemail + in-app chat1 bdIN-APP
enterpriseshared slack, csm1 h sev-124×7

Tickets open with diagnostics attached

When you file from the admin console, the ticket carries your tailnet's recent state — node names, connection status output, the last policy change — with sensitive fields redacted. The first reply answers the question instead of asking for it.

# what support already sees on open
tailnet acme-corp · premium · 214 nodes
nodes build-01 ↔ db-prod, relayed
policy last change 2026-08-14, by devops
redacted keys, secrets, payload — never sent
 
# your ticket: what were you trying to do?

By plan

PlanChannelFirst responseCoverage
FreeCommunity forum + KBBest effortCommunity-driven
StarterEmail2 business daysBusiness hours
PremiumEmail + in-app1 business dayBusiness hours
EnterpriseShared Slack channel1 hour, 24×7 for Sev-1Named CSM + escalation path

Plan details →

Route your issue

Technical

Connectivity, ACLs, clients — open a ticket or chat in-app with your node diagnostics attached.

Open ticket →

Billing & accounts

Plans, invoices, seats — billing handles these in the same queue, priority-separate.

Contact billing →

Security

Vulnerability reports go to the disclosure channel, never public forums.

Responsible disclosure →

Before you file

Sixty seconds of prep makes tickets resolve twice as fast.

  • ✓Run openvlan status on both ends, include the output
  • ✓Note the node names and what changed recently
  • ✓Check the status page for incidents first
  • ✓Search the KB — the top 20 answers live there

Current system status →

Support FAQs

What counts as Sev-1?
Tailnet-wide outages: nobody can connect, authentication is failing, or the coordination plane is down. A single user's flaky hotel wifi is not Sev-1 — it's a ticket, and a fast one, but it doesn't page anyone's phone.
Do you help with rollout planning?
Enterprise plans include a guided rollout with an engineer — pilot design, IdP wiring, and the decommission plan. Everyone else gets the same playbook in the docs and the migration blog series, which is what the guided version follows.
Can support make changes to our tailnet for us?
We advise; you apply. Support can review your ACL file, suggest the fix, and dry-run it with you on a call — but changes to your production network come from your keys. It's the same separation your auditors want.
Is there a status page for incidents?
Yes — current system status, incident history, and per-component uptime at 90 days and trailing 12 months. Enterprise tenants can subscribe to webhook alerts that feed their internal chat.
What response times do you actually hit?
Targets are commitments, not aspirations: we publish actual response-time attainment by plan each quarter. Last quarter it was 100% for Enterprise Sev-1, 97% for Premium first response — the misses and their post-mortems are in the same report.

Stuck right now?

The KB covers the 20 questions that make up 80% of tickets.