Ducktails is a zero-config mesh VPN for humans and autonomous agents. Connect any device, server, or AI worker into one private network in under 60 seconds. The infrastructure Tailscale forgot to build.
Every feature earns its place. No bloat, no "AI-enhanced" marketing slop. Just the networking primitives modern teams and agents actually need.
One curl command. Sign in with Google, GitHub, or SSO. Devices find each other automatically. Never edit a config file again.
Built on WireGuard®. Traffic never decrypts on our servers. We run zero logs. We literally can't read your data.
Direct peer-to-peer when possible, relayed when not. NAT, corporate firewall, hotel wifi — your mesh stays up.
Every autonomous worker gets its own network identity, ACL, and audit trail. Kill a rogue agent with one click. See every connection it made, every resource it touched, every second of its life on your network. This is what Tailscale doesn't give you.
Stop writing YAML at midnight. Describe access rules the way you'd tell a teammate: "dev-team can SSH to staging servers, not prod." We compile it to secure policy automatically.
Don't trust us? Run our control plane on your own hardware. No "call sales." No enterprise gate. Open source clients.
macOS, Windows, Linux, iOS, Android, Docker, Kubernetes sidecar. Your laptop, your phone, your prod cluster — all on the same tail.
Every connection. Every denial. Every ACL change. Exportable to Datadog, Splunk, S3. SOC 2 auditors love us. You will too.
REST, gRPC, CLI, Terraform provider. Provision mesh nodes programmatically. GitOps your entire network topology.
Your whole fleet — laptops, servers, containers, AI agents — reachable by name, encrypted end-to-end, in the time it takes to make coffee.
Run curl -fsSL ducktails.ai/install | sh. Sign in with your existing IdP — Google, GitHub, Microsoft, Okta. You're on the tail.
Same command, same login. The devices find each other through our coordination server and open a direct encrypted tunnel. No IPs to memorize.
SSH to your home server from anywhere. Reach your prod DB from your phone. Let your AI agent hit a private API. ducktails ping nas-home — done.
Tag devices, write ACLs in plain English, provision agents via API. Your network grows from 3 nodes to 3,000 without adding complexity.
In 2026 your infrastructure isn't just humans anymore. It's browsers, scrapers, autonomous workers, and LLM-driven agents spawning in milliseconds, hitting APIs, mutating databases, and dying. They need their own identity model. We built it.
Every autonomous worker gets a unique network identity — not a shared service account. Revoke one without touching the others.
Which agent hit which endpoint at which time with which response code. Exportable, queryable, forever.
Model hallucinating? Rate-limit blown? Cost runaway? One click disconnects an agent from your entire mesh. Instantly.
Spin up 500 agents for a job, tear them down after. No residual credentials, no stale ACL entries, no cleanup.
Cap bandwidth, request volume, or destination scope per agent. Stop one rogue worker from nuking your AWS bill.
Describe agent permissions in English. Our compiler turns "allow scraper to read, not write" into verified policy.
Honest pricing you can read in 30 seconds. Every plan includes every feature. The price scales with your fleet, not your anxiety. Cancel anytime.
Private beta is rolling out now. Drop your email and we'll send you an invite this week. No spam, no marketing drip — just access.