Aperture GA: Building a home(lab) for agentic AI Tailscale announced the general availability of Aperture, its AI gateway for agentic AI, which now includes initial tokens for new instances, MCP endpoints for tailnet control, and an upgraded chat experience with Projects and fine-grained tool permissions. The company aims to provide an 'it just works' experience for individuals and homelab enthusiasts while maintaining identity-aware networking and safety. We started building Aperture 10 months ago to demonstrate that you don’t need to choose between ease of use, identity-aware networking, and robust safety when using agentic AI with Tailscale. Our solution started as an LLM proxy https://tailscale.com/blog/aperture-private-alpha that eliminated the need to distribute API keys to both engineers and agents connected to your tailnet. Since then, it has grown into a comprehensive AI gateway, with countless visibility and control features for enterprises. These include cost controls https://tailscale.com/blog/aperture-public-beta , request and response hooks, guardrails, extensive logging, and even a full MCP Model Context Protocol and API proxy, keeping even more keys away from agents and people. With today’s general availability GA announcement, however, we want to go back to the roots of Tailscale, focusing on something that provides an “it just works” experience for individuals and homelab enthusiasts. So we’re also announcing a handful of new features, including: - Purchasing tokens through Aperture - MCPs for controlling your tailnets and the devices on them - An upgraded chat experience ~~Batteries~~ Tokens included We believe the future of cost-effective AI use involves experimenting with different models from many different labs. In particular, open-weight models are becoming increasingly prevalent and powerful, but they can still be difficult to use and require large upfront investments. Until now, bringing open-weight models into your Aperture instance required either a third-party API key or enough expensive hardware to route state-of-the-art self-hosted models through Aperture. Today, each new Aperture instance comes with some initial tokens included. You can also buy more for any major model, both open-weight and closed, directly inside of Aperture. Whether you bring your own subscriptions https://tailscale.com/blog/aperture-ai-passthrough-subscription-costs and API keys, or use tokens sourced through Tailscale, our goal is simple: we want you to be productive with AI as quickly as possible. Controlling the tailnet via MCP controlling-the-tailnet-via-mcp Administrating a homelab or any network with or without AI in the mix can range from fun to Sisyphean. For the times when you’re pushing that boulder uphill, we’ve added two new MCP endpoints, Tailscale and Tailscale SSH. They make it easier for Aperture and coding agents to add new nodes to your tailnet, as well as access them via Tailscale SSH https://tailscale.com/docs/features/tailscale-ssh . This is useful in situations where, for example, you want an agent to deploy a service to a node in your tailnet that you want to access remotely, or share with others. With MCP access, the agent can prompt you for access and, once approved, configure the service without manually copying keys and filling in environment variables. Before you get too anxious about an agent doing all of this, I’d like to point out three things. First, Tailscale’s unidirectional access control rules are in effect: Aperture — and any agents working through it — must respect them, so you can control exactly which machines can talk to Aperture and vice versa. Second, you approve every machine Aperture wants to add to your tailnet. Third, there’s a clear audit trail, because all of your agent’s actions are logged. We hope these new MCPs allow you to hold onto the fun parts of homelabbing, while handing the fiddly YAML and other brittle configuration tasks to an LLM with constraints you control. Chat gets projects and fine-grained tool permissions chat-gets-projects-and-fine-grained-tool-permissions Since we announced the chat interface built into Aperture https://tailscale.com/blog/ai-without-lock-in , we’ve received tons of feedback on how it could better work with your data and your devices. That’s why we’ve added Projects, and customized default tool permissions. Projects lets you group chats, with shared initial contexts instructions , tool access, and tailnet nodes among them. You spend less time prompting each chat with the outline and goals of your project. You can expand tool access beyond your defaults, or rein it in for trickier work. And you don’t have to tell an LLM how to access your NAS; the NAS is present as a Tailscale node, and the LLM can reach it in your tailnet if your access control rules allow it. The second major addition is the ability to define default tool permissions for everything exposed in Aperture. We’ve been trying to strike the balance between the added predictability that comes with specifying every tool for every chat, and the serendipity that comes when the LLM has broad access to tools. Now you can set defaults that make sense for your own use, carried across all chats. What’s next and getting started with Aperture whats-next-and-getting-started-with-aperture We don’t know what the future holds when it comes to agentic AI, but we know it demands the right balance of flexibility and security, supporting use cases people can only dream up in the coming days, weeks, and months. If you’d like to go on this journey with us and use Aperture to control and extend your AI agents, you can add it to your tailnet today https://aperture.tailscale.com/ . As always, we appreciate and read all of the feedback you submit, so let us know what you think by using the feedback form in Aperture, or emailing us at aperture@tailscale.com mailto:aperture@tailscale.com .