openapi: 3.1.0 info: title: Tailscale REST Devices Policy API description: 'REST API for managing Tailscale tailnets, devices, users, ACL policy, DNS, keys, logging, and user/device invites. Authenticated via HTTP Basic Auth with the API token as the username, Bearer token, or OAuth client credentials with scoped access. Source: https://api.tailscale.com/api/v2 (OpenAPI), https://tailscale.com/api' version: '2' contact: name: Tailscale url: https://tailscale.com/api servers: - url: https://api.tailscale.com/api/v2 description: Production security: - BearerAuth: [] - BasicAuth: [] tags: - name: Policy paths: /tailnet/{tailnet}/acl: parameters: - name: tailnet in: path required: true schema: type: string get: tags: - Policy summary: Get ACL policy file operationId: getAclPolicy responses: '200': description: OK post: tags: - Policy summary: Set ACL policy file operationId: setAclPolicy responses: '200': description: OK /tailnet/{tailnet}/acl/validate: parameters: - name: tailnet in: path required: true schema: type: string post: tags: - Policy summary: Validate ACL policy file operationId: validateAclPolicy responses: '200': description: OK components: securitySchemes: BearerAuth: type: http scheme: bearer description: Tailscale API access token (prefixed "tskey-api-") passed in the Authorization header. Tokens are created in the admin console with 1-90 day expiry, or via OAuth client credentials with scopes. BasicAuth: type: http scheme: basic description: HTTP Basic Auth with the access token as the username and an empty password.