Tailscale Key Expiry !!better!!
To rotate Tailscale keys:
Auth keys created via the Tailscale admin console or CLI use these defaults unless overridden. tailscale key expiry
Admins can go to the Machines page and select Temporarily extend key . This restores connectivity for 30 minutes , allowing you to log in and either re-authenticate the device or permanently disable its expiry. To rotate Tailscale keys: Auth keys created via
Click the menu on the right and select Disable Key Expiry . Changing the Global Expiry Period Click the menu on the right and select Disable Key Expiry
By understanding and actively managing , you can significantly improve your tailnet's security posture while enabling smooth automation and device lifecycle management.
You can disable expiry for specific devices, which is highly recommended for servers, subnet routers, or remote machines.
Yes, node keys rotate automatically every ~24 hours. This is seamless and requires no action.

