27.06.2026
Tailscale Pricing 2026: When Self-Hosting Headscale or NetBird Beats Seat Pricing
Two news items reshaped the market for modern mesh VPNs in 2026. Tailscale overhauled its pricing and now bills business plans per seat. And NetBird,...
WZ-IT installs and operates Headscale as a self-hosted control server. We integrate OIDC, ACLs, DNS, subnet routers and DERP into your network and identity architecture and handle monitoring, backups and updates.
The following are trademarks of their respective owners: Headscale (the Headscale project (Juan Font Alonso)), Tailscale (Tailscale Inc.). WZ-IT is an independent service provider and has no business, partnership, or contractual relationship with these companies. We offer independent migration, installation, hosting, and operations services.

Headscale is a self-hosted, open-source implementation of the Tailscale control server. With complete control over your VPN network, Headscale provides a secure alternative for organizations of any size.
As a self-hosted solution, Headscale implements the same features as Tailscale but without external dependencies. The solution supports modern VPN technologies, Access Control Lists (ACLs), and Single Sign-On (SSO) integration.
We install, host and operate Headscale for your company - either on our secure, privacy-focused infrastructure in Germany or other locations, as well as on-premise in your own environment.
We provide 24/7 monitoring, backups and maintenance for your Headscale instance. Human response times and support coverage follow the selected service level.
Run your own Tailscale control server with complete control over your network infrastructure.
Granular network access controls with tag-based authorization and group management.
OIDC integration with Keycloak, Active Directory, Google, Azure AD, and other identity providers.
Route all internet traffic through designated exit nodes for secure external connections.
Automatic DNS resolution for VPN hosts and custom DNS records for internal services.
Complete REST API for node management, ACL administration, and network configuration.
Professional installation on your infrastructure - on-premise, cloud or hybrid
In your data center
AWS, Azure, Hetzner & more
Advanced architecture after technical and licence assessment
Secure access and access control for your installation
WireGuard, NetBird or Tailscale
Directly or through an upstream identity layer
Depends on application, edition and identity provider
Fail2Ban, Rate Limiting, IP Whitelisting
We set up secure VPN access to your installation - ideal for remote work and external employees.
Full-service installation with no hidden costs
Headscale is the open-source implementation of the Tailscale control server (BSD-3-Clause, around 41,000 GitHub stars). The official Tailscale clients connect to your server via "tailscale up --login-server"; the project aims to support the last 10 client releases. What you can expect from it - and what not:
For an honest assessment: the project's README describes its own scope as deliberately narrow - a single Tailscale network (tailnet), suitable for personal use or a small organisation. You should know these limits before planning Headscale company-wide.
A clearly defined operating scope instead of an opaque hosting flat fee.
We combine the right compute size with ongoing operations, backups, monitoring and a service level appropriate for the criticality of Headscale. High availability and recovery targets are designed separately where needed.
We also design custom hosting architectures, integrations and migrations around Headscale. Contact us for a technical assessment.
One managed standard Headscale application is included in the Starter workload. Every service level also includes flexible expert time for planned work during regular service hours. Select compute, additional applications, storage and the appropriate service level.
A workload is one compute instance with the applications agreed for it.
One standard app per workload is already included. Additional dedicated servers count as separate workloads.
€79.90 per started TB and month, including daily encrypted offsite backup with 7-day retention.
Briefly describe the current state and objective for Headscale. We assess infrastructure, integration, and ongoing operations.
A trust fact on the side: Headscale is "not associated with Tailscale Inc.", but Tailscale employs the head maintainer (without directing the project) and actively helps maintain compatibility of the official clients. Headscale fits when:
NetBird is a standalone product with its own dashboard, user and group management and access policies - designed from the start as a fully-fledged self-hosted platform. If your setup grows beyond a single tailnet or you need a central management interface, NetBird is usually the better fit. We will advise you honestly on which approach suits your environment.
View NetBirdNo. Headscale is an independent open-source project and, per its own README, "not associated with Tailscale Inc.". Worth knowing for context: Tailscale employs the project's head maintainer (without directing or steering the project) and helps maintain compatibility of the official clients - an unusually cooperative relationship.
Yes. The official Tailscale clients for Windows, macOS, Linux, iOS and Android connect to your own Headscale server via "tailscale up --login-server <URL>". The project aims to support the last 10 Tailscale client releases.
Not or only partially supported are Funnel (publicly exposing services), Serve and network flow logs; additionally, OIDC groups cannot be used in ACLs. Headscale also manages exactly one tailnet - multi-tenant setups are not supported. Supported, on the other hand, are MagicDNS, split DNS, Taildrop, tags, subnet routers, exit nodes, ACLs, auto approvers, Tailscale SSH and OIDC registration.
The project deliberately positions itself with a narrow scope in its README: a single tailnet, suitable for personal use or a small organisation. In practice this means: for smaller teams with a clear setup, Headscale is an excellent choice. If you need a larger self-hosted setup with its own dashboard and policy management, take a look at NetBird.
Headscale is published under the BSD-3-Clause licence and the project does not maintain a separate commercial feature tier. Before production use, we still verify the current release, compatibility with the deployed Tailscale clients and the required operational capabilities.
Yes. We install and operate Headscale on your infrastructure or on European servers - including OIDC integration, ACL design, monitoring, updates and backup. Control and coordination data remain fully under your sovereignty.
In-depth knowledge from our remote access knowledge base.
27.06.2026
Two news items reshaped the market for modern mesh VPNs in 2026. Tailscale overhauled its pricing and now bills business plans per seat. And NetBird,...
11.05.2026
A Cisco ASA vulnerability from September 2025 is still being actively exploited in May 2026. Seven months after the patch, CrowdSec counts 292 source IPs...
These solutions are often used together with Headscale
These solutions offer similar functionalities and can be evaluated together
These solutions are direct alternatives with similar use cases
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.
Timo Wevelsiep & Robin Zins
Managing Directors of WZ-IT
