Join us live on August 26 in San Francisco for TailscaleUpTICKETS ON SALE NOW ->
  • Blog
  • Docs
  • Download
  • Contact sales
  • Meet Tailscale

    • How Tailscale Works
    • WireGuard® for Enterprises
    • Features
    • Integrations
    • Docs
    • Download
    • Compare Tailscale

    Products

    • Business VPN
    • PAM
    • CI/CD Connectivity
    • Secure Access to AI
    • Workload Connectivity
    • Edge & IoT
    • Homelab
    aperture dashboard

    Aperture by Tailscale

    Unified AI governance for AI agents and users.

    Join us at TailscaleUp

    Tailscale’s conference for engineering, security, and IT leaders.

    Learn more
  • Solutions

    • Cloud Connectivity
    • Infrastructure Access
    • Zero Trust Networking
    • Remote Access
    • Kubernetes Networking
    • Secure SaaS
  • Customer Stories

    • Instacart
    • Cribl
    • Mercury
    • Hugging Face
    • All Customer Stories
  • Join the Community

    • About Community
    • Tailscale Insiders
    • Community Projects
    • Bring Tailscale to Work

    Events

    • Events and Webinars
    • TailscaleUp

    Learn more

    • Docs
    • Blog
    • Changelog
    • Press

    Join us at TailscaleUp

    Tailscale’s conference for engineering, security, and IT leaders.

    Learn more
  • Partner Opportunities

    • Become a Partner
    • Community Projects
    • Integrations
    • Contact Partnerships Team
  • Pricing
  • Login
  • Get started - it's free!
  • Blog
  • Docs
  • Download
  • Contact sales
Platform

Meet Tailscale

  • How Tailscale Works
  • WireGuard® for Enterprises
  • Features
  • Integrations
  • Docs
  • Download
  • Compare Tailscale

Products

  • Business VPN
  • PAM
  • CI/CD Connectivity
  • Secure Access to AI
  • Workload Connectivity
  • Edge & IoT
  • Homelab
Solutions

Solutions

  • Cloud Connectivity
  • Infrastructure Access
  • Zero Trust Networking
  • Remote Access
  • Kubernetes Networking
  • Secure SaaS
Customers

Customer Stories

  • Instacart
  • Cribl
  • Mercury
  • Hugging Face
  • All Customer Stories
Community

Join the Community

  • About Community
  • Tailscale Insiders
  • Community Projects
  • Bring Tailscale to Work

Events

  • Events and Webinars
  • TailscaleUp

Learn more

  • Docs
  • Blog
  • Changelog
  • Press
Partnerships

Partner Opportunities

  • Become a Partner
  • Community Projects
  • Integrations
  • Contact Partnerships Team
Pricing
  • Login
  • Get started - it's free!

Company

  • About Tailscale
  • Careers
  • Press
  • Open Source

Help & Support

  • Support
  • Sales
  • Partnerships
  • Security
  • Changelog
  • Tailscale Status

Legal

  • Terms of Service
  • Privacy Policy
  • California Notice
  • Cookie Notice
  • All Legal

Social

  • Discord
  • GitHub
  • LinkedIn
  • Mastodon
  • Reddit
  • YouTube
  • X (Twitter)
© 2026 Tailscale Inc.
Tailscale is a registered trademark of Tailscale Inc. | WireGuard is a registered trademark of Jason A. Donenfeld

Securing AI

Bring AI usage into focus with Aperture by Tailscale

The unified AI governance solution that gives a clear picture of how you’re using AI and what it costs.

Get started
Screenshots showing the Aperture personal view dashboard page and logs page.
Leaderboard showing LLM token usage across the organization.

Visibility and auditability for every AI interaction

Everyone is adopting AI, but now it’s time to understand what you’re using it for, who is using it, and how it is being managed. Log every AI interaction and attribute it to an identity. Audit trails are available day one: know exactly who is calling which models, when, and how many tokens are used.

Get started
Logs in Aperture

Cut through the blur of fragmentation and sprawl

Declutter from rapid AI adoption’s collection of tools, providers, and credentials with no central inventory, no consistent access controls, and no single place to make changes. Aperture by Tailscale has an endpoint for each provider, centralized inventory, and access tied to identity instead of keys.

Get started

Develop with your preferred agents

Aperture by Tailscale supports major agents like Claude Code, Codex, Gemini CLI and agent frameworks that support a custom base URL. Connect self-hosted OSS models and hosted models from OpenAI, Anthropic, and Google.

Tool use graphs in Aperture

AI governance without a separate identity system

Close the governance gap with Aperture and Tailscale as the trust boundary

A complete inventory of what is calling what

Every request is logged with the identity of the caller, the model called, the provider, the timestamp, and the token count.

Write one policy for every environment

Apply your policy to every AI call across your organization. Updates take effect immediately across all teams and environments. No redeployment required.

Access by identity, not shared credentials

Authenticate with Tailscale’s network identity, not credentials you need to distribute and manually rotate that may leak.

One endpoint for every provider

With credentials for every provider in one place, adding a new provider is a configuration change, and revoking access is one policy update.

The same access model across every environment

The same identity in a development environment gets the same policy in production. No more environment-specific credential management.

Remove recurring operational debt

Access to AI is granted through policy. Define it once to control which users, teams, or automated systems can call which models, at what rate, and with what controls.

Rate limits and spend caps

Define token and request rate limits per agent, per team, or across the organization.

Control which models each identity can call

Prevent a team from using a high-cost model in contexts where a lower-cost model would work. Add new providers only with procurement approval.

Policy as an enforcement layer for AI usage

Enforce your organization's AI usage policy at every request. IT defines what is sanctioned. Aperture applies it automatically.

Questions and answers

How can Aperture not require all the API keys?

With Aperture, you only need a single API key per provider. The gateway uses Tailscale identities to identify connecting users and agents, meaning it’s no longer necessary to distribute keys to individual users.

Does Aperture work with my coding agent or framework?

Aperture works with any coding agent that allows the end user to replace the base URL of the API endpoint. It supports Claude Code, Codex, Gemini CLI, Roo Code, Cline, and others.

How is Aperture priced?

We do not have published pricing during the current Alpha and Beta period. Contact sales to learn more.

Will Aperture be available on the self-serve / free plan?

Aperture is available via self-serve now! You can sign up today.

How do I set up and deploy Aperture?

We’re currently experimenting with multiple deployment options, and supporting Alpha and Beta customers one-on-one. Contact sales to learn more.

Can I export LLM logs from Aperture?

Yes, Aperture currently supports S3 export.

Do I have to use Tailscale to use Aperture?

Aperture can be purchased for use separately from paid Tailscale plans.

Does Aperture work in sandboxed environments?

Yes, as long as it’s possible to run Tailscale. Aperture and Tailscale work in common containerized environments, like GitHub Actions, without needing to expose either the agent or gateway to the public internet.

Does Aperture work with MCP?

Currently, Aperture can extract MCP and local tool calls from popular agents. We are planning to add more fine-grained MCP control.

Does Aperture work with self-hosted (or private) LLMs?

Yes, it’s possible to proxy self-hosted LLMs with Aperture without exposing the endpoints to the public internet.

AI governance,
Without the hassle.

Contact us