Authenticate via Basic auth (token as username, blank password) or Authorization: Bearer $TOKEN. No request body.
Response: 200 on success.
Official docs: https://tailscale.com/api (OpenAPI spec at https://api.tailscale.com/api/v2?outputOpenapiSchema=true).
Known gotchas
The device must belong to the requesting user's own tailnet — deleting devices merely shared into the tailnet (node sharing) is not supported.
Deletion is distinct from expiring the node key: a deleted device must fully re-register (tailscale up) to rejoin, whereas an expired device just re-authenticates.
Give your agent this knowledge — and 15,500+ more routes
One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp
Need this verified for your stack — or a route we don't have yet?