Headscale Admin

Not just the Headscale web interface

# single binary# supervises headscale# OIDC SSO# TOTP 2FA# PassKey
Features

Everything in one binary

Free
No fees, no restrictions, no telemetry, you get everything we have. Not open source yet, sorry, but we are considering this possibility in the future :)
Supervised headscale
Downloads headscale release, prepare its config, database and keys, and supervises the process. No separate headscale to install or run.
Single-port front + TLS
One public listener for admin, headscale and gRPC control endpoint with terminates TLS — self-signed, your own cert, or Let's Encrypt.
OIDC SSO
Use your OIDC identity provider for auth to admin panel.
Local 2FA & passkeys
Without OIDC, accounts use email + password with optional TOTP two-factor and WebAuthn passkeys for passwordless sign-in.
Visual ACL editor
Edit groups, tag owners, hosts, auto-approvers, ACL rules, grants and SSH visually or as raw HuJSON — with a live access-map graph of who can reach what.
One-click upgrades
Move the supervised headscale to a new release from the UI: checksum-verified, restarts headscale, and auto-reverts on failure.
External user sync
Fill ACL group members from JumpCloud, Authentik, Keycloak or LDAP via the integrated headscale-pf, with a diff preview before you apply.
Audit log
Record of every state-changing action via admin panel.
Backups
Full backup with one click.
The UI

Full Headscale feature UI

headscale-admin · /admin The headscale-admin dashboard: nodes, users, control-server status and recently added machines