Weft Start free trial

Compare · Tailscale

Weft vs Tailscale

Both are built on WireGuard, and both will get you from a laptop to a server. They start from opposite ends: Tailscale connects people and devices, Weft connects places. This page says where each fits, including where Tailscale is the better choice.

The short version

  • Choose Tailscale if what you need is people and their devices reaching servers and each other — including phones — with almost no setup, and your offices are a side concern.
  • Choose Weft if what you need is offices, cloud networks and data centres joined into one routed network, with the office machine acting as the gateway for everything behind it, and changes you can make without fear of breaking every site at once.

Side by side

WeftTailscale
Built forJoining sites: offices, cloud networks, data centres, plus roaming laptopsJoining devices and users into one private network (a "tailnet")
What runs whereThe Weft agent on one Ubuntu 24.04 machine per site, which becomes the site's gateway; apps on laptopsThe Tailscale client on each device, or a Linux subnet router in front of devices that cannot run it
Devices behind a siteReach the fabric through the site's gateway, as they would any router. Weft can be the LANs' gateway itself, with DHCP per network and VLANsNeed a route to the subnet router: Tailscale's site-to-site guide has static routes added on each LAN device, or on the LAN's router
Your existing routersExchange routes over OSPF or eBGP, or hand off a routed network on a dedicated portSubnet routers advertise routes into the tailnet; LAN equipment is pointed at them with static routes
Layer 2Stretch a layer-2 segment between sites over VXLANLayer 3 only
Two internet linesA tunnel over each uplink, with failure detected by BFD in under a secondThe client picks the best path it can find
When there is no direct pathTraffic goes through a hub, which is one of your own sitesTraffic is relayed through Tailscale's DERP servers (still end-to-end encrypted) or a peer relay you run
Internet breakoutPer site, through a chosen internet exit, or through your own head-office firewall; Microsoft 365 can break out locallyExit nodes: route a device's internet traffic through another device in the tailnet
Changing the networkEach change goes to one canary site first and reaches the rest only once that site reports healthyPolicy changes apply across the tailnet
ClientsmacOS, Windows, LinuxmacOS, Windows, Linux, iOS, Android and more
Console sign-inOpenID Connect single sign-on; your own identity provider by arrangementSign in with a wide range of identity providers, self-service
Control planeServerless, in AWS London (eu-west-2); never carries your trafficTailscale's coordination server; never carries your traffic, though relayed traffic passes through DERP
Pricing modelPer site and per roaming clientPer user; no per-device charge

Tailscale details are from its pricing page and site-to-site guide as of October 2026. If something here is out of date, tell us at support@weftnetworks.com and we will correct it.

Where the difference shows: an office

Take an office with a file server, printers, a phone system and thirty desks, most of which will never run a VPN client.

With Tailscale, a Linux machine in the office becomes a subnet router. To let the office's devices reach the other office, rather than just letting tailnet devices reach in, each office's routing needs to know about the other: Tailscale's guide turns off source NAT on the subnet router and adds a static route on the devices, or on the office router, for every remote subnet. It works, and many people run it this way. It is also the part you maintain by hand.

With Weft, the office machine is the office's gateway into the fabric. If you already have a router, Weft exchanges routes with it over OSPF or eBGP, so new networks appear on both sides without anyone editing static routes. If you do not, Weft can be the gateway for each LAN, hand out addresses, and keep guest Wi-Fi away from the servers by policy. Adding a third office is one enrolment.

Where Tailscale is the better choice

  • Phones and tablets. Tailscale has iOS and Android apps. Weft's clients are macOS, Windows and Linux.
  • No offices. A distributed team reaching cloud servers does not need sites at all, and Tailscale's per-user plans, including its free tier, fit that well.
  • Device-to-device access. SSH to a colleague's machine, reaching a home lab, sharing a single device: this is what Tailscale is designed around.
  • Self-service identity providers. Tailscale lets you sign in with your own provider today; with Weft it is arranged with us.

Where Weft is the better choice

  • Sites first. Whole networks reach whole networks, through a gateway at each site, with routing protocols rather than static routes.
  • Safe change. Changes are proved on one canary site before the rest of the fleet sees them, and upgrades roll back by themselves if a site does not come up.
  • Knowing it is still right. Drift detection catches a hand-edited firewall or a missing route, and names it.
  • Your traffic stays on your own sites. When two sites cannot reach each other directly, they meet at a hub that is one of your sites, not a relay we run.
  • Data held in the UK. The control plane and everything it stores are in AWS London.
  • Layer 2 and two-line failover for the sites that need them.

On price

Tailscale charges per user, with no charge per device, and is free for up to six users. Weft charges £30 per site and £4 per roaming client a month, with every feature on one plan. For a small team on Tailscale's free tier, Tailscale costs less; beyond that, Weft's per-client price is lower, and each office adds £30.

Using both

They do not conflict. You can join your offices and cloud networks with Weft and keep Tailscale for developer access to individual machines.