Compare · Tailscale
Weft vs Tailscale
Both are built on WireGuard, and both will get you from a laptop to a server. They start from opposite ends: Tailscale connects people and devices, Weft connects places. This page says where each fits, including where Tailscale is the better choice.
The short version
- Choose Tailscale if what you need is people and their devices reaching servers and each other — including phones — with almost no setup, and your offices are a side concern.
- Choose Weft if what you need is offices, cloud networks and data centres joined into one routed network, with the office machine acting as the gateway for everything behind it, and changes you can make without fear of breaking every site at once.
Side by side
| Weft | Tailscale | |
|---|---|---|
| Built for | Joining sites: offices, cloud networks, data centres, plus roaming laptops | Joining devices and users into one private network (a "tailnet") |
| What runs where | The Weft agent on one Ubuntu 24.04 machine per site, which becomes the site's gateway; apps on laptops | The Tailscale client on each device, or a Linux subnet router in front of devices that cannot run it |
| Devices behind a site | Reach the fabric through the site's gateway, as they would any router. Weft can be the LANs' gateway itself, with DHCP per network and VLANs | Need a route to the subnet router: Tailscale's site-to-site guide has static routes added on each LAN device, or on the LAN's router |
| Your existing routers | Exchange routes over OSPF or eBGP, or hand off a routed network on a dedicated port | Subnet routers advertise routes into the tailnet; LAN equipment is pointed at them with static routes |
| Layer 2 | Stretch a layer-2 segment between sites over VXLAN | Layer 3 only |
| Two internet lines | A tunnel over each uplink, with failure detected by BFD in under a second | The client picks the best path it can find |
| When there is no direct path | Traffic goes through a hub, which is one of your own sites | Traffic is relayed through Tailscale's DERP servers (still end-to-end encrypted) or a peer relay you run |
| Internet breakout | Per site, through a chosen internet exit, or through your own head-office firewall; Microsoft 365 can break out locally | Exit nodes: route a device's internet traffic through another device in the tailnet |
| Changing the network | Each change goes to one canary site first and reaches the rest only once that site reports healthy | Policy changes apply across the tailnet |
| Clients | macOS, Windows, Linux | macOS, Windows, Linux, iOS, Android and more |
| Console sign-in | OpenID Connect single sign-on; your own identity provider by arrangement | Sign in with a wide range of identity providers, self-service |
| Control plane | Serverless, in AWS London (eu-west-2); never carries your traffic | Tailscale's coordination server; never carries your traffic, though relayed traffic passes through DERP |
| Pricing model | Per site and per roaming client | Per user; no per-device charge |
Tailscale details are from its pricing page and site-to-site guide as of October 2026. If something here is out of date, tell us at support@weftnetworks.com and we will correct it.
Where the difference shows: an office
Take an office with a file server, printers, a phone system and thirty desks, most of which will never run a VPN client.
With Tailscale, a Linux machine in the office becomes a subnet router. To let the office's devices reach the other office, rather than just letting tailnet devices reach in, each office's routing needs to know about the other: Tailscale's guide turns off source NAT on the subnet router and adds a static route on the devices, or on the office router, for every remote subnet. It works, and many people run it this way. It is also the part you maintain by hand.
With Weft, the office machine is the office's gateway into the fabric. If you already have a router, Weft exchanges routes with it over OSPF or eBGP, so new networks appear on both sides without anyone editing static routes. If you do not, Weft can be the gateway for each LAN, hand out addresses, and keep guest Wi-Fi away from the servers by policy. Adding a third office is one enrolment.
Where Tailscale is the better choice
- Phones and tablets. Tailscale has iOS and Android apps. Weft's clients are macOS, Windows and Linux.
- No offices. A distributed team reaching cloud servers does not need sites at all, and Tailscale's per-user plans, including its free tier, fit that well.
- Device-to-device access. SSH to a colleague's machine, reaching a home lab, sharing a single device: this is what Tailscale is designed around.
- Self-service identity providers. Tailscale lets you sign in with your own provider today; with Weft it is arranged with us.
Where Weft is the better choice
- Sites first. Whole networks reach whole networks, through a gateway at each site, with routing protocols rather than static routes.
- Safe change. Changes are proved on one canary site before the rest of the fleet sees them, and upgrades roll back by themselves if a site does not come up.
- Knowing it is still right. Drift detection catches a hand-edited firewall or a missing route, and names it.
- Your traffic stays on your own sites. When two sites cannot reach each other directly, they meet at a hub that is one of your sites, not a relay we run.
- Data held in the UK. The control plane and everything it stores are in AWS London.
- Layer 2 and two-line failover for the sites that need them.
On price
Tailscale charges per user, with no charge per device, and is free for up to six users. Weft charges £30 per site and £4 per roaming client a month, with every feature on one plan. For a small team on Tailscale's free tier, Tailscale costs less; beyond that, Weft's per-client price is lower, and each office adds £30.
Using both
They do not conflict. You can join your offices and cloud networks with Weft and keep Tailscale for developer access to individual machines.