relay·ssh

RelaySSH vs Tailscale

Competitor details verified September 2026.

Tailscale is a mesh VPN: install it on every machine you own and they can all reach each other on any port, as if on one private network. RelaySSH is a tunnel for one port on one device, reachable with plain ssh from any machine, with nothing installed on the side you connect from. Pick Tailscale for a private network between your own computers. Pick RelaySSH for SSH to devices from wherever you happen to be sitting.

Side by side

RelaySSHTailscale
Nothing to install where you connect from Any SSH client, on any machine. Tailscale runs on every machine that takes part.
Authentication stays on your device Your device's sshd checks your key. The relay holds no logins. Plain SSH over the tailnet: yes. With Tailscale SSH, the node identity replaces your keys and ACLs decide who may log in.
Device stays off the public internet The tunnel's port is public. Your sshd sees login attempts and rejects them. Only members of the tailnet can reach it.
Any port, any protocol One TCP port per tunnel. No UDP. A full IP link over WireGuard.
Sign up with an email address Email and password. Apple, Google, GitHub, Microsoft, Okta, OneLogin, a custom OIDC provider, or a passkey. No Tailscale passwords by design.
Pricing shape $1 per device per month. Free during the beta. Free for up to 6 users with unlimited devices and 50 tagged resources. Standard is $8 per user per month.
Open-source client The agent is not open source today. Clients and DERP relays are open source; the coordination server is closed. Headscale is an independent open-source replacement for it.
Bundled beyond the tunnel A dashboard with device status and tunnels. Admin console, ACLs, Tailscale SSH with re-authentication, node sharing with other users.

Both work through NAT and CGNAT. Tailscale connects devices directly where it can and falls back to its DERP relays, which forward WireGuard traffic they cannot decrypt. RelaySSH always goes through the relay, which forwards SSH traffic it cannot decrypt.

When Tailscale is the better choice

When the machines are all yours and you want them on one network. A laptop, a desktop, a NAS, and three Pis that can all see each other on every port — file shares, VNC, printers, a database, UDP — with nothing exposed to the internet at all. That is a mesh VPN's job, and a one-port tunnel is the wrong tool for it.

When you have a team. ACLs say which people reach which machines, Tailscale SSH can demand a fresh login from your identity provider before a session, and node sharing lets someone outside your network reach one device. And for personal use the price is zero: six users and unlimited devices on the free plan.

When RelaySSH is the better choice

When you connect from machines that are not yours. A colleague's laptop, a CI runner, a customer's workstation, a locked-down corporate desktop — none of them will run Tailscale, and all of them have ssh. Give someone a host, a port, and a key and they are in, without joining your network or signing in to anything.

When the devices belong to an operator rather than to people. Tailscale is priced per user and its free plan caps tagged resources at 50; a fleet of headless Pis in the field has no users, only devices, and RelaySSH charges per device. Your keys and your sshd stay in charge, and a monitoring script or an Ansible inventory needs nothing but a host and a port that never changes.

Moving from Tailscale

There is nothing to move. Both agents make outbound connections only, so RelaySSH runs next to Tailscale without either noticing.

  1. Install the RelaySSH agent with the one-line command from your dashboard.
  2. Add a tunnel to port 22 on the device's page. The relay assigns a port between 20000 and 29999.
  3. Connect with ssh -p 20001 pi@relayssh.com instead of the tailnet name.

If you were using Tailscale SSH, your device's sshd takes over authentication again, so make sure your public key is in ~/.ssh/authorized_keys on the device before you switch. Keep Tailscale for everything that is not SSH; RelaySSH does not replace the mesh.