---
title: "Registration methods"
description: "Register personal and tagged nodes through web authentication or pre-auth keys, how tagged ownership works, and when a node is ephemeral."
---

Slopscale supports multiple ways to register a node. The preferred registration method depends on the identity of a node
and your use case.

## Identity model

Tailscale's identity model distinguishes between personal and tagged nodes:

- A personal node (or user-owned node) is owned by a human and typically refers to end-user devices such as laptops,
  workstations or mobile phones. End-user devices are managed by a single user.
- A tagged node (or service-based node or non-human node) provides services to the network. Common examples include web-
  and database servers. Those nodes are typically managed by a team of users. Some additional restrictions apply for
  tagged nodes, e.g. a tagged node is not allowed to [Tailscale SSH](https://tailscale.com/docs/features/tailscale-ssh)
  into a personal node.

Slopscale implements Tailscale's identity model and distinguishes between personal and tagged nodes where a personal
node is owned by a Slopscale user and a tagged node is owned by a tag. Tagged devices are grouped under the special user
`tagged-devices`.

## Registration methods

There are two main ways to register new nodes, [web authentication](#web-authentication) and [registration with a pre
authenticated key](#pre-authenticated-key). Both methods can be used to register personal and tagged nodes.

### Web authentication

Web authentication is the default method to register a new node. It's interactive, where the client initiates the
registration and the Slopscale administrator needs to approve the new node before it is allowed to join the network. A
node can be approved with:

- Slopscale CLI (described in this documentation)
- [Slopscale API](/slopscale/ref/api)
- Or delegated to an identity provider via [OpenID Connect](/slopscale/ref/oidc)

Web authentication relies on the presence of a Slopscale user. Use the `slopscale users` command to create a new
user[^1]:

```console
slopscale users create <USER>
```

The display name and profile picture the clients show can be set at creation or later:

```console
slopscale users set --name <USER> --display-name "Alice Liddell" --picture-url https://example.com/alice.png
```

**Personal devices**

Run `tailscale up` to login your personal device:

```console
tailscale up --login-server <YOUR_SLOPSCALE_URL>
```

Usually, a browser window with further instructions is opened. This page explains how to complete the registration
on your Slopscale server and it also prints the Auth ID required to approve the node:

```console
slopscale auth register --user <USER> --auth-id <AUTH_ID>
```

Congrations, the registration of your personal node is complete and it should be listed as "online" in the output of
`slopscale nodes list`. The "User" column displays `<USER>` as the owner of the node.

**Tagged devices**

Your Slopscale user needs to be authorized to register tagged devices. This authorization is specified in the
[`tagOwners`](https://tailscale.com/docs/reference/syntax/policy-file#tag-owners) section of the
[policy](/slopscale/ref/policy). A simple example looks like this:

```json title="The user alice can register nodes tagged with tag:server"
{
  "tagOwners": {
    "tag:server": ["alice@"]
  },
  // more rules
}
```

Run `tailscale up` and provide at least one tag to login a tagged device:

```console
tailscale up --login-server <YOUR_SLOPSCALE_URL> --advertise-tags tag:<TAG>
```

Usually, a browser window with further instructions is opened. This page explains how to complete the registration
on your Slopscale server and it also prints the Auth ID required to approve the node:

```console
slopscale auth register --user <USER> --auth-id <AUTH_ID>
```

Slopscale checks that `<USER>` is allowed to register a node with the specified tag(s) and then transfers ownership
of the new node to the special user `tagged-devices`. The registration of a tagged node is complete and it should be
listed as "online" in the output of `slopscale nodes list`. The "User" column displays `tagged-devices` as the owner
of the node. See the "Tags" column for the list of assigned tags.

### Pre authenticated key

Registration with a pre authenticated key (or auth key) is a non-interactive way to register a new node. The Slopscale
administrator creates a preauthkey upfront and this preauthkey can then be used to register a node non-interactively.
Its best suited for automation.

**Personal devices**

A personal node is always assigned to a Slopscale user. Use the `slopscale users` command to create a new user[^1]:

```console
slopscale users create <USER>
```

Create a new pre authenticated key for your user, by name or by the ID that `slopscale user list` shows:

```console
slopscale preauthkeys create --user <USER>
```

The above prints a pre authenticated key with the default settings (can be used once and is valid for one hour). Use
this auth key to register a node non-interactively:

```console
tailscale up --login-server <YOUR_SLOPSCALE_URL> --authkey <YOUR_AUTH_KEY>
```

Congrations, the registration of your personal node is complete and it should be listed as "online" in the output of
`slopscale nodes list`. The "User" column displays `<USER>` as the owner of the node.

**Tagged devices**

Create a new pre authenticated key and provide at least one tag:

```console
slopscale preauthkeys create --tags tag:<TAG>
```

The above prints a pre authenticated key with the default settings (can be used once and is valid for one hour). Use
this auth key to register a node non-interactively. You don't need to provide the `--advertise-tags` parameter as
the tags are automatically read from the pre authenticated key. Advertising a subset of the key's tags is accepted;
any other tag is rejected:

```console
tailscale up --login-server <YOUR_SLOPSCALE_URL> --authkey <YOUR_AUTH_KEY>
```

The registration of a tagged node is complete and it should be listed as "online" in the output of
`slopscale nodes list`. The "User" column displays `tagged-devices` as the owner of the node. See the "Tags" column for the list of
assigned tags.

## Ephemeral nodes

An ephemeral node is deleted when it logs out and, once it has been offline for `node.ephemeral.inactivity_timeout`,
by the server on its own. A node is ephemeral in either of two ways: it registered with an ephemeral pre-auth key
(`slopscale preauthkeys create --ephemeral`), or it asked to be ephemeral in its register request, which a `tailscaled`
with in-memory state (`--state=mem:`), a `tsnet` program with `Ephemeral` set and the browser client do whatever key
they use, or with none at all through an interactive login. `slopscale nodes list` and the console mark both alike.

[^1]: /slopscale/ref/[Ensure that the Slopscale username does not end with `@`.](/slopscale/ref/oidc#reference-a-user-in-the-policy)
