====== Resolving "Authorization failed: device with nodekey already exists" in Tailscale ====== ===== ===== This error occurs when Tailscale detects that a **node key** for your device is already registered in the tailnet, preventing a new login without explicitly logging out first. Node keys uniquely identify devices and are tied to both the machine and user identity. If the key already exists, re-authentication or cleanup is required. **Example:** tailscale up ; '' '' authorization failed: device with nodekey already exists; please log out explicitly and try logging in again A common cause is that the device’s previous Tailscale state still holds a valid node key, so the server refuses to register it again. This can happen after reinstallations, migrations, or when node keys expire and are regenerated. To fix this, first log out from Tailscale on the affected device: sudo tailscale logout Then log back in: sudo tailscale up If logout fails or the state is corrupted, stop the Tailscale service and remove its local state files before restarting: sudo systemctl stop tailscaled sudo rm -rf /var/lib/tailscale /var/cache/tailscale sudo systemctl start tailscaled sudo tailscale up On Windows, stop the Tailscale service, delete //C:\ProgramData\Tailscale// and //%LocalAppData%\Tailscale//, then restart and log in again. On macOS, remove ///Library/Tailscale// and related cache directories after stopping the service. In some cases, resetting credentials via the app’s settings (e.g., “Reset Keychain” on iOS) resolves the issue. If using pre-auth keys, generating a new one from the admin console may be necessary when old keys expire or become invalid. This process ensures that stale or duplicate node keys are removed so your device can authenticate cleanly with a fresh key pair.