How to Control Your Mac from Apple Watch — Anywhere on Earth

A 5-minute setup guide that finally fixes the "same WiFi only" problem.

Updated 2026-05-08 · ~10 minute read

The problem with most "Apple Watch Mac remote" apps

Search the App Store for "Mac remote" and you get a long list of apps that all do roughly the same thing — and all break the moment you leave your home WiFi. They use Bonjour discovery on the local network, which is fast and zero-config but completely useless from a coffee shop, an office on a different floor, a hotel room, or another country.

That's a real limitation. The most useful Mac remote scenarios are exactly the ones where you aren't at home: pausing music your Mac is playing while you're in a meeting room three floors up, locking your Mac after you've left the house, restarting it from a different city, controlling it during a presentation when your laptop is plugged into a projector. None of those work over Bonjour.

This guide walks through a setup that solves it: Tailscale (a private mesh network that gives your Mac a stable IP reachable from anywhere on Earth), plus SSH (the same protocol you use for any remote terminal session), plus MacTap (an Apple Watch and iPhone app that wraps it all in a one-tap interface). Setup takes about five minutes. After that, your Mac is one wrist tap away regardless of where you are.

Why Tailscale + SSH instead of a cloud-relay app? Tailscale uses WireGuard, an open-source encryption protocol, to build a private mesh between your own devices. Your traffic doesn't pass through a vendor's cloud servers. That makes it both faster (lower latency than relayed-through-Frankfurt routes) and more private (nobody on a cloud relay can see what commands you're sending).

What you'll need

Total time: about 5 minutes once everything is downloaded.

Step 1: Install Tailscale on your Mac

Tailscale is the foundation. It assigns each of your devices a stable private IP address (something like 100.64.1.5) that's reachable from any of your other Tailscale devices, regardless of network. Free for up to 100 personal devices, no payment details required.

  1. Visit tailscale.com/download and download the macOS client.
  2. Install the .pkg file (drag to Applications, then launch).
  3. Click the Tailscale menu bar icon and sign in. You can use Google, Microsoft, GitHub, Apple, or email — just pick one and remember it, you'll use the same on iPhone.
  4. Once signed in, your Mac shows up in the Tailscale admin console with a Tailscale IP. Note it down — you'll need it in Step 5.
[ Screenshot needed: Tailscale menu bar icon showing Mac's Tailscale IP ]

Step 2: Install Tailscale on your iPhone

  1. Search the App Store for "Tailscale" and install the official app.
  2. Open it and sign in with the same account you used on the Mac.
  3. Toggle the VPN connection on. iOS will ask for permission — accept.
  4. You'll see your Mac listed in the device list with its Tailscale IP. That's the address you'll use to reach it.

From this point on, your iPhone can reach your Mac at that Tailscale IP regardless of which WiFi or cellular network it's on. The Tailscale tunnel is always available in the background.

Step 3: Enable Remote Login on your Mac

SSH (the protocol MacTap uses to send commands) is built into macOS but turned off by default. You need to flip the switch in System Settings.

  1. Open System Settings.
  2. Go to General → Sharing.
  3. Toggle Remote Login on.
  4. Set "Allow access for" to your user account (or "All users" if you prefer).
[ Screenshot needed: System Settings → General → Sharing with Remote Login toggled on ]

Your Mac will now accept SSH connections. Note your Mac's username — you'll need it in Step 5. (You can find it in System Settings → Users & Groups, or by running whoami in Terminal.)

Step 4: Generate an SSH key on iPhone

SSH uses key-pair authentication: a private key stays on your iPhone (in the iOS Keychain), and a public key is added to your Mac's authorized list. Once that's done, your iPhone can connect without a password.

You don't need to touch the Terminal. MacTap handles key generation in-app:

  1. Open MacTap on your iPhone.
  2. Tap Setup.
  3. In the SSH Key section, tap Generate New Key. MacTap creates an Ed25519 key pair (modern, fast, more secure than older RSA keys) and stores the private key in the iOS Keychain.
  4. The public key is shown on screen and copied to your clipboard automatically.

Now you need to authorize the public key on your Mac. The simplest way:

echo "PASTE_PUBLIC_KEY_HERE" >> ~/.ssh/authorized_keys
chmod 600 ~/.ssh/authorized_keys

Run those two lines in Terminal on your Mac, replacing the placeholder with the public key MacTap copied. That's the only Terminal command in the entire setup.

Step 5: Configure MacTap

Back in MacTap on your iPhone, fill in the connection details:

Tap Connect. MacTap establishes an SSH session over Tailscale and shows a green status pill once connected. If it doesn't connect, the most common causes are:

MacTap Settings screen showing Tailscale IP, Mac username, and SSH key configuration fields
MacTap Settings screen — Tailscale IP, username, and SSH key all in one place.

Step 6: Use it from your Watch

If you have an Apple Watch paired with the iPhone where MacTap is installed, the Watch app installs automatically. Open it and you'll see a list of preset commands. Tap any one — your Mac executes it within a second.

The Watch doesn't need its own Tailscale client or SSH connection. Commands relay through your iPhone via WatchConnectivity (a built-in Apple framework), and the iPhone handles the SSH session. As long as your iPhone and Watch are within Bluetooth range — about 10 metres, or anywhere on the same WiFi — the Watch works.

MacTap on Apple Watch Ultra showing Power, Sleep, and Lock command buttons
MacTap on Apple Watch — single-tap commands, no menus.

The 50+ commands MacTap ships with

CategoryCommands
PowerSleep, Lock, Wake, Restart, Shutdown
AudioVolume up/down, Mute, jump to 25/50/75/100%, current level
MediaPlay/Pause, Next, Previous, Stop, shuffle library, playlist picker, now playing
AppsLaunch Safari, Finder, Messages, Mail, Calendar, Music, Notes, Xcode, Chrome, Spotify, and 11 more
SystemEmpty Trash, kill front app, battery, uptime, disk space, Wi-Fi IP, top CPU process
Radio23 free internet radio stations across 9 genres

Use cases

The "anywhere" thing isn't theoretical — here are the situations MacTap actually gets used for:

Why this is secure

Three layers, all independent:

How does this compare to other Mac remote apps?

AppWorks off home WiFi?SetupCost
Bonjour-based "Mac Remote" apps (most of the App Store)No — same WiFi onlyZero config$0–$5
Splashtop (screen mirroring)Yes (their relay)Account, paid plan for cellular$5/month+
Apple's Screen Sharing / Back to My MacLimited — same iCloud networkBuilt-in$0
Remote Desktop Manager + manual port forwardingYesRouter config, security riskFree / paid tiers
MacTap + TailscaleYes, anywhere on Earth5 min, no port forwardingOne-time $29.99

Frequently asked questions

Does this work over cellular data?

Yes. Because MacTap uses Tailscale instead of local network discovery, it works on cellular, public WiFi, hotel networks, and any other internet connection your iPhone is on.

How much battery does Tailscale use on my iPhone?

Idle. Tailscale's iOS client doesn't drain noticeable battery when you aren't actively using it — under 1% per day in typical use. It only does work when there's active traffic.

What if my Mac is asleep?

If your Mac is fully asleep (lid closed on a laptop, no power), MacTap can't wake it remotely — this is a macOS limitation, not a MacTap one. But if you have Wake for network access enabled (System Settings → Energy Saver → Network) or your Mac is plugged into power, it stays reachable. MacTap shows a clear "connecting…" state and times out cleanly if the Mac doesn't respond, so you're not left guessing.

How much data does it use?

Each command exchanges a few hundred bytes of SSH traffic. A full day of heavy use is well under 1 MB. Negligible on any modern data plan.

Is this secure?

Yes — three independent layers: Tailscale's WireGuard encryption, SSH key authentication with the private key in iOS Keychain, and no third-party servers in the data path. See the Why this is secure section above for the detail.

Can I use it without an Apple Watch?

Yes. The iPhone app has the full command library. Apple Watch is the hero interface but optional.

Will it work if I switch WiFi networks or move between cellular and WiFi?

Yes. Tailscale automatically rebuilds the tunnel as your iPhone's network changes. You won't need to reconnect manually.

What happens if I lose my iPhone?

Your private key is in the iOS Keychain, protected by Face ID / passcode / iCloud Keychain encryption. If your phone is lost, the standard iOS Find My / remote wipe flow handles it. As an extra layer, you can revoke the device from your Tailscale admin console — that immediately cuts off network access from the lost device.

Stop being tied to home WiFi.

MacTap is a one-time $29.99 purchase. No subscription. No servers. No recurring costs.

Get MacTap on the App Store