(There’s another really shitty VPN app for tvOS that I tried, but it also costs money so screw that. It’s also buggy as hell and crashes all the time.)
I should add that my use case is the occasional trip where we take the Apple TV with us places and want to access my media library. Or being able to share my media library with extended family (setting their Apple TV up with a vpn to my house.) More complex things like travel routers can work, but are more hassle than I want, although I’m increasingly leaning towards taking the plunge there…
You could create an account with any one of their identity providers (or roll your own OIDC, it's possible) and just have it not have a linked credit card. The account you use to authenticate Tailscale doesn't have to be the Apple account that you use to log into the hardware device itself - my wife's laptop, phone, and iPads are logged in under my Tailscale account but separate Apple/iCloud accounts (we have family sharing for our apps, etc., but the TS is usually going to be up to me, so I haven't created another account for her). Free gets you 100 devices, so we're nowhere close to running out of those.
Wish I’d read this a few hours ago and the AppleTV would be coming with me.
I can't find it right now but there was a post announcing the port to tvOS on their blog where a developer from the UK (but living in the US) talked about how it let him buy, configure, and ship a simple consumer box that uses little power and needs minimal hands-on maintenance to his parents' house as a replacement for a server he had been running in their house as a VPN endpoint for this sort of thing - so he could watch BBC, etc.
I wouldn't want to update a RPi that's in someone else's house on the other side of the ocean.
While I still prefer running a plain Wireguard VPN if possible (i.e. when there's a publicly reachable UDP port), the really big advantage of Tailscale over other solutions is that it has great NAT traversal, so it's possible to run a routing node behind all kinds of nasty topologies (CG-NAT, double NAT, restrictive firewalls etc.)
At worst, I turn on phone hotspot, authenticate, then switch back to WiFi. A purely serendipitous discovery on my part, but a very welcome one.