MCP Tunnels
api/admin/mcp_tunnels
History
api/admin/mcp_tunnels Changed · +174 / -265 lines
### Path parameters ### Headers #### Response (200) ### Query parameters ### Headers #### Response (200) ### Path parameters ### Headers #### Response (200) ### Path parameters ### Headers ### Body parameters #### Response (200) ### Path parameters ### Headers #### Response (200) ## Domain types ## MCP Tunnels › Tunnel Certificates ### Create Tunnel Certificate #### Path parameters #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### Get Tunnel Certificate #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ### List Tunnel Certificates #### Path parameters #### Query parameters #### Headers #### Returns #### Example ##### Response (200) ### Archive Tunnel Certificate #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ### Path Parameters ### Header Parameters #### Response ### Query Parameters ### Header Parameters #### Response ### Path Parameters ### Header Parameters #### Response ### Path Parameters ### Header Parameters ### Body Parameters #### Response ### Path Parameters ### Header Parameters #### Response ## Domain Types # Tunnel Certificates ## Create Tunnel Certificate ### Path Parameters ### Header Parameters ### Body Parameters #### Response ## Get Tunnel Certificate ### Path Parameters ### Header Parameters #### Response ## List Tunnel Certificates ### Path Parameters ### Query Parameters ### Header Parameters #### Response ## Archive Tunnel Certificate ### Path Parameters ### Header Parameters #### Response ## Domain Types ### Tunnel Certificate Create Response ### Tunnel Certificate Retrieve Response ### Tunnel Certificate List Response ### Tunnel Certificate Archive Response
The two sides of this change are too far apart to line up, so this is the differ's own diff of it.
---- -title: MCP Tunnels -url: https://platform.claude.com/docs/en/api/admin/mcp_tunnels ---- - # MCP Tunnels ## Get Tunnel -**get** `/v1/organizations/tunnels/{tunnel_id}` +**GET** `/v1/organizations/tunnels/{tunnel_id}` + +**Deprecated** **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window. Retrieve a single tunnel in the caller's organization by ID. -### Path Parameters +### Path parameters - `tunnel_id: string` ID of the Tunnel. -### Header Parameters +### Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - - `"mcp-tunnels-2026-05-19"` ### Returns
RFC 3339 datetime string indicating when the Tunnel was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the Tunnel was created. + + format: date-time - `display_name: string or null`
Object type. Always `tunnel` for Tunnels. - - `"tunnel"` + default: tunnel - `workspace_id: string or null`
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
## List Tunnels -**get** `/v1/organizations/tunnels` +**GET** `/v1/organizations/tunnels` + +**Deprecated** **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
(newest first). Use `workspace_id` to filter to a single workspace; archived tunnels are excluded unless `include_archived` is set. -### Query Parameters +### Query parameters - `include_archived: optional boolean` Include archived tunnels in the results. Archived tunnels are excluded by default. + default: false + - `limit: optional number` Maximum number of tunnels to return in a single page. + + default: 20, maximum: 1000, minimum: 1 - `page: optional string`
Return only tunnels in this Workspace. Accepts a `wrkspc_`-prefixed Workspace ID; omit to list tunnels across all Workspaces. -### Header Parameters +### Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - `"mcp-tunnels-2026-05-19"` - ### Returns -- `data: array of object { id, archived_at, created_at, 4 more }` +- `data: array of object` - `id: string`
RFC 3339 datetime string indicating when the Tunnel was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the Tunnel was created. + + format: date-time - `display_name: string or null`
Object type. Always `tunnel` for Tunnels. - - `"tunnel"` + default: tunnel - `workspace_id: string or null`
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/tunnels \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
## Reveal Tunnel Token -**post** `/v1/organizations/tunnels/{tunnel_id}/reveal_token` +**POST** `/v1/organizations/tunnels/{tunnel_id}/reveal_token` + +**Deprecated** **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
Exposed as `POST` so the token does not appear in intermediary access logs. -### Path Parameters +### Path parameters - `tunnel_id: string` ID of the Tunnel. -### Header Parameters +### Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - - `"mcp-tunnels-2026-05-19"` ### Returns
Object type. Always `tunnel_token` for Tunnel Tokens. - - `"tunnel_token"` + default: tunnel_token ### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/reveal_token \ -X POST \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
## Rotate Tunnel Token -**post** `/v1/organizations/tunnels/{tunnel_id}/rotate_token` +**POST** `/v1/organizations/tunnels/{tunnel_id}/rotate_token` + +**Deprecated** **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
restarted after rotation must use the new value. An optional `reason` is captured for operational context. -### Path Parameters +### Path parameters - `tunnel_id: string` ID of the Tunnel. -### Header Parameters +### Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - `"mcp-tunnels-2026-05-19"` - -### Body Parameters +### Body parameters - `reason: optional string or null` Optional free-text reason for the rotation, recorded for audit. + + maxLength: 1024 ### Returns
Object type. Always `tunnel_token` for Tunnel Tokens. - - `"tunnel_token"` + default: tunnel_token ### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/rotate_token \ -X POST \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
## Archive Tunnel -**post** `/v1/organizations/tunnels/{tunnel_id}/archive` +**POST** `/v1/organizations/tunnels/{tunnel_id}/archive` + +**Deprecated** **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
tunnel token is invalidated. Retrying against an already-archived tunnel returns the existing record unchanged. -### Path Parameters +### Path parameters - `tunnel_id: string` ID of the Tunnel. -### Header Parameters +### Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - - `"mcp-tunnels-2026-05-19"` ### Returns
RFC 3339 datetime string indicating when the Tunnel was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the Tunnel was created. + + format: date-time - `display_name: string or null`
Object type. Always `tunnel` for Tunnels. - - `"tunnel"` + default: tunnel - `workspace_id: string or null`
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
} ``` -## Domain Types +## Domain types ### MCP Tunnel Retrieve Response -- `MCPTunnelRetrieveResponse object { id, archived_at, created_at, 4 more }` +- `MCPTunnelRetrieveResponse object` - `id: string`
RFC 3339 datetime string indicating when the Tunnel was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the Tunnel was created. + + format: date-time - `display_name: string or null`
Object type. Always `tunnel` for Tunnels. - - `"tunnel"` + default: tunnel - `workspace_id: string or null`
### MCP Tunnel List Response -- `MCPTunnelListResponse object { id, archived_at, created_at, 4 more }` +- `MCPTunnelListResponse object` - `id: string`
RFC 3339 datetime string indicating when the Tunnel was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the Tunnel was created. + + format: date-time - `display_name: string or null`
Object type. Always `tunnel` for Tunnels. - - `"tunnel"` + default: tunnel - `workspace_id: string or null`
### MCP Tunnel Reveal Token Response -- `MCPTunnelRevealTokenResponse object { id, tunnel_token, type }` +- `MCPTunnelRevealTokenResponse object` - `id: string`
Object type. Always `tunnel_token` for Tunnel Tokens. - - `"tunnel_token"` + default: tunnel_token ### MCP Tunnel Rotate Token Response -- `MCPTunnelRotateTokenResponse object { id, tunnel_token, type }` +- `MCPTunnelRotateTokenResponse object` - `id: string`
Object type. Always `tunnel_token` for Tunnel Tokens. - - `"tunnel_token"` + default: tunnel_token ### MCP Tunnel Archive Response -- `MCPTunnelArchiveResponse object { id, archived_at, created_at, 4 more }` +- `MCPTunnelArchiveResponse object` - `id: string`
RFC 3339 datetime string indicating when the Tunnel was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the Tunnel was created. + + format: date-time - `display_name: string or null`
Object type. Always `tunnel` for Tunnels. - - `"tunnel"` + default: tunnel - `workspace_id: string or null` ID of the Workspace this Tunnel belongs to, or `null` for the default Workspace. Immutable after creation. -# Tunnel Certificates - -## Create Tunnel Certificate - -**post** `/v1/organizations/tunnels/{tunnel_id}/certificates` +## MCP Tunnels › Tunnel Certificates + +### Create Tunnel Certificate + +**POST** `/v1/organizations/tunnels/{tunnel_id}/certificates` + +**Deprecated** **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
exactly one X.509 certificate and no private-key material. A tunnel holds at most two non-archived certificates. -### Path Parameters +#### Path parameters - `tunnel_id: string` ID of the Tunnel. -### Header Parameters +#### Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - `"mcp-tunnels-2026-05-19"` - -### Body Parameters +#### Body parameters - `ca_certificate_pem: string` PEM-encoded X.509 CA certificate. Must contain exactly one certificate and no private-key material. -### Returns + maxLength: 8192 + +#### Returns - `id: string`
RFC 3339 datetime string indicating when the certificate was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the certificate was registered. + + format: date-time - `expires_at: string or null` RFC 3339 datetime string indicating when the certificate expires, or `null` if it does not expire. + format: date-time + - `fingerprint: string` The certificate's SHA-256 fingerprint, as a lowercase hex string.
Object type. Always `tunnel_certificate` for Tunnel Certificates. - - `"tunnel_certificate"` - -### Example - -```http + default: tunnel_certificate + +#### Example + +```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +##### Response (200) ```json {
} ``` -## Get Tunnel Certificate - -**get** `/v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id}` +### Get Tunnel Certificate + +**GET** `/v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id}` + +**Deprecated** **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window. Retrieve a single certificate registered on a tunnel by ID. -### Path Parameters +#### Path parameters - `tunnel_id: string`
ID of the Tunnel Certificate. -### Header Parameters +#### Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - `"mcp-tunnels-2026-05-19"` - -### Returns +#### Returns - `id: string`
RFC 3339 datetime string indicating when the certificate was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the certificate was registered. + + format: date-time - `expires_at: string or null` RFC 3339 datetime string indicating when the certificate expires, or `null` if it does not expire. + format: date-time + - `fingerprint: string` The certificate's SHA-256 fingerprint, as a lowercase hex string.
Object type. Always `tunnel_certificate` for Tunnel Certificates. - - `"tunnel_certificate"` - -### Example - -```http + default: tunnel_certificate + +#### Example + +```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +##### Response (200) ```json {
} ``` -## List Tunnel Certificates - -**get** `/v1/organizations/tunnels/{tunnel_id}/certificates` +### List Tunnel Certificates + +**GET** `/v1/organizations/tunnels/{tunnel_id}/certificates` + +**Deprecated** **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
Archived certificates are excluded unless `include_archived` is set. -### Path Parameters +#### Path parameters - `tunnel_id: string` ID of the Tunnel. -### Query Parameters +#### Query parameters - `include_archived: optional boolean` Include archived certificates in the results. Archived certificates are excluded by default. + default: false + - `limit: optional number` Maximum number of certificates to return. + + default: 20, maximum: 1000, minimum: 1 - `page: optional string` A tunnel has at most two active certificates, so this list is not paginated. -### Header Parameters +#### Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - `"mcp-tunnels-2026-05-19"` - -### Returns - -- `data: array of object { id, archived_at, created_at, 4 more }` +#### Returns + +- `data: array of object` - `id: string`
RFC 3339 datetime string indicating when the certificate was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the certificate was registered. + + format: date-time - `expires_at: string or null` RFC 3339 datetime string indicating when the certificate expires, or `null` if it does not expire. + format: date-time + - `fingerprint: string` The certificate's SHA-256 fingerprint, as a lowercase hex string.
Object type. Always `tunnel_certificate` for Tunnel Certificates. - - `"tunnel_certificate"` + default: tunnel_certificate - `next_page: string or null` Opaque cursor for the next page, or `null` if there are no more results. -### Example - -```http +#### Example + +```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +##### Response (200) ```json {
} ``` -## Archive Tunnel Certificate - -**post** `/v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id}/archive` +### Archive Tunnel Certificate + +**POST** `/v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id}/archive` + +**Deprecated** **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
certificate is permitted; the tunnel rejects MCP traffic until a new certificate is added. -### Path Parameters +#### Path parameters - `tunnel_id: string`
ID of the Tunnel Certificate. -### Header Parameters +#### Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - `"mcp-tunnels-2026-05-19"` - -### Returns +#### Returns - `id: string`
RFC 3339 datetime string indicating when the certificate was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the certificate was registered. + + format: date-time - `expires_at: string or null` RFC 3339 datetime string indicating when the certificate expires, or `null` if it does not expire. + format: date-time + - `fingerprint: string` The certificate's SHA-256 fingerprint, as a lowercase hex string.
Object type. Always `tunnel_certificate` for Tunnel Certificates. - - `"tunnel_certificate"` - -### Example - -```http + default: tunnel_certificate + +#### Example + +```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +##### Response (200) ```json {
"type": "tunnel_certificate" } ``` - -## Domain Types - -### Tunnel Certificate Create Response - -- `TunnelCertificateCreateResponse object { id, archived_at, created_at, 4 more }` - - - `id: string` - - ID of the Tunnel Certificate. - - - `archived_at: string or null` - - RFC 3339 datetime string indicating when the certificate was archived, or - `null` if it is not archived. - - - `created_at: string` - - RFC 3339 datetime string indicating when the certificate was registered. - - - `expires_at: string or null` - - RFC 3339 datetime string indicating when the certificate expires, or - `null` if it does not expire. - - - `fingerprint: string` - - The certificate's SHA-256 fingerprint, as a lowercase hex string. - - - `tunnel_id: string` - - ID of the Tunnel this certificate is registered against. - - - `type: "tunnel_certificate"` - - Object type. Always `tunnel_certificate` for Tunnel Certificates. - - - `"tunnel_certificate"` - -### Tunnel Certificate Retrieve Response - -- `TunnelCertificateRetrieveResponse object { id, archived_at, created_at, 4 more }` - - - `id: string` - - ID of the Tunnel Certificate. - - - `archived_at: string or null` - - RFC 3339 datetime string indicating when the certificate was archived, or - `null` if it is not archived. - - - `created_at: string` - - RFC 3339 datetime string indicating when the certificate was registered. - - - `expires_at: string or null` - - RFC 3339 datetime string indicating when the certificate expires, or - `null` if it does not expire. - - - `fingerprint: string` - - The certificate's SHA-256 fingerprint, as a lowercase hex string. - - - `tunnel_id: string` - - ID of the Tunnel this certificate is registered against. - - - `type: "tunnel_certificate"` - - Object type. Always `tunnel_certificate` for Tunnel Certificates. - - - `"tunnel_certificate"` - -### Tunnel Certificate List Response - -- `TunnelCertificateListResponse object { id, archived_at, created_at, 4 more }` - - - `id: string` - - ID of the Tunnel Certificate. - - - `archived_at: string or null` - - RFC 3339 datetime string indicating when the certificate was archived, or - `null` if it is not archived. - - - `created_at: string` - - RFC 3339 datetime string indicating when the certificate was registered. - - - `expires_at: string or null` - - RFC 3339 datetime string indicating when the certificate expires, or - `null` if it does not expire. - - - `fingerprint: string` - - The certificate's SHA-256 fingerprint, as a lowercase hex string. - - - `tunnel_id: string` - - ID of the Tunnel this certificate is registered against. - - - `type: "tunnel_certificate"` - - Object type. Always `tunnel_certificate` for Tunnel Certificates. - - - `"tunnel_certificate"` - -### Tunnel Certificate Archive Response - -- `TunnelCertificateArchiveResponse object { id, archived_at, created_at, 4 more }` - - - `id: string` - - ID of the Tunnel Certificate. - - - `archived_at: string or null` - - RFC 3339 datetime string indicating when the certificate was archived, or - `null` if it is not archived. - - - `created_at: string` - - RFC 3339 datetime string indicating when the certificate was registered. - - - `expires_at: string or null` - - RFC 3339 datetime string indicating when the certificate expires, or - `null` if it does not expire. - - - `fingerprint: string` - - The certificate's SHA-256 fingerprint, as a lowercase hex string. - - - `tunnel_id: string` - - ID of the Tunnel this certificate is registered against. - - - `type: "tunnel_certificate"` - - Object type. Always `tunnel_certificate` for Tunnel Certificates. - - - `"tunnel_certificate"`
api/admin/mcp_tunnels First recorded · 1085 lines, first recorded
# MCP Tunnels ## Get Tunnel ### Path Parameters ### Header Parameters ### Returns ### Example #### Response ## List Tunnels ### Query Parameters ### Header Parameters ### Returns ### Example #### Response ## Reveal Tunnel Token ### Path Parameters ### Header Parameters ### Returns ### Example #### Response ## Rotate Tunnel Token ### Path Parameters ### Header Parameters ### Body Parameters ### Returns ### Example #### Response ## Archive Tunnel ### Path Parameters ### Header Parameters ### Returns ### Example #### Response ## Domain Types ### MCP Tunnel Retrieve Response ### MCP Tunnel List Response ### MCP Tunnel Reveal Token Response ### MCP Tunnel Rotate Token Response ### MCP Tunnel Archive Response # Tunnel Certificates ## Create Tunnel Certificate ### Path Parameters ### Header Parameters ### Body Parameters ### Returns ### Example #### Response ## Get Tunnel Certificate ### Path Parameters ### Header Parameters ### Returns ### Example #### Response ## List Tunnel Certificates ### Path Parameters ### Query Parameters ### Header Parameters ### Returns ### Example #### Response ## Archive Tunnel Certificate ### Path Parameters ### Header Parameters ### Returns ### Example #### Response ## Domain Types ### Tunnel Certificate Create Response ### Tunnel Certificate Retrieve Response ### Tunnel Certificate List Response ### Tunnel Certificate Archive Response
The first capture of this source. The page was already there, and this is what it said.
---
title: MCP Tunnels
url: https://platform.claude.com/docs/en/api/admin/mcp_tunnels
---
# MCP Tunnels
## Get Tunnel
**get** `/v1/organizations/tunnels/{tunnel_id}`
**Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
Retrieve a single tunnel in the caller's organization by ID.
### Path Parameters
- `tunnel_id: string`
ID of the Tunnel.
### Header Parameters
- `"anthropic-beta": array of "mcp-tunnels-2026-05-19"`
Required for all Tunnel endpoints.
- `"mcp-tunnels-2026-05-19"`
### Returns
- `id: string`
ID of the Tunnel.
- `archived_at: string or null`
RFC 3339 datetime string indicating when the Tunnel was archived, or
`null` if it is not archived.
- `created_at: string`
RFC 3339 datetime string indicating when the Tunnel was created.
- `display_name: string or null`
Human-readable name for the Tunnel (1–255 characters), or `null` if unset.
- `domain: string`
Anthropic-assigned hostname for the Tunnel. MCP server URLs whose host is a
subdomain of this value are routed through the Tunnel. Globally unique and
never reused, even after the Tunnel is archived.
- `type: "tunnel"`
Object type. Always `tunnel` for Tunnels.
- `"tunnel"`
- `workspace_id: string or null`
ID of the Workspace this Tunnel belongs to, or `null` for the default
Workspace. Immutable after creation.
### Example
```http
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID \
-H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN"
```
#### Response
```json
{
"id": "tnl_01Hx9Kp2RtQvMn3sWbYdLcF8",
"archived_at": "2024-11-01T23:59:27.427722Z",
"created_at": "2024-10-30T23:58:27.427722Z",
"display_name": "Production",
"domain": "a1b2c3d4.tunnel.anthropic.com",
"type": "tunnel",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
}
```
## List Tunnels
**get** `/v1/organizations/tunnels`
**Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
List the organization's tunnels.
Results span the caller's organization, ordered by creation time
(newest first). Use `workspace_id` to filter to a single workspace;
archived tunnels are excluded unless `include_archived` is set.
### Query Parameters
- `include_archived: optional boolean`
Include archived tunnels in the results. Archived tunnels are excluded by
default.
- `limit: optional number`
Maximum number of tunnels to return in a single page.
- `page: optional string`
Opaque pagination cursor from a previous response's `next_page`. Omit to
fetch the first page.
- `workspace_id: optional string`
Return only tunnels in this Workspace. Accepts a `wrkspc_`-prefixed
Workspace ID; omit to list tunnels across all Workspaces.
### Header Parameters
- `"anthropic-beta": array of "mcp-tunnels-2026-05-19"`
Required for all Tunnel endpoints.
- `"mcp-tunnels-2026-05-19"`
### Returns
- `data: array of object { id, archived_at, created_at, 4 more }`
- `id: string`
ID of the Tunnel.
- `archived_at: string or null`
RFC 3339 datetime string indicating when the Tunnel was archived, or
`null` if it is not archived.
- `created_at: string`
RFC 3339 datetime string indicating when the Tunnel was created.
- `display_name: string or null`
Human-readable name for the Tunnel (1–255 characters), or `null` if unset.
- `domain: string`
Anthropic-assigned hostname for the Tunnel. MCP server URLs whose host is a
subdomain of this value are routed through the Tunnel. Globally unique and
never reused, even after the Tunnel is archived.
- `type: "tunnel"`
Object type. Always `tunnel` for Tunnels.
- `"tunnel"`
- `workspace_id: string or null`
ID of the Workspace this Tunnel belongs to, or `null` for the default
Workspace. Immutable after creation.
- `next_page: string or null`
Opaque cursor for the next page, or `null` if there are no more results.
### Example
```http
curl https://api.anthropic.com/v1/organizations/tunnels \
-H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN"
```
#### Response
```json
{
"data": [
{
"id": "tnl_01Hx9Kp2RtQvMn3sWbYdLcF8",
"archived_at": "2024-11-01T23:59:27.427722Z",
"created_at": "2024-10-30T23:58:27.427722Z",
"display_name": "Production",
"domain": "a1b2c3d4.tunnel.anthropic.com",
"type": "tunnel",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
}
],
"next_page": "page_MjAyNS0wNS0xNFQwMDowMDowMFo="
}
```
## Reveal Tunnel Token
**post** `/v1/organizations/tunnels/{tunnel_id}/reveal_token`
**Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
Return the tunnel's current connection token.
The value is fetched live on each call; Anthropic does not store it.
Repeated calls return the same value until the token is rotated.
Exposed as `POST` so the token does not appear in intermediary
access logs.
### Path Parameters
- `tunnel_id: string`
ID of the Tunnel.
### Header Parameters
- `"anthropic-beta": array of "mcp-tunnels-2026-05-19"`
Required for all Tunnel endpoints.
- `"mcp-tunnels-2026-05-19"`
### Returns
- `id: string`
Stable identifier for the current token value. Changes when the token is
rotated.
- `tunnel_token: string`
The tunnel's connection token.
- `type: "tunnel_token"`
Object type. Always `tunnel_token` for Tunnel Tokens.
- `"tunnel_token"`
### Example
```http
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/reveal_token \
-X POST \
-H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN"
```
#### Response
```json
{
"id": "ttkn_bb97000eaec162831399ca9b6684a4fdf5be49ace5683057b017aab5c87e19e0",
"tunnel_token": "eyJhIjoiRVhBTVBMRSIsInQiOiJFWEFNUExFIiwicyI6IkVYQU1QTEUifQ==",
"type": "tunnel_token"
}
```
## Rotate Tunnel Token
**post** `/v1/organizations/tunnels/{tunnel_id}/rotate_token`
**Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
Invalidate the tunnel's current token for new connections and return a fresh value.
Established connections are not severed by rotation; a connector
restarted after rotation must use the new value. An optional
`reason` is captured for operational context.
### Path Parameters
- `tunnel_id: string`
ID of the Tunnel.
### Header Parameters
- `"anthropic-beta": array of "mcp-tunnels-2026-05-19"`
Required for all Tunnel endpoints.
- `"mcp-tunnels-2026-05-19"`
### Body Parameters
- `reason: optional string or null`
Optional free-text reason for the rotation, recorded for audit.
### Returns
- `id: string`
Stable identifier for the current token value. Changes when the token is
rotated.
- `tunnel_token: string`
Cut at 300 lines.