Source Intelligence
Sweep 28 Aug 2026 · 00:00Z Build v2.1.250 478 read Stable v2.1.236 Latest v2.1.250 Next v2.1.250 Feeds RSS JSON llms.txt

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

Page history

MCP Tunnels

api/admin/mcp_tunnels

2 recorded changes 994 lines First seen Last changed Upstream

History

api/admin/mcp_tunnels Changed · +174 / -265 lines

### Path parameters ### Headers #### Response (200) ### Query parameters ### Headers #### Response (200) ### Path parameters ### Headers #### Response (200) ### Path parameters ### Headers ### Body parameters #### Response (200) ### Path parameters ### Headers #### Response (200) ## Domain types ## MCP Tunnels › Tunnel Certificates ### Create Tunnel Certificate #### Path parameters #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### Get Tunnel Certificate #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ### List Tunnel Certificates #### Path parameters #### Query parameters #### Headers #### Returns #### Example ##### Response (200) ### Archive Tunnel Certificate #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ### Path Parameters ### Header Parameters #### Response ### Query Parameters ### Header Parameters #### Response ### Path Parameters ### Header Parameters #### Response ### Path Parameters ### Header Parameters ### Body Parameters #### Response ### Path Parameters ### Header Parameters #### Response ## Domain Types # Tunnel Certificates ## Create Tunnel Certificate ### Path Parameters ### Header Parameters ### Body Parameters #### Response ## Get Tunnel Certificate ### Path Parameters ### Header Parameters #### Response ## List Tunnel Certificates ### Path Parameters ### Query Parameters ### Header Parameters #### Response ## Archive Tunnel Certificate ### Path Parameters ### Header Parameters #### Response ## Domain Types ### Tunnel Certificate Create Response ### Tunnel Certificate Retrieve Response ### Tunnel Certificate List Response ### Tunnel Certificate Archive Response

The two sides of this change are too far apart to line up, so this is the differ's own diff of it.

from line 1
----
-title: MCP Tunnels
-url: https://platform.claude.com/docs/en/api/admin/mcp_tunnels
----
-
 # MCP Tunnels
 
 ## Get Tunnel
 
-**get** `/v1/organizations/tunnels/{tunnel_id}`
+**GET** `/v1/organizations/tunnels/{tunnel_id}`
+
+**Deprecated**
 
 **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
 
 Retrieve a single tunnel in the caller's organization by ID.
 
-### Path Parameters
+### Path parameters
 
 - `tunnel_id: string`
 
   ID of the Tunnel.
 
-### Header Parameters
+### Headers
 
 - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"`
 
   Required for all Tunnel endpoints.
-
-  - `"mcp-tunnels-2026-05-19"`
 
 ### Returns
 
from line 33
   RFC 3339 datetime string indicating when the Tunnel was archived, or
   `null` if it is not archived.
 
+  format: date-time
+
 - `created_at: string`
 
   RFC 3339 datetime string indicating when the Tunnel was created.
+
+  format: date-time
 
 - `display_name: string or null`
 
from line 55
 
   Object type. Always `tunnel` for Tunnels.
 
-  - `"tunnel"`
+  default: tunnel
 
 - `workspace_id: string or null`
 
from line 64
 
 ### Example
 
-```http
+```bash
 curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID \
     -H 'anthropic-version: 2023-06-01' \
     -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN"
 ```
 
-#### Response
+#### Response (200)
 
 ```json
 {
from line 86
 
 ## List Tunnels
 
-**get** `/v1/organizations/tunnels`
+**GET** `/v1/organizations/tunnels`
+
+**Deprecated**
 
 **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
 
from line 98
 (newest first). Use `workspace_id` to filter to a single workspace;
 archived tunnels are excluded unless `include_archived` is set.
 
-### Query Parameters
+### Query parameters
 
 - `include_archived: optional boolean`
 
   Include archived tunnels in the results. Archived tunnels are excluded by
   default.
 
+  default: false
+
 - `limit: optional number`
 
   Maximum number of tunnels to return in a single page.
+
+  default: 20, maximum: 1000, minimum: 1
 
 - `page: optional string`
 
from line 123
   Return only tunnels in this Workspace. Accepts a `wrkspc_`-prefixed
   Workspace ID; omit to list tunnels across all Workspaces.
 
-### Header Parameters
+### Headers
 
 - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"`
 
   Required for all Tunnel endpoints.
 
-  - `"mcp-tunnels-2026-05-19"`
-
 ### Returns
 
-- `data: array of object { id, archived_at, created_at, 4 more }`
+- `data: array of object`
 
   - `id: string`
 
from line 142
     RFC 3339 datetime string indicating when the Tunnel was archived, or
     `null` if it is not archived.
 
+    format: date-time
+
   - `created_at: string`
 
     RFC 3339 datetime string indicating when the Tunnel was created.
+
+    format: date-time
 
   - `display_name: string or null`
 
from line 164
 
     Object type. Always `tunnel` for Tunnels.
 
-    - `"tunnel"`
+    default: tunnel
 
   - `workspace_id: string or null`
 
from line 177
 
 ### Example
 
-```http
+```bash
 curl https://api.anthropic.com/v1/organizations/tunnels \
     -H 'anthropic-version: 2023-06-01' \
     -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN"
 ```
 
-#### Response
+#### Response (200)
 
 ```json
 {
from line 204
 
 ## Reveal Tunnel Token
 
-**post** `/v1/organizations/tunnels/{tunnel_id}/reveal_token`
+**POST** `/v1/organizations/tunnels/{tunnel_id}/reveal_token`
+
+**Deprecated**
 
 **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
 
from line 217
 Exposed as `POST` so the token does not appear in intermediary
 access logs.
 
-### Path Parameters
+### Path parameters
 
 - `tunnel_id: string`
 
   ID of the Tunnel.
 
-### Header Parameters
+### Headers
 
 - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"`
 
   Required for all Tunnel endpoints.
-
-  - `"mcp-tunnels-2026-05-19"`
 
 ### Returns
 
from line 244
 
   Object type. Always `tunnel_token` for Tunnel Tokens.
 
-  - `"tunnel_token"`
+  default: tunnel_token
 
 ### Example
 
-```http
+```bash
 curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/reveal_token \
     -X POST \
     -H 'anthropic-version: 2023-06-01' \
     -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN"
 ```
 
-#### Response
+#### Response (200)
 
 ```json
 {
from line 267
 
 ## Rotate Tunnel Token
 
-**post** `/v1/organizations/tunnels/{tunnel_id}/rotate_token`
+**POST** `/v1/organizations/tunnels/{tunnel_id}/rotate_token`
+
+**Deprecated**
 
 **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
 
from line 279
 restarted after rotation must use the new value. An optional
 `reason` is captured for operational context.
 
-### Path Parameters
+### Path parameters
 
 - `tunnel_id: string`
 
   ID of the Tunnel.
 
-### Header Parameters
+### Headers
 
 - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"`
 
   Required for all Tunnel endpoints.
 
-  - `"mcp-tunnels-2026-05-19"`
-
-### Body Parameters
+### Body parameters
 
 - `reason: optional string or null`
 
   Optional free-text reason for the rotation, recorded for audit.
+
+  maxLength: 1024
 
 ### Returns
 
from line 314
 
   Object type. Always `tunnel_token` for Tunnel Tokens.
 
-  - `"tunnel_token"`
+  default: tunnel_token
 
 ### Example
 
-```http
+```bash
 curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/rotate_token \
     -X POST \
     -H 'anthropic-version: 2023-06-01' \
     -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN"
 ```
 
-#### Response
+#### Response (200)
 
 ```json
 {
from line 337
 
 ## Archive Tunnel
 
-**post** `/v1/organizations/tunnels/{tunnel_id}/archive`
+**POST** `/v1/organizations/tunnels/{tunnel_id}/archive`
+
+**Deprecated**
 
 **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
 
from line 350
 tunnel token is invalidated. Retrying against an already-archived
 tunnel returns the existing record unchanged.
 
-### Path Parameters
+### Path parameters
 
 - `tunnel_id: string`
 
   ID of the Tunnel.
 
-### Header Parameters
+### Headers
 
 - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"`
 
   Required for all Tunnel endpoints.
-
-  - `"mcp-tunnels-2026-05-19"`
 
 ### Returns
 
from line 373
   RFC 3339 datetime string indicating when the Tunnel was archived, or
   `null` if it is not archived.
 
+  format: date-time
+
 - `created_at: string`
 
   RFC 3339 datetime string indicating when the Tunnel was created.
+
+  format: date-time
 
 - `display_name: string or null`
 
from line 395
 
   Object type. Always `tunnel` for Tunnels.
 
-  - `"tunnel"`
+  default: tunnel
 
 - `workspace_id: string or null`
 
from line 404
 
 ### Example
 
-```http
+```bash
 curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/archive \
     -X POST \
     -H 'anthropic-version: 2023-06-01' \
     -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN"
 ```
 
-#### Response
+#### Response (200)
 
 ```json
 {
from line 425
 }
 ```
 
-## Domain Types
+## Domain types
 
 ### MCP Tunnel Retrieve Response
 
-- `MCPTunnelRetrieveResponse object { id, archived_at, created_at, 4 more }`
+- `MCPTunnelRetrieveResponse object`
 
   - `id: string`
 
from line 440
     RFC 3339 datetime string indicating when the Tunnel was archived, or
     `null` if it is not archived.
 
+    format: date-time
+
   - `created_at: string`
 
     RFC 3339 datetime string indicating when the Tunnel was created.
+
+    format: date-time
 
   - `display_name: string or null`
 
from line 462
 
     Object type. Always `tunnel` for Tunnels.
 
-    - `"tunnel"`
+    default: tunnel
 
   - `workspace_id: string or null`
 
from line 471
 
 ### MCP Tunnel List Response
 
-- `MCPTunnelListResponse object { id, archived_at, created_at, 4 more }`
+- `MCPTunnelListResponse object`
 
   - `id: string`
 
from line 482
     RFC 3339 datetime string indicating when the Tunnel was archived, or
     `null` if it is not archived.
 
+    format: date-time
+
   - `created_at: string`
 
     RFC 3339 datetime string indicating when the Tunnel was created.
+
+    format: date-time
 
   - `display_name: string or null`
 
from line 504
 
     Object type. Always `tunnel` for Tunnels.
 
-    - `"tunnel"`
+    default: tunnel
 
   - `workspace_id: string or null`
 
from line 513
 
 ### MCP Tunnel Reveal Token Response
 
-- `MCPTunnelRevealTokenResponse object { id, tunnel_token, type }`
+- `MCPTunnelRevealTokenResponse object`
 
   - `id: string`
 
from line 528
 
     Object type. Always `tunnel_token` for Tunnel Tokens.
 
-    - `"tunnel_token"`
+    default: tunnel_token
 
 ### MCP Tunnel Rotate Token Response
 
-- `MCPTunnelRotateTokenResponse object { id, tunnel_token, type }`
+- `MCPTunnelRotateTokenResponse object`
 
   - `id: string`
 
from line 547
 
     Object type. Always `tunnel_token` for Tunnel Tokens.
 
-    - `"tunnel_token"`
+    default: tunnel_token
 
 ### MCP Tunnel Archive Response
 
-- `MCPTunnelArchiveResponse object { id, archived_at, created_at, 4 more }`
+- `MCPTunnelArchiveResponse object`
 
   - `id: string`
 
from line 562
     RFC 3339 datetime string indicating when the Tunnel was archived, or
     `null` if it is not archived.
 
+    format: date-time
+
   - `created_at: string`
 
     RFC 3339 datetime string indicating when the Tunnel was created.
+
+    format: date-time
 
   - `display_name: string or null`
 
from line 584
 
     Object type. Always `tunnel` for Tunnels.
 
-    - `"tunnel"`
+    default: tunnel
 
   - `workspace_id: string or null`
 
     ID of the Workspace this Tunnel belongs to, or `null` for the default
     Workspace. Immutable after creation.
 
-# Tunnel Certificates
-
-## Create Tunnel Certificate
-
-**post** `/v1/organizations/tunnels/{tunnel_id}/certificates`
+## MCP Tunnels › Tunnel Certificates
+
+### Create Tunnel Certificate
+
+**POST** `/v1/organizations/tunnels/{tunnel_id}/certificates`
+
+**Deprecated**
 
 **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
 
from line 608
 exactly one X.509 certificate and no private-key material. A tunnel
 holds at most two non-archived certificates.
 
-### Path Parameters
+#### Path parameters
 
 - `tunnel_id: string`
 
   ID of the Tunnel.
 
-### Header Parameters
+#### Headers
 
 - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"`
 
   Required for all Tunnel endpoints.
 
-  - `"mcp-tunnels-2026-05-19"`
-
-### Body Parameters
+#### Body parameters
 
 - `ca_certificate_pem: string`
 
   PEM-encoded X.509 CA certificate. Must contain exactly one certificate and
   no private-key material.
 
-### Returns
+  maxLength: 8192
+
+#### Returns
 
 - `id: string`
 
from line 640
   RFC 3339 datetime string indicating when the certificate was archived, or
   `null` if it is not archived.
 
+  format: date-time
+
 - `created_at: string`
 
   RFC 3339 datetime string indicating when the certificate was registered.
+
+  format: date-time
 
 - `expires_at: string or null`
 
   RFC 3339 datetime string indicating when the certificate expires, or
   `null` if it does not expire.
 
+  format: date-time
+
 - `fingerprint: string`
 
   The certificate's SHA-256 fingerprint, as a lowercase hex string.
from line 667
 
   Object type. Always `tunnel_certificate` for Tunnel Certificates.
 
-  - `"tunnel_certificate"`
-
-### Example
-
-```http
+  default: tunnel_certificate
+
+#### Example
+
+```bash
 curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \
     -H 'Content-Type: application/json' \
     -H 'anthropic-version: 2023-06-01' \
from line 681
         }'
 ```
 
-#### Response
+##### Response (200)
 
 ```json
 {
from line 695
 }
 ```
 
-## Get Tunnel Certificate
-
-**get** `/v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id}`
+### Get Tunnel Certificate
+
+**GET** `/v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id}`
+
+**Deprecated**
 
 **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
 
 Retrieve a single certificate registered on a tunnel by ID.
 
-### Path Parameters
+#### Path parameters
 
 - `tunnel_id: string`
 
from line 715
 
   ID of the Tunnel Certificate.
 
-### Header Parameters
+#### Headers
 
 - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"`
 
   Required for all Tunnel endpoints.
 
-  - `"mcp-tunnels-2026-05-19"`
-
-### Returns
+#### Returns
 
 - `id: string`
 
from line 732
   RFC 3339 datetime string indicating when the certificate was archived, or
   `null` if it is not archived.
 
+  format: date-time
+
 - `created_at: string`
 
   RFC 3339 datetime string indicating when the certificate was registered.
+
+  format: date-time
 
 - `expires_at: string or null`
 
   RFC 3339 datetime string indicating when the certificate expires, or
   `null` if it does not expire.
 
+  format: date-time
+
 - `fingerprint: string`
 
   The certificate's SHA-256 fingerprint, as a lowercase hex string.
from line 759
 
   Object type. Always `tunnel_certificate` for Tunnel Certificates.
 
-  - `"tunnel_certificate"`
-
-### Example
-
-```http
+  default: tunnel_certificate
+
+#### Example
+
+```bash
 curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID \
     -H 'anthropic-version: 2023-06-01' \
     -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN"
 ```
 
-#### Response
+##### Response (200)
 
 ```json
 {
from line 783
 }
 ```
 
-## List Tunnel Certificates
-
-**get** `/v1/organizations/tunnels/{tunnel_id}/certificates`
+### List Tunnel Certificates
+
+**GET** `/v1/organizations/tunnels/{tunnel_id}/certificates`
+
+**Deprecated**
 
 **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
 
from line 795
 
 Archived certificates are excluded unless `include_archived` is set.
 
-### Path Parameters
+#### Path parameters
 
 - `tunnel_id: string`
 
   ID of the Tunnel.
 
-### Query Parameters
+#### Query parameters
 
 - `include_archived: optional boolean`
 
   Include archived certificates in the results. Archived certificates are
   excluded by default.
 
+  default: false
+
 - `limit: optional number`
 
   Maximum number of certificates to return.
+
+  default: 20, maximum: 1000, minimum: 1
 
 - `page: optional string`
 
   A tunnel has at most two active certificates, so this list is not
   paginated.
 
-### Header Parameters
+#### Headers
 
 - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"`
 
   Required for all Tunnel endpoints.
 
-  - `"mcp-tunnels-2026-05-19"`
-
-### Returns
-
-- `data: array of object { id, archived_at, created_at, 4 more }`
+#### Returns
+
+- `data: array of object`
 
   - `id: string`
 
from line 840
     RFC 3339 datetime string indicating when the certificate was archived, or
     `null` if it is not archived.
 
+    format: date-time
+
   - `created_at: string`
 
     RFC 3339 datetime string indicating when the certificate was registered.
+
+    format: date-time
 
   - `expires_at: string or null`
 
     RFC 3339 datetime string indicating when the certificate expires, or
     `null` if it does not expire.
 
+    format: date-time
+
   - `fingerprint: string`
 
     The certificate's SHA-256 fingerprint, as a lowercase hex string.
from line 867
 
     Object type. Always `tunnel_certificate` for Tunnel Certificates.
 
-    - `"tunnel_certificate"`
+    default: tunnel_certificate
 
 - `next_page: string or null`
 
   Opaque cursor for the next page, or `null` if there are no more results.
 
-### Example
-
-```http
+#### Example
+
+```bash
 curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \
     -H 'anthropic-version: 2023-06-01' \
     -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN"
 ```
 
-#### Response
+##### Response (200)
 
 ```json
 {
from line 900
 }
 ```
 
-## Archive Tunnel Certificate
-
-**post** `/v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id}/archive`
+### Archive Tunnel Certificate
+
+**POST** `/v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id}/archive`
+
+**Deprecated**
 
 **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
 
from line 914
 certificate is permitted; the tunnel rejects MCP traffic until a new
 certificate is added.
 
-### Path Parameters
+#### Path parameters
 
 - `tunnel_id: string`
 
from line 924
 
   ID of the Tunnel Certificate.
 
-### Header Parameters
+#### Headers
 
 - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"`
 
   Required for all Tunnel endpoints.
 
-  - `"mcp-tunnels-2026-05-19"`
-
-### Returns
+#### Returns
 
 - `id: string`
 
from line 941
   RFC 3339 datetime string indicating when the certificate was archived, or
   `null` if it is not archived.
 
+  format: date-time
+
 - `created_at: string`
 
   RFC 3339 datetime string indicating when the certificate was registered.
+
+  format: date-time
 
 - `expires_at: string or null`
 
   RFC 3339 datetime string indicating when the certificate expires, or
   `null` if it does not expire.
 
+  format: date-time
+
 - `fingerprint: string`
 
   The certificate's SHA-256 fingerprint, as a lowercase hex string.
from line 968
 
   Object type. Always `tunnel_certificate` for Tunnel Certificates.
 
-  - `"tunnel_certificate"`
-
-### Example
-
-```http
+  default: tunnel_certificate
+
+#### Example
+
+```bash
 curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID/archive \
     -X POST \
     -H 'anthropic-version: 2023-06-01' \
     -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN"
 ```
 
-#### Response
+##### Response (200)
 
 ```json
 {
from line 992
   "type": "tunnel_certificate"
 }
 ```
-
-## Domain Types
-
-### Tunnel Certificate Create Response
-
-- `TunnelCertificateCreateResponse object { id, archived_at, created_at, 4 more }`
-
-  - `id: string`
-
-    ID of the Tunnel Certificate.
-
-  - `archived_at: string or null`
-
-    RFC 3339 datetime string indicating when the certificate was archived, or
-    `null` if it is not archived.
-
-  - `created_at: string`
-
-    RFC 3339 datetime string indicating when the certificate was registered.
-
-  - `expires_at: string or null`
-
-    RFC 3339 datetime string indicating when the certificate expires, or
-    `null` if it does not expire.
-
-  - `fingerprint: string`
-
-    The certificate's SHA-256 fingerprint, as a lowercase hex string.
-
-  - `tunnel_id: string`
-
-    ID of the Tunnel this certificate is registered against.
-
-  - `type: "tunnel_certificate"`
-
-    Object type. Always `tunnel_certificate` for Tunnel Certificates.
-
-    - `"tunnel_certificate"`
-
-### Tunnel Certificate Retrieve Response
-
-- `TunnelCertificateRetrieveResponse object { id, archived_at, created_at, 4 more }`
-
-  - `id: string`
-
-    ID of the Tunnel Certificate.
-
-  - `archived_at: string or null`
-
-    RFC 3339 datetime string indicating when the certificate was archived, or
-    `null` if it is not archived.
-
-  - `created_at: string`
-
-    RFC 3339 datetime string indicating when the certificate was registered.
-
-  - `expires_at: string or null`
-
-    RFC 3339 datetime string indicating when the certificate expires, or
-    `null` if it does not expire.
-
-  - `fingerprint: string`
-
-    The certificate's SHA-256 fingerprint, as a lowercase hex string.
-
-  - `tunnel_id: string`
-
-    ID of the Tunnel this certificate is registered against.
-
-  - `type: "tunnel_certificate"`
-
-    Object type. Always `tunnel_certificate` for Tunnel Certificates.
-
-    - `"tunnel_certificate"`
-
-### Tunnel Certificate List Response
-
-- `TunnelCertificateListResponse object { id, archived_at, created_at, 4 more }`
-
-  - `id: string`
-
-    ID of the Tunnel Certificate.
-
-  - `archived_at: string or null`
-
-    RFC 3339 datetime string indicating when the certificate was archived, or
-    `null` if it is not archived.
-
-  - `created_at: string`
-
-    RFC 3339 datetime string indicating when the certificate was registered.
-
-  - `expires_at: string or null`
-
-    RFC 3339 datetime string indicating when the certificate expires, or
-    `null` if it does not expire.
-
-  - `fingerprint: string`
-
-    The certificate's SHA-256 fingerprint, as a lowercase hex string.
-
-  - `tunnel_id: string`
-
-    ID of the Tunnel this certificate is registered against.
-
-  - `type: "tunnel_certificate"`
-
-    Object type. Always `tunnel_certificate` for Tunnel Certificates.
-
-    - `"tunnel_certificate"`
-
-### Tunnel Certificate Archive Response
-
-- `TunnelCertificateArchiveResponse object { id, archived_at, created_at, 4 more }`
-
-  - `id: string`
-
-    ID of the Tunnel Certificate.
-
-  - `archived_at: string or null`
-
-    RFC 3339 datetime string indicating when the certificate was archived, or
-    `null` if it is not archived.
-
-  - `created_at: string`
-
-    RFC 3339 datetime string indicating when the certificate was registered.
-
-  - `expires_at: string or null`
-
-    RFC 3339 datetime string indicating when the certificate expires, or
-    `null` if it does not expire.
-
-  - `fingerprint: string`
-
-    The certificate's SHA-256 fingerprint, as a lowercase hex string.
-
-  - `tunnel_id: string`
-
-    ID of the Tunnel this certificate is registered against.
-
-  - `type: "tunnel_certificate"`
-
-    Object type. Always `tunnel_certificate` for Tunnel Certificates.
-
-    - `"tunnel_certificate"`
 

api/admin/mcp_tunnels First recorded · 1085 lines, first recorded

# MCP Tunnels ## Get Tunnel ### Path Parameters ### Header Parameters ### Returns ### Example #### Response ## List Tunnels ### Query Parameters ### Header Parameters ### Returns ### Example #### Response ## Reveal Tunnel Token ### Path Parameters ### Header Parameters ### Returns ### Example #### Response ## Rotate Tunnel Token ### Path Parameters ### Header Parameters ### Body Parameters ### Returns ### Example #### Response ## Archive Tunnel ### Path Parameters ### Header Parameters ### Returns ### Example #### Response ## Domain Types ### MCP Tunnel Retrieve Response ### MCP Tunnel List Response ### MCP Tunnel Reveal Token Response ### MCP Tunnel Rotate Token Response ### MCP Tunnel Archive Response # Tunnel Certificates ## Create Tunnel Certificate ### Path Parameters ### Header Parameters ### Body Parameters ### Returns ### Example #### Response ## Get Tunnel Certificate ### Path Parameters ### Header Parameters ### Returns ### Example #### Response ## List Tunnel Certificates ### Path Parameters ### Query Parameters ### Header Parameters ### Returns ### Example #### Response ## Archive Tunnel Certificate ### Path Parameters ### Header Parameters ### Returns ### Example #### Response ## Domain Types ### Tunnel Certificate Create Response ### Tunnel Certificate Retrieve Response ### Tunnel Certificate List Response ### Tunnel Certificate Archive Response

The first capture of this source. The page was already there, and this is what it said.

---
title: MCP Tunnels
url: https://platform.claude.com/docs/en/api/admin/mcp_tunnels
---

# MCP Tunnels

## Get Tunnel

**get** `/v1/organizations/tunnels/{tunnel_id}`

**Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.

Retrieve a single tunnel in the caller's organization by ID.

### Path Parameters

- `tunnel_id: string`

  ID of the Tunnel.

### Header Parameters

- `"anthropic-beta": array of "mcp-tunnels-2026-05-19"`

  Required for all Tunnel endpoints.

  - `"mcp-tunnels-2026-05-19"`

### Returns

- `id: string`

  ID of the Tunnel.

- `archived_at: string or null`

  RFC 3339 datetime string indicating when the Tunnel was archived, or
  `null` if it is not archived.

- `created_at: string`

  RFC 3339 datetime string indicating when the Tunnel was created.

- `display_name: string or null`

  Human-readable name for the Tunnel (1–255 characters), or `null` if unset.

- `domain: string`

  Anthropic-assigned hostname for the Tunnel. MCP server URLs whose host is a
  subdomain of this value are routed through the Tunnel. Globally unique and
  never reused, even after the Tunnel is archived.

- `type: "tunnel"`

  Object type. Always `tunnel` for Tunnels.

  - `"tunnel"`

- `workspace_id: string or null`

  ID of the Workspace this Tunnel belongs to, or `null` for the default
  Workspace. Immutable after creation.

### Example

```http
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID \
    -H 'anthropic-version: 2023-06-01' \
    -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN"
```

#### Response

```json
{
  "id": "tnl_01Hx9Kp2RtQvMn3sWbYdLcF8",
  "archived_at": "2024-11-01T23:59:27.427722Z",
  "created_at": "2024-10-30T23:58:27.427722Z",
  "display_name": "Production",
  "domain": "a1b2c3d4.tunnel.anthropic.com",
  "type": "tunnel",
  "workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
}
```

## List Tunnels

**get** `/v1/organizations/tunnels`

**Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.

List the organization's tunnels.

Results span the caller's organization, ordered by creation time
(newest first). Use `workspace_id` to filter to a single workspace;
archived tunnels are excluded unless `include_archived` is set.

### Query Parameters

- `include_archived: optional boolean`

  Include archived tunnels in the results. Archived tunnels are excluded by
  default.

- `limit: optional number`

  Maximum number of tunnels to return in a single page.

- `page: optional string`

  Opaque pagination cursor from a previous response's `next_page`. Omit to
  fetch the first page.

- `workspace_id: optional string`

  Return only tunnels in this Workspace. Accepts a `wrkspc_`-prefixed
  Workspace ID; omit to list tunnels across all Workspaces.

### Header Parameters

- `"anthropic-beta": array of "mcp-tunnels-2026-05-19"`

  Required for all Tunnel endpoints.

  - `"mcp-tunnels-2026-05-19"`

### Returns

- `data: array of object { id, archived_at, created_at, 4 more }`

  - `id: string`

    ID of the Tunnel.

  - `archived_at: string or null`

    RFC 3339 datetime string indicating when the Tunnel was archived, or
    `null` if it is not archived.

  - `created_at: string`

    RFC 3339 datetime string indicating when the Tunnel was created.

  - `display_name: string or null`

    Human-readable name for the Tunnel (1–255 characters), or `null` if unset.

  - `domain: string`

    Anthropic-assigned hostname for the Tunnel. MCP server URLs whose host is a
    subdomain of this value are routed through the Tunnel. Globally unique and
    never reused, even after the Tunnel is archived.

  - `type: "tunnel"`

    Object type. Always `tunnel` for Tunnels.

    - `"tunnel"`

  - `workspace_id: string or null`

    ID of the Workspace this Tunnel belongs to, or `null` for the default
    Workspace. Immutable after creation.

- `next_page: string or null`

  Opaque cursor for the next page, or `null` if there are no more results.

### Example

```http
curl https://api.anthropic.com/v1/organizations/tunnels \
    -H 'anthropic-version: 2023-06-01' \
    -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN"
```

#### Response

```json
{
  "data": [
    {
      "id": "tnl_01Hx9Kp2RtQvMn3sWbYdLcF8",
      "archived_at": "2024-11-01T23:59:27.427722Z",
      "created_at": "2024-10-30T23:58:27.427722Z",
      "display_name": "Production",
      "domain": "a1b2c3d4.tunnel.anthropic.com",
      "type": "tunnel",
      "workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
    }
  ],
  "next_page": "page_MjAyNS0wNS0xNFQwMDowMDowMFo="
}
```

## Reveal Tunnel Token

**post** `/v1/organizations/tunnels/{tunnel_id}/reveal_token`

**Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.

Return the tunnel's current connection token.

The value is fetched live on each call; Anthropic does not store it.
Repeated calls return the same value until the token is rotated.
Exposed as `POST` so the token does not appear in intermediary
access logs.

### Path Parameters

- `tunnel_id: string`

  ID of the Tunnel.

### Header Parameters

- `"anthropic-beta": array of "mcp-tunnels-2026-05-19"`

  Required for all Tunnel endpoints.

  - `"mcp-tunnels-2026-05-19"`

### Returns

- `id: string`

  Stable identifier for the current token value. Changes when the token is
  rotated.

- `tunnel_token: string`

  The tunnel's connection token.

- `type: "tunnel_token"`

  Object type. Always `tunnel_token` for Tunnel Tokens.

  - `"tunnel_token"`

### Example

```http
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/reveal_token \
    -X POST \
    -H 'anthropic-version: 2023-06-01' \
    -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN"
```

#### Response

```json
{
  "id": "ttkn_bb97000eaec162831399ca9b6684a4fdf5be49ace5683057b017aab5c87e19e0",
  "tunnel_token": "eyJhIjoiRVhBTVBMRSIsInQiOiJFWEFNUExFIiwicyI6IkVYQU1QTEUifQ==",
  "type": "tunnel_token"
}
```

## Rotate Tunnel Token

**post** `/v1/organizations/tunnels/{tunnel_id}/rotate_token`

**Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.

Invalidate the tunnel's current token for new connections and return a fresh value.

Established connections are not severed by rotation; a connector
restarted after rotation must use the new value. An optional
`reason` is captured for operational context.

### Path Parameters

- `tunnel_id: string`

  ID of the Tunnel.

### Header Parameters

- `"anthropic-beta": array of "mcp-tunnels-2026-05-19"`

  Required for all Tunnel endpoints.

  - `"mcp-tunnels-2026-05-19"`

### Body Parameters

- `reason: optional string or null`

  Optional free-text reason for the rotation, recorded for audit.

### Returns

- `id: string`

  Stable identifier for the current token value. Changes when the token is
  rotated.

- `tunnel_token: string`

Cut at 300 lines.