# Tunnel Certificates ## Create Tunnel Certificate ### Path Parameters ### Header Parameters ### Body Parameters ### Returns ### Example #### Response ## Get Tunnel Certificate ### Path Parameters ### Header Parameters ### Returns ### Example #### Response ## List Tunnel Certificates ### Path Parameters ### Query Parameters ### Header Parameters ### Returns ### Example #### Response ## Archive Tunnel Certificate ### Path Parameters ### Header Parameters ### Returns ### Example #### Response ## Domain Types ### Tunnel Certificate Create Response ### Tunnel Certificate Retrieve Response ### Tunnel Certificate List Response ### Tunnel Certificate Archive Response
The whole hunk
522 lines, first recordedThe first capture of this source. The page was already there, and this is what it said.
---
title: Tunnel Certificates
url: https://platform.claude.com/docs/en/api/admin/mcp_tunnels/tunnel_certificates
---
# Tunnel Certificates
## Create Tunnel Certificate
**post** `/v1/organizations/tunnels/{tunnel_id}/certificates`
**Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
Register a public CA certificate for the tunnel.
Anthropic verifies the gateway's server certificate against this CA
when it terminates the inner TLS session. The PEM body must contain
exactly one X.509 certificate and no private-key material. A tunnel
holds at most two non-archived certificates.
### Path Parameters
- `tunnel_id: string`
ID of the Tunnel.
### Header Parameters
- `"anthropic-beta": array of "mcp-tunnels-2026-05-19"`
Required for all Tunnel endpoints.
- `"mcp-tunnels-2026-05-19"`
### Body Parameters
- `ca_certificate_pem: string`
PEM-encoded X.509 CA certificate. Must contain exactly one certificate and
no private-key material.
### Returns
- `id: string`
ID of the Tunnel Certificate.
- `archived_at: string or null`
RFC 3339 datetime string indicating when the certificate was archived, or
`null` if it is not archived.
- `created_at: string`
RFC 3339 datetime string indicating when the certificate was registered.
- `expires_at: string or null`
RFC 3339 datetime string indicating when the certificate expires, or
`null` if it does not expire.
- `fingerprint: string`
The certificate's SHA-256 fingerprint, as a lowercase hex string.
- `tunnel_id: string`
ID of the Tunnel this certificate is registered against.
- `type: "tunnel_certificate"`
Object type. Always `tunnel_certificate` for Tunnel Certificates.
- `"tunnel_certificate"`
### Example
```http
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \
-d '{
"ca_certificate_pem": "-----BEGIN CERTIFICATE-----\nMIIBexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexa\n...illustrative placeholder, not a real certificate...\n-----END CERTIFICATE-----\n"
}'
```
#### Response
```json
{
"id": "tcrt_01JmWq4ZxnBvR7tKpY2sLdH9",
"archived_at": "2024-11-01T23:59:27.427722Z",
"created_at": "2024-10-30T23:58:27.427722Z",
"expires_at": "2024-10-30T23:58:27.427722Z",
"fingerprint": "9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08",
"tunnel_id": "tnl_01Hx9Kp2RtQvMn3sWbYdLcF8",
"type": "tunnel_certificate"
}
```
## Get Tunnel Certificate
**get** `/v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id}`
**Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
Retrieve a single certificate registered on a tunnel by ID.
### Path Parameters
- `tunnel_id: string`
ID of the Tunnel.
- `certificate_id: string`
ID of the Tunnel Certificate.
### Header Parameters
- `"anthropic-beta": array of "mcp-tunnels-2026-05-19"`
Required for all Tunnel endpoints.
- `"mcp-tunnels-2026-05-19"`
### Returns
- `id: string`
ID of the Tunnel Certificate.
- `archived_at: string or null`
RFC 3339 datetime string indicating when the certificate was archived, or
`null` if it is not archived.
- `created_at: string`
RFC 3339 datetime string indicating when the certificate was registered.
- `expires_at: string or null`
RFC 3339 datetime string indicating when the certificate expires, or
`null` if it does not expire.
- `fingerprint: string`
The certificate's SHA-256 fingerprint, as a lowercase hex string.
- `tunnel_id: string`
ID of the Tunnel this certificate is registered against.
- `type: "tunnel_certificate"`
Object type. Always `tunnel_certificate` for Tunnel Certificates.
- `"tunnel_certificate"`
### Example
```http
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID \
-H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN"
```
#### Response
```json
{
"id": "tcrt_01JmWq4ZxnBvR7tKpY2sLdH9",
"archived_at": "2024-11-01T23:59:27.427722Z",
"created_at": "2024-10-30T23:58:27.427722Z",
"expires_at": "2024-10-30T23:58:27.427722Z",
"fingerprint": "9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08",
"tunnel_id": "tnl_01Hx9Kp2RtQvMn3sWbYdLcF8",
"type": "tunnel_certificate"
}
```
## List Tunnel Certificates
**get** `/v1/organizations/tunnels/{tunnel_id}/certificates`
**Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
List the certificates registered on a tunnel.
Archived certificates are excluded unless `include_archived` is set.
### Path Parameters
- `tunnel_id: string`
ID of the Tunnel.
### Query Parameters
- `include_archived: optional boolean`
Include archived certificates in the results. Archived certificates are
excluded by default.
- `limit: optional number`
Maximum number of certificates to return.
- `page: optional string`
A tunnel has at most two active certificates, so this list is not
paginated.
### Header Parameters
- `"anthropic-beta": array of "mcp-tunnels-2026-05-19"`
Required for all Tunnel endpoints.
- `"mcp-tunnels-2026-05-19"`
### Returns
- `data: array of object { id, archived_at, created_at, 4 more }`
- `id: string`
ID of the Tunnel Certificate.
- `archived_at: string or null`
RFC 3339 datetime string indicating when the certificate was archived, or
`null` if it is not archived.
- `created_at: string`
RFC 3339 datetime string indicating when the certificate was registered.
- `expires_at: string or null`
RFC 3339 datetime string indicating when the certificate expires, or
`null` if it does not expire.
- `fingerprint: string`
The certificate's SHA-256 fingerprint, as a lowercase hex string.
- `tunnel_id: string`
ID of the Tunnel this certificate is registered against.
- `type: "tunnel_certificate"`
Object type. Always `tunnel_certificate` for Tunnel Certificates.
- `"tunnel_certificate"`
- `next_page: string or null`
Opaque cursor for the next page, or `null` if there are no more results.
### Example
```http
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \
-H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN"
```
#### Response
```json
{
"data": [
{
"id": "tcrt_01JmWq4ZxnBvR7tKpY2sLdH9",
"archived_at": "2024-11-01T23:59:27.427722Z",
"created_at": "2024-10-30T23:58:27.427722Z",
"expires_at": "2024-10-30T23:58:27.427722Z",
"fingerprint": "9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08",
"tunnel_id": "tnl_01Hx9Kp2RtQvMn3sWbYdLcF8",
"type": "tunnel_certificate"
}
],
"next_page": "page_MjAyNS0wNS0xNFQwMDowMDowMFo="
}
```
## Archive Tunnel Certificate
**post** `/v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id}/archive`
**Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
Archive a certificate, removing it from the set Anthropic trusts for this tunnel.
The certificate record is retained. Archiving the last non-archived
certificate is permitted; the tunnel rejects MCP traffic until a new
Cut at 300 lines. The page has the rest.