MCP Tunnels
api/admin/mcp_tunnels
Nearest release: v2.1.245, published an hour after this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
api/admin/mcp_tunnels Changed · +174 / -265 lines
### Path parameters ### Headers #### Response (200) ### Query parameters ### Headers #### Response (200) ### Path parameters ### Headers #### Response (200) ### Path parameters ### Headers ### Body parameters #### Response (200) ### Path parameters ### Headers #### Response (200) ## Domain types ## MCP Tunnels › Tunnel Certificates ### Create Tunnel Certificate #### Path parameters #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### Get Tunnel Certificate #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ### List Tunnel Certificates #### Path parameters #### Query parameters #### Headers #### Returns #### Example ##### Response (200) ### Archive Tunnel Certificate #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ### Path Parameters ### Header Parameters #### Response ### Query Parameters ### Header Parameters #### Response ### Path Parameters ### Header Parameters #### Response ### Path Parameters ### Header Parameters ### Body Parameters #### Response ### Path Parameters ### Header Parameters #### Response ## Domain Types # Tunnel Certificates ## Create Tunnel Certificate ### Path Parameters ### Header Parameters ### Body Parameters #### Response ## Get Tunnel Certificate ### Path Parameters ### Header Parameters #### Response ## List Tunnel Certificates ### Path Parameters ### Query Parameters ### Header Parameters #### Response ## Archive Tunnel Certificate ### Path Parameters ### Header Parameters #### Response ## Domain Types ### Tunnel Certificate Create Response ### Tunnel Certificate Retrieve Response ### Tunnel Certificate List Response ### Tunnel Certificate Archive Response
The two sides of this change are too far apart to line up, so this is the differ's own diff of it.
---- -title: MCP Tunnels -url: https://platform.claude.com/docs/en/api/admin/mcp_tunnels ---- - # MCP Tunnels ## Get Tunnel -**get** `/v1/organizations/tunnels/{tunnel_id}` +**GET** `/v1/organizations/tunnels/{tunnel_id}` + +**Deprecated** **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window. Retrieve a single tunnel in the caller's organization by ID. -### Path Parameters +### Path parameters - `tunnel_id: string` ID of the Tunnel. -### Header Parameters +### Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - - `"mcp-tunnels-2026-05-19"` ### Returns
RFC 3339 datetime string indicating when the Tunnel was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the Tunnel was created. + + format: date-time - `display_name: string or null`
Object type. Always `tunnel` for Tunnels. - - `"tunnel"` + default: tunnel - `workspace_id: string or null`
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
## List Tunnels -**get** `/v1/organizations/tunnels` +**GET** `/v1/organizations/tunnels` + +**Deprecated** **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
(newest first). Use `workspace_id` to filter to a single workspace; archived tunnels are excluded unless `include_archived` is set. -### Query Parameters +### Query parameters - `include_archived: optional boolean` Include archived tunnels in the results. Archived tunnels are excluded by default. + default: false + - `limit: optional number` Maximum number of tunnels to return in a single page. + + default: 20, maximum: 1000, minimum: 1 - `page: optional string`
Return only tunnels in this Workspace. Accepts a `wrkspc_`-prefixed Workspace ID; omit to list tunnels across all Workspaces. -### Header Parameters +### Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - `"mcp-tunnels-2026-05-19"` - ### Returns -- `data: array of object { id, archived_at, created_at, 4 more }` +- `data: array of object` - `id: string`
RFC 3339 datetime string indicating when the Tunnel was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the Tunnel was created. + + format: date-time - `display_name: string or null`
Object type. Always `tunnel` for Tunnels. - - `"tunnel"` + default: tunnel - `workspace_id: string or null`
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/tunnels \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
## Reveal Tunnel Token -**post** `/v1/organizations/tunnels/{tunnel_id}/reveal_token` +**POST** `/v1/organizations/tunnels/{tunnel_id}/reveal_token` + +**Deprecated** **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
Exposed as `POST` so the token does not appear in intermediary access logs. -### Path Parameters +### Path parameters - `tunnel_id: string` ID of the Tunnel. -### Header Parameters +### Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - - `"mcp-tunnels-2026-05-19"` ### Returns
Object type. Always `tunnel_token` for Tunnel Tokens. - - `"tunnel_token"` + default: tunnel_token ### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/reveal_token \ -X POST \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
## Rotate Tunnel Token -**post** `/v1/organizations/tunnels/{tunnel_id}/rotate_token` +**POST** `/v1/organizations/tunnels/{tunnel_id}/rotate_token` + +**Deprecated** **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
restarted after rotation must use the new value. An optional `reason` is captured for operational context. -### Path Parameters +### Path parameters - `tunnel_id: string` ID of the Tunnel. -### Header Parameters +### Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - `"mcp-tunnels-2026-05-19"` - -### Body Parameters +### Body parameters - `reason: optional string or null` Optional free-text reason for the rotation, recorded for audit. + + maxLength: 1024 ### Returns
Object type. Always `tunnel_token` for Tunnel Tokens. - - `"tunnel_token"` + default: tunnel_token ### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/rotate_token \ -X POST \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
## Archive Tunnel -**post** `/v1/organizations/tunnels/{tunnel_id}/archive` +**POST** `/v1/organizations/tunnels/{tunnel_id}/archive` + +**Deprecated** **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
tunnel token is invalidated. Retrying against an already-archived tunnel returns the existing record unchanged. -### Path Parameters +### Path parameters - `tunnel_id: string` ID of the Tunnel. -### Header Parameters +### Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - - `"mcp-tunnels-2026-05-19"` ### Returns
RFC 3339 datetime string indicating when the Tunnel was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the Tunnel was created. + + format: date-time - `display_name: string or null`
Object type. Always `tunnel` for Tunnels. - - `"tunnel"` + default: tunnel - `workspace_id: string or null`
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
} ``` -## Domain Types +## Domain types ### MCP Tunnel Retrieve Response -- `MCPTunnelRetrieveResponse object { id, archived_at, created_at, 4 more }` +- `MCPTunnelRetrieveResponse object` - `id: string`
RFC 3339 datetime string indicating when the Tunnel was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the Tunnel was created. + + format: date-time - `display_name: string or null`
Object type. Always `tunnel` for Tunnels. - - `"tunnel"` + default: tunnel - `workspace_id: string or null`
### MCP Tunnel List Response -- `MCPTunnelListResponse object { id, archived_at, created_at, 4 more }` +- `MCPTunnelListResponse object` - `id: string`
RFC 3339 datetime string indicating when the Tunnel was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the Tunnel was created. + + format: date-time - `display_name: string or null`
Object type. Always `tunnel` for Tunnels. - - `"tunnel"` + default: tunnel - `workspace_id: string or null`
### MCP Tunnel Reveal Token Response -- `MCPTunnelRevealTokenResponse object { id, tunnel_token, type }` +- `MCPTunnelRevealTokenResponse object` - `id: string`
Object type. Always `tunnel_token` for Tunnel Tokens. - - `"tunnel_token"` + default: tunnel_token ### MCP Tunnel Rotate Token Response -- `MCPTunnelRotateTokenResponse object { id, tunnel_token, type }` +- `MCPTunnelRotateTokenResponse object` - `id: string`
Object type. Always `tunnel_token` for Tunnel Tokens. - - `"tunnel_token"` + default: tunnel_token ### MCP Tunnel Archive Response -- `MCPTunnelArchiveResponse object { id, archived_at, created_at, 4 more }` +- `MCPTunnelArchiveResponse object` - `id: string`
RFC 3339 datetime string indicating when the Tunnel was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the Tunnel was created. + + format: date-time - `display_name: string or null`
Object type. Always `tunnel` for Tunnels. - - `"tunnel"` + default: tunnel - `workspace_id: string or null` ID of the Workspace this Tunnel belongs to, or `null` for the default Workspace. Immutable after creation. -# Tunnel Certificates - -## Create Tunnel Certificate - -**post** `/v1/organizations/tunnels/{tunnel_id}/certificates` +## MCP Tunnels › Tunnel Certificates + +### Create Tunnel Certificate + +**POST** `/v1/organizations/tunnels/{tunnel_id}/certificates` + +**Deprecated** **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
exactly one X.509 certificate and no private-key material. A tunnel holds at most two non-archived certificates. -### Path Parameters +#### Path parameters - `tunnel_id: string` ID of the Tunnel. -### Header Parameters +#### Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - `"mcp-tunnels-2026-05-19"` - -### Body Parameters +#### Body parameters - `ca_certificate_pem: string` PEM-encoded X.509 CA certificate. Must contain exactly one certificate and no private-key material. -### Returns + maxLength: 8192 + +#### Returns - `id: string`
RFC 3339 datetime string indicating when the certificate was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the certificate was registered. + + format: date-time - `expires_at: string or null` RFC 3339 datetime string indicating when the certificate expires, or `null` if it does not expire. + format: date-time + - `fingerprint: string` The certificate's SHA-256 fingerprint, as a lowercase hex string.
Object type. Always `tunnel_certificate` for Tunnel Certificates. - - `"tunnel_certificate"` - -### Example - -```http + default: tunnel_certificate + +#### Example + +```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +##### Response (200) ```json {
} ``` -## Get Tunnel Certificate - -**get** `/v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id}` +### Get Tunnel Certificate + +**GET** `/v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id}` + +**Deprecated** **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window. Retrieve a single certificate registered on a tunnel by ID. -### Path Parameters +#### Path parameters - `tunnel_id: string`
ID of the Tunnel Certificate. -### Header Parameters +#### Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - `"mcp-tunnels-2026-05-19"` - -### Returns +#### Returns - `id: string`
RFC 3339 datetime string indicating when the certificate was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the certificate was registered. + + format: date-time - `expires_at: string or null` RFC 3339 datetime string indicating when the certificate expires, or `null` if it does not expire. + format: date-time + - `fingerprint: string` The certificate's SHA-256 fingerprint, as a lowercase hex string.
Object type. Always `tunnel_certificate` for Tunnel Certificates. - - `"tunnel_certificate"` - -### Example - -```http + default: tunnel_certificate + +#### Example + +```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +##### Response (200) ```json {
} ``` -## List Tunnel Certificates - -**get** `/v1/organizations/tunnels/{tunnel_id}/certificates` +### List Tunnel Certificates + +**GET** `/v1/organizations/tunnels/{tunnel_id}/certificates` + +**Deprecated** **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
Archived certificates are excluded unless `include_archived` is set. -### Path Parameters +#### Path parameters - `tunnel_id: string` ID of the Tunnel. -### Query Parameters +#### Query parameters - `include_archived: optional boolean` Include archived certificates in the results. Archived certificates are excluded by default. + default: false + - `limit: optional number` Maximum number of certificates to return. + + default: 20, maximum: 1000, minimum: 1 - `page: optional string` A tunnel has at most two active certificates, so this list is not paginated. -### Header Parameters +#### Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - `"mcp-tunnels-2026-05-19"` - -### Returns - -- `data: array of object { id, archived_at, created_at, 4 more }` +#### Returns + +- `data: array of object` - `id: string`
RFC 3339 datetime string indicating when the certificate was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the certificate was registered. + + format: date-time - `expires_at: string or null` RFC 3339 datetime string indicating when the certificate expires, or `null` if it does not expire. + format: date-time + - `fingerprint: string` The certificate's SHA-256 fingerprint, as a lowercase hex string.
Object type. Always `tunnel_certificate` for Tunnel Certificates. - - `"tunnel_certificate"` + default: tunnel_certificate - `next_page: string or null` Opaque cursor for the next page, or `null` if there are no more results. -### Example - -```http +#### Example + +```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +##### Response (200) ```json {
} ``` -## Archive Tunnel Certificate - -**post** `/v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id}/archive` +### Archive Tunnel Certificate + +**POST** `/v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id}/archive` + +**Deprecated** **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
certificate is permitted; the tunnel rejects MCP traffic until a new certificate is added. -### Path Parameters +#### Path parameters - `tunnel_id: string`
ID of the Tunnel Certificate. -### Header Parameters +#### Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - `"mcp-tunnels-2026-05-19"` - -### Returns +#### Returns - `id: string`
RFC 3339 datetime string indicating when the certificate was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the certificate was registered. + + format: date-time - `expires_at: string or null` RFC 3339 datetime string indicating when the certificate expires, or `null` if it does not expire. + format: date-time + - `fingerprint: string` The certificate's SHA-256 fingerprint, as a lowercase hex string.
Object type. Always `tunnel_certificate` for Tunnel Certificates. - - `"tunnel_certificate"` - -### Example - -```http + default: tunnel_certificate + +#### Example + +```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +##### Response (200) ```json {
"type": "tunnel_certificate" } ``` - -## Domain Types - -### Tunnel Certificate Create Response - -- `TunnelCertificateCreateResponse object { id, archived_at, created_at, 4 more }` - - - `id: string` - - ID of the Tunnel Certificate. - - - `archived_at: string or null` - - RFC 3339 datetime string indicating when the certificate was archived, or - `null` if it is not archived. - - - `created_at: string` - - RFC 3339 datetime string indicating when the certificate was registered. - - - `expires_at: string or null` - - RFC 3339 datetime string indicating when the certificate expires, or - `null` if it does not expire. - - - `fingerprint: string` - - The certificate's SHA-256 fingerprint, as a lowercase hex string. - - - `tunnel_id: string` - - ID of the Tunnel this certificate is registered against. - - - `type: "tunnel_certificate"` - - Object type. Always `tunnel_certificate` for Tunnel Certificates. - - - `"tunnel_certificate"` - -### Tunnel Certificate Retrieve Response - -- `TunnelCertificateRetrieveResponse object { id, archived_at, created_at, 4 more }` - - - `id: string` - - ID of the Tunnel Certificate. - - - `archived_at: string or null` - - RFC 3339 datetime string indicating when the certificate was archived, or - `null` if it is not archived. - - - `created_at: string` - - RFC 3339 datetime string indicating when the certificate was registered. - - - `expires_at: string or null` - - RFC 3339 datetime string indicating when the certificate expires, or - `null` if it does not expire. - - - `fingerprint: string` - - The certificate's SHA-256 fingerprint, as a lowercase hex string. - - - `tunnel_id: string` - - ID of the Tunnel this certificate is registered against. - - - `type: "tunnel_certificate"` - - Object type. Always `tunnel_certificate` for Tunnel Certificates. - - - `"tunnel_certificate"` - -### Tunnel Certificate List Response - -- `TunnelCertificateListResponse object { id, archived_at, created_at, 4 more }` - - - `id: string` - - ID of the Tunnel Certificate. - - - `archived_at: string or null` - - RFC 3339 datetime string indicating when the certificate was archived, or - `null` if it is not archived. - - - `created_at: string` - - RFC 3339 datetime string indicating when the certificate was registered. - - - `expires_at: string or null` - - RFC 3339 datetime string indicating when the certificate expires, or - `null` if it does not expire. - - - `fingerprint: string` - - The certificate's SHA-256 fingerprint, as a lowercase hex string. - - - `tunnel_id: string` - - ID of the Tunnel this certificate is registered against. - - - `type: "tunnel_certificate"` - - Object type. Always `tunnel_certificate` for Tunnel Certificates. - - - `"tunnel_certificate"` - -### Tunnel Certificate Archive Response - -- `TunnelCertificateArchiveResponse object { id, archived_at, created_at, 4 more }` - - - `id: string` - - ID of the Tunnel Certificate. - - - `archived_at: string or null` - - RFC 3339 datetime string indicating when the certificate was archived, or - `null` if it is not archived. - - - `created_at: string` - - RFC 3339 datetime string indicating when the certificate was registered. - - - `expires_at: string or null` - - RFC 3339 datetime string indicating when the certificate expires, or - `null` if it does not expire. - - - `fingerprint: string` - - The certificate's SHA-256 fingerprint, as a lowercase hex string. - - - `tunnel_id: string` - - ID of the Tunnel this certificate is registered against. - - - `type: "tunnel_certificate"` - - Object type. Always `tunnel_certificate` for Tunnel Certificates. - - - `"tunnel_certificate"`