Tunnel Certificates
api/admin/mcp_tunnels/tunnel_certificates
Nearest release: v2.1.245, published an hour after this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
api/admin/mcp_tunnels/tunnel_certificates Changed · +98 / -49 lines
### Path parameters ### Headers ### Body parameters #### Response (200) ### Path parameters ### Headers #### Response (200) ### Path parameters ### Query parameters ### Headers #### Response (200) ### Path parameters ### Headers #### Response (200) ## Domain types ### Path Parameters ### Header Parameters ### Body Parameters #### Response ### Path Parameters ### Header Parameters #### Response ### Path Parameters ### Query Parameters ### Header Parameters #### Response ### Path Parameters ### Header Parameters #### Response ## Domain Types
---- -title: Tunnel Certificates -url: https://platform.claude.com/docs/en/api/admin/mcp_tunnels/tunnel_certificates ---- - # Tunnel Certificates ## Create Tunnel Certificate -**post** `/v1/organizations/tunnels/{tunnel_id}/certificates` +**POST** `/v1/organizations/tunnels/{tunnel_id}/certificates` +**Deprecated** + **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window. Register a public CA certificate for the tunnel.
exactly one X.509 certificate and no private-key material. A tunnel holds at most two non-archived certificates. -### Path Parameters +### Path parameters - `tunnel_id: string` ID of the Tunnel. -### Header Parameters +### Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - `"mcp-tunnels-2026-05-19"` +### Body parameters -### Body Parameters - - `ca_certificate_pem: string` PEM-encoded X.509 CA certificate. Must contain exactly one certificate and no private-key material. + maxLength: 8192 + ### Returns - `id: string`
RFC 3339 datetime string indicating when the certificate was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the certificate was registered. + format: date-time + - `expires_at: string or null` RFC 3339 datetime string indicating when the certificate expires, or `null` if it does not expire. + format: date-time + - `fingerprint: string` The certificate's SHA-256 fingerprint, as a lowercase hex string.
Object type. Always `tunnel_certificate` for Tunnel Certificates. - - `"tunnel_certificate"` + default: tunnel_certificate ### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +#### Response (200) ```json {
## Get Tunnel Certificate -**get** `/v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id}` +**GET** `/v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id}` +**Deprecated** + **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window. Retrieve a single certificate registered on a tunnel by ID. -### Path Parameters +### Path parameters - `tunnel_id: string`
ID of the Tunnel Certificate. -### Header Parameters +### Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - `"mcp-tunnels-2026-05-19"` - ### Returns - `id: string`
RFC 3339 datetime string indicating when the certificate was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the certificate was registered. + format: date-time + - `expires_at: string or null` RFC 3339 datetime string indicating when the certificate expires, or `null` if it does not expire. + format: date-time + - `fingerprint: string` The certificate's SHA-256 fingerprint, as a lowercase hex string.
Object type. Always `tunnel_certificate` for Tunnel Certificates. - - `"tunnel_certificate"` + default: tunnel_certificate ### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
## List Tunnel Certificates -**get** `/v1/organizations/tunnels/{tunnel_id}/certificates` +**GET** `/v1/organizations/tunnels/{tunnel_id}/certificates` +**Deprecated** + **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window. List the certificates registered on a tunnel.
Archived certificates are excluded unless `include_archived` is set. -### Path Parameters +### Path parameters - `tunnel_id: string` ID of the Tunnel. -### Query Parameters +### Query parameters - `include_archived: optional boolean`
Include archived certificates in the results. Archived certificates are excluded by default. + default: false + - `limit: optional number` Maximum number of certificates to return. + default: 20, maximum: 1000, minimum: 1 + - `page: optional string` A tunnel has at most two active certificates, so this list is not paginated. -### Header Parameters +### Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - `"mcp-tunnels-2026-05-19"` - ### Returns -- `data: array of object { id, archived_at, created_at, 4 more }` +- `data: array of object` - `id: string`
RFC 3339 datetime string indicating when the certificate was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the certificate was registered. + format: date-time + - `expires_at: string or null` RFC 3339 datetime string indicating when the certificate expires, or `null` if it does not expire. + format: date-time + - `fingerprint: string` The certificate's SHA-256 fingerprint, as a lowercase hex string.
Object type. Always `tunnel_certificate` for Tunnel Certificates. - - `"tunnel_certificate"` + default: tunnel_certificate - `next_page: string or null`
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
## Archive Tunnel Certificate -**post** `/v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id}/archive` +**POST** `/v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id}/archive` +**Deprecated** + **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window. Archive a certificate, removing it from the set Anthropic trusts for this tunnel.
certificate is permitted; the tunnel rejects MCP traffic until a new certificate is added. -### Path Parameters +### Path parameters - `tunnel_id: string`
ID of the Tunnel Certificate. -### Header Parameters +### Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - `"mcp-tunnels-2026-05-19"` - ### Returns - `id: string`
RFC 3339 datetime string indicating when the certificate was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the certificate was registered. + format: date-time + - `expires_at: string or null` RFC 3339 datetime string indicating when the certificate expires, or `null` if it does not expire. + format: date-time + - `fingerprint: string` The certificate's SHA-256 fingerprint, as a lowercase hex string.
Object type. Always `tunnel_certificate` for Tunnel Certificates. - - `"tunnel_certificate"` + default: tunnel_certificate ### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
} ``` -## Domain Types +## Domain types ### Tunnel Certificate Create Response -- `TunnelCertificateCreateResponse object { id, archived_at, created_at, 4 more }` +- `TunnelCertificateCreateResponse object` - `id: string`
RFC 3339 datetime string indicating when the certificate was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the certificate was registered. + format: date-time + - `expires_at: string or null` RFC 3339 datetime string indicating when the certificate expires, or `null` if it does not expire. + format: date-time + - `fingerprint: string` The certificate's SHA-256 fingerprint, as a lowercase hex string.
Object type. Always `tunnel_certificate` for Tunnel Certificates. - - `"tunnel_certificate"` + default: tunnel_certificate ### Tunnel Certificate Retrieve Response -- `TunnelCertificateRetrieveResponse object { id, archived_at, created_at, 4 more }` +- `TunnelCertificateRetrieveResponse object` - `id: string`
RFC 3339 datetime string indicating when the certificate was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the certificate was registered. + format: date-time + - `expires_at: string or null` RFC 3339 datetime string indicating when the certificate expires, or `null` if it does not expire. + format: date-time + - `fingerprint: string` The certificate's SHA-256 fingerprint, as a lowercase hex string.
Object type. Always `tunnel_certificate` for Tunnel Certificates. - - `"tunnel_certificate"` + default: tunnel_certificate ### Tunnel Certificate List Response -- `TunnelCertificateListResponse object { id, archived_at, created_at, 4 more }` +- `TunnelCertificateListResponse object` - `id: string`
RFC 3339 datetime string indicating when the certificate was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the certificate was registered. + format: date-time + - `expires_at: string or null` RFC 3339 datetime string indicating when the certificate expires, or `null` if it does not expire. + format: date-time + - `fingerprint: string` The certificate's SHA-256 fingerprint, as a lowercase hex string.
Object type. Always `tunnel_certificate` for Tunnel Certificates. - - `"tunnel_certificate"` + default: tunnel_certificate ### Tunnel Certificate Archive Response -- `TunnelCertificateArchiveResponse object { id, archived_at, created_at, 4 more }` +- `TunnelCertificateArchiveResponse object` - `id: string`
RFC 3339 datetime string indicating when the certificate was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the certificate was registered. + format: date-time + - `expires_at: string or null` RFC 3339 datetime string indicating when the certificate expires, or `null` if it does not expire. + format: date-time + - `fingerprint: string` The certificate's SHA-256 fingerprint, as a lowercase hex string.
Object type. Always `tunnel_certificate` for Tunnel Certificates. - - `"tunnel_certificate"` + default: tunnel_certificate