Create Tunnel Certificate
api/admin/mcp_tunnels/tunnel_certificates/create
Nearest release: v2.1.245, published an hour after this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
api/admin/mcp_tunnels/tunnel_certificates/create Changed · +19 / -16 lines
# Create Tunnel Certificate ## Path parameters ## Headers ## Body parameters ## Returns ## Example ### Response (200) ## Create Tunnel Certificate ### Path Parameters ### Header Parameters ### Body Parameters ### Returns ### Example #### Response
---- -title: Create Tunnel Certificate -url: https://platform.claude.com/docs/en/api/admin/mcp_tunnels/tunnel_certificates/create ---- +# Create Tunnel Certificate -## Create Tunnel Certificate +**POST** `/v1/organizations/tunnels/{tunnel_id}/certificates` -**post** `/v1/organizations/tunnels/{tunnel_id}/certificates` +**Deprecated** **Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.
exactly one X.509 certificate and no private-key material. A tunnel holds at most two non-archived certificates. -### Path Parameters +## Path parameters - `tunnel_id: string` ID of the Tunnel. -### Header Parameters +## Headers - `"anthropic-beta": array of "mcp-tunnels-2026-05-19"` Required for all Tunnel endpoints. - - `"mcp-tunnels-2026-05-19"` +## Body parameters -### Body Parameters - - `ca_certificate_pem: string` PEM-encoded X.509 CA certificate. Must contain exactly one certificate and no private-key material. -### Returns + maxLength: 8192 +## Returns + - `id: string` ID of the Tunnel Certificate.
RFC 3339 datetime string indicating when the certificate was archived, or `null` if it is not archived. + format: date-time + - `created_at: string` RFC 3339 datetime string indicating when the certificate was registered. + format: date-time + - `expires_at: string or null` RFC 3339 datetime string indicating when the certificate expires, or `null` if it does not expire. + format: date-time + - `fingerprint: string` The certificate's SHA-256 fingerprint, as a lowercase hex string.
Object type. Always `tunnel_certificate` for Tunnel Certificates. - - `"tunnel_certificate"` + default: tunnel_certificate -### Example +## Example -```http +```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +### Response (200) ```json {