Tunnels
api/beta/tunnels
Nearest release: v2.1.245, published an hour after this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
api/beta/tunnels Changed · +143 / -154 lines
### Headers ### Body parameters #### Response (200) ### Path parameters ### Headers #### Response (200) ### Query parameters ### Headers #### Response (200) ### Path parameters ### Headers #### Response (200) ### Path parameters ### Headers #### Response (200) ### Path parameters ### Headers ### Body parameters #### Response (200) ## Domain types ## Tunnels › Certificates ### Create Tunnel Certificate #### Path parameters #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### Get Tunnel Certificate #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ### List Tunnel Certificates #### Path parameters #### Query parameters #### Headers #### Returns #### Example ##### Response (200) ### Archive Tunnel Certificate #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ### Header Parameters ### Body Parameters #### Response ### Path Parameters ### Header Parameters #### Response ### Query Parameters ### Header Parameters #### Response ### Path Parameters ### Header Parameters #### Response ### Path Parameters ### Header Parameters #### Response ### Path Parameters ### Header Parameters ### Body Parameters #### Response ## Domain Types # Certificates ## Create Tunnel Certificate ### Path Parameters ### Header Parameters ### Body Parameters #### Response ## Get Tunnel Certificate ### Path Parameters ### Header Parameters #### Response ## List Tunnel Certificates ### Path Parameters ### Query Parameters ### Header Parameters #### Response ## Archive Tunnel Certificate ### Path Parameters ### Header Parameters #### Response ## Domain Types ### Beta Tunnel Certificate
---- -title: Tunnels -url: https://platform.claude.com/docs/en/api/beta/tunnels ---- - # Tunnels ## Create Tunnel -**post** `/v1/tunnels` +**POST** `/v1/tunnels` The Tunnels API is in research preview. It requires the `anthropic-beta: mcp-tunnels-2026-06-22` header and may change without a deprecation period. It supersedes the Admin API endpoints at `/v1/organizations/tunnels`, which remain available during a migration window. Creates a tunnel. Creation allocates a fresh hostname and provisions the tunnel; it is not idempotent. The new tunnel rejects MCP traffic until at least one CA certificate is added. -### Header Parameters +### Headers - `"anthropic-beta": optional array of AnthropicBeta`
- `"mid-conversation-tool-changes-2026-07-01"` -### Body Parameters +### Body parameters - `display_name: optional string or null` Optional human-readable name for the tunnel (1-255 characters). + minLength: 1, maxLength: 255 + ### Returns -- `BetaTunnel object { id, archived_at, created_at, 3 more }` +- `BetaTunnel object` An MCP tunnel.
A timestamp in RFC 3339 format + format: date-time + - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `display_name: string or null` Human-readable name for the tunnel (1-255 characters). Null if unset.
- `type: "tunnel"` - - `"tunnel"` - ### Example -```http +```bash curl https://api.anthropic.com/v1/tunnels \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
-d '{}' ``` -#### Response +#### Response (200) ```json {
## Get Tunnel -**get** `/v1/tunnels/{tunnel_id}` +**GET** `/v1/tunnels/{tunnel_id}` The Tunnels API is in research preview. It requires the `anthropic-beta: mcp-tunnels-2026-06-22` header and may change without a deprecation period. It supersedes the Admin API endpoints at `/v1/organizations/tunnels`, which remain available during a migration window. Fetches a tunnel by ID. -### Path Parameters +### Path parameters - `tunnel_id: string` -### Header Parameters +### Headers - `"anthropic-beta": optional array of AnthropicBeta`
### Returns -- `BetaTunnel object { id, archived_at, created_at, 3 more }` +- `BetaTunnel object` An MCP tunnel.
A timestamp in RFC 3339 format + format: date-time + - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `display_name: string or null` Human-readable name for the tunnel (1-255 characters). Null if unset.
- `type: "tunnel"` - - `"tunnel"` - ### Example -```http +```bash curl https://api.anthropic.com/v1/tunnels/$TUNNEL_ID \ -H 'anthropic-version: 2023-06-01' \ -H 'anthropic-beta: mcp-tunnels-2026-06-22' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +#### Response (200) ```json {
## List Tunnels -**get** `/v1/tunnels` +**GET** `/v1/tunnels` The Tunnels API is in research preview. It requires the `anthropic-beta: mcp-tunnels-2026-06-22` header and may change without a deprecation period. It supersedes the Admin API endpoints at `/v1/organizations/tunnels`, which remain available during a migration window. Lists tunnels. Results are ordered by creation time, newest first; archived tunnels are excluded unless include_archived is set. -### Query Parameters +### Query parameters - `include_archived: optional boolean`
Maximum number of tunnels to return per page. Defaults to 20, maximum 1000. + format: int32 + - `page: optional string` Opaque pagination cursor from a previous `list_tunnels` response. -### Header Parameters +### Headers - `"anthropic-beta": optional array of AnthropicBeta`
A timestamp in RFC 3339 format + format: date-time + - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `display_name: string or null` Human-readable name for the tunnel (1-255 characters). Null if unset.
- `type: "tunnel"` - - `"tunnel"` - - `next_page: string or null` Pagination cursor for the next page, or null if no more results.
### Example -```http +```bash curl https://api.anthropic.com/v1/tunnels \ -H 'anthropic-version: 2023-06-01' \ -H 'anthropic-beta: mcp-tunnels-2026-06-22' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +#### Response (200) ```json {
## Archive Tunnel -**post** `/v1/tunnels/{tunnel_id}/archive` +**POST** `/v1/tunnels/{tunnel_id}/archive` The Tunnels API is in research preview. It requires the `anthropic-beta: mcp-tunnels-2026-06-22` header and may change without a deprecation period. It supersedes the Admin API endpoints at `/v1/organizations/tunnels`, which remain available during a migration window. Archives a tunnel. Archival is irreversible: every non-archived certificate on the tunnel is archived in the same operation, the hostname is retired and never re-allocated, and the tunnel token is invalidated. Retrying against an already-archived tunnel returns the existing record unchanged. -### Path Parameters +### Path parameters - `tunnel_id: string` -### Header Parameters +### Headers - `"anthropic-beta": optional array of AnthropicBeta`
### Returns -- `BetaTunnel object { id, archived_at, created_at, 3 more }` +- `BetaTunnel object` An MCP tunnel.
A timestamp in RFC 3339 format + format: date-time + - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `display_name: string or null` Human-readable name for the tunnel (1-255 characters). Null if unset.
- `type: "tunnel"` - - `"tunnel"` - ### Example -```http +```bash curl https://api.anthropic.com/v1/tunnels/$TUNNEL_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +#### Response (200) ```json {
## Reveal Tunnel Token -**post** `/v1/tunnels/{tunnel_id}/reveal_token` +**POST** `/v1/tunnels/{tunnel_id}/reveal_token` The Tunnels API is in research preview. It requires the `anthropic-beta: mcp-tunnels-2026-06-22` header and may change without a deprecation period. It supersedes the Admin API endpoints at `/v1/organizations/tunnels`, which remain available during a migration window. Reveals a tunnel's connector token. The value is fetched live on each call; Anthropic does not store it. Repeated calls return the same value until the token is rotated. Exposed as POST so the token does not appear in intermediary access logs. -### Path Parameters +### Path parameters - `tunnel_id: string` -### Header Parameters +### Headers - `"anthropic-beta": optional array of AnthropicBeta`
### Returns -- `BetaTunnelToken object { id, tunnel_token, type }` +- `BetaTunnelToken object` A tunnel's connector token.
- `type: "tunnel_token"` - - `"tunnel_token"` - ### Example -```http +```bash curl https://api.anthropic.com/v1/tunnels/$TUNNEL_ID/reveal_token \ -X POST \ -H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +#### Response (200) ```json {
## Rotate Tunnel Token -**post** `/v1/tunnels/{tunnel_id}/rotate_token` +**POST** `/v1/tunnels/{tunnel_id}/rotate_token` The Tunnels API is in research preview. It requires the `anthropic-beta: mcp-tunnels-2026-06-22` header and may change without a deprecation period. It supersedes the Admin API endpoints at `/v1/organizations/tunnels`, which remain available during a migration window. Rotates a tunnel's connector token. Rotation invalidates the current token for new connections and returns a fresh value; established connections are not severed. A connector restarted after rotation must use the new value. -### Path Parameters +### Path parameters - `tunnel_id: string` -### Header Parameters +### Headers - `"anthropic-beta": optional array of AnthropicBeta`
- `"mid-conversation-tool-changes-2026-07-01"` -### Body Parameters +### Body parameters - `reason: optional string or null` Optional free-text reason for the rotation, recorded for audit. + maxLength: 1024 + ### Returns -- `BetaTunnelToken object { id, tunnel_token, type }` +- `BetaTunnelToken object` A tunnel's connector token.
- `type: "tunnel_token"` - - `"tunnel_token"` - ### Example -```http +```bash curl https://api.anthropic.com/v1/tunnels/$TUNNEL_ID/rotate_token \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
-d '{}' ``` -#### Response +#### Response (200) ```json {
} ``` -## Domain Types +## Domain types ### Beta Tunnel -- `BetaTunnel object { id, archived_at, created_at, 3 more }` +- `BetaTunnel object` An MCP tunnel.
A timestamp in RFC 3339 format + format: date-time + - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `display_name: string or null` Human-readable name for the tunnel (1-255 characters). Null if unset.
- `type: "tunnel"` - - `"tunnel"` - ### Beta Tunnel Token -- `BetaTunnelToken object { id, tunnel_token, type }` +- `BetaTunnelToken object` A tunnel's connector token.
- `type: "tunnel_token"` - - `"tunnel_token"` +## Tunnels › Certificates -# Certificates +### Create Tunnel Certificate -## Create Tunnel Certificate +**POST** `/v1/tunnels/{tunnel_id}/certificates` -**post** `/v1/tunnels/{tunnel_id}/certificates` - The Tunnels API is in research preview. It requires the `anthropic-beta: mcp-tunnels-2026-06-22` header and may change without a deprecation period. It supersedes the Admin API endpoints at `/v1/organizations/tunnels`, which remain available during a migration window. Registers a public CA certificate on a tunnel. Anthropic verifies the gateway's server certificate against this CA when it terminates the inner TLS session. A tunnel holds at most two non-archived certificates. -### Path Parameters +#### Path parameters - `tunnel_id: string` -### Header Parameters +#### Headers - `"anthropic-beta": optional array of AnthropicBeta`
- `"mid-conversation-tool-changes-2026-07-01"` -### Body Parameters +#### Body parameters - `ca_certificate_pem: string` PEM-encoded X.509 CA certificate. Must contain exactly one certificate and no private-key material. Maximum 8KB. -### Returns + maxLength: 8192 -- `BetaTunnelCertificate object { id, archived_at, created_at, 4 more }` +#### Returns +- `BetaTunnelCertificate object` + A CA certificate attached to a tunnel. - `id: string`
A timestamp in RFC 3339 format + format: date-time + - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `expires_at: string or null` A timestamp in RFC 3339 format + format: date-time + - `fingerprint: string` Lowercase hex SHA-256 fingerprint of the certificate's DER encoding.
- `type: "tunnel_certificate"` - - `"tunnel_certificate"` +#### Example -### Example - -```http +```bash curl https://api.anthropic.com/v1/tunnels/$TUNNEL_ID/certificates \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +##### Response (200) ```json {
} ``` -## Get Tunnel Certificate +### Get Tunnel Certificate -**get** `/v1/tunnels/{tunnel_id}/certificates/{certificate_id}` +**GET** `/v1/tunnels/{tunnel_id}/certificates/{certificate_id}` The Tunnels API is in research preview. It requires the `anthropic-beta: mcp-tunnels-2026-06-22` header and may change without a deprecation period. It supersedes the Admin API endpoints at `/v1/organizations/tunnels`, which remain available during a migration window. Fetches a tunnel certificate by ID. -### Path Parameters +#### Path parameters - `tunnel_id: string` - `certificate_id: string` -### Header Parameters +#### Headers - `"anthropic-beta": optional array of AnthropicBeta`
- `"mid-conversation-tool-changes-2026-07-01"` -### Returns +#### Returns -- `BetaTunnelCertificate object { id, archived_at, created_at, 4 more }` +- `BetaTunnelCertificate object` A CA certificate attached to a tunnel.
A timestamp in RFC 3339 format + format: date-time + - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `expires_at: string or null` A timestamp in RFC 3339 format + format: date-time + - `fingerprint: string` Lowercase hex SHA-256 fingerprint of the certificate's DER encoding.
- `type: "tunnel_certificate"` - - `"tunnel_certificate"` +#### Example -### Example - -```http +```bash curl https://api.anthropic.com/v1/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID \ -H 'anthropic-version: 2023-06-01' \ -H 'anthropic-beta: mcp-tunnels-2026-06-22' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +##### Response (200) ```json {
} ``` -## List Tunnel Certificates +### List Tunnel Certificates -**get** `/v1/tunnels/{tunnel_id}/certificates` +**GET** `/v1/tunnels/{tunnel_id}/certificates` The Tunnels API is in research preview. It requires the `anthropic-beta: mcp-tunnels-2026-06-22` header and may change without a deprecation period. It supersedes the Admin API endpoints at `/v1/organizations/tunnels`, which remain available during a migration window. Lists the certificates registered on a tunnel. Archived certificates are excluded unless include_archived is set. -### Path Parameters +#### Path parameters - `tunnel_id: string` -### Query Parameters +#### Query parameters - `include_archived: optional boolean`
Maximum number of certificates to return per page. Defaults to 20, maximum 1000. + format: int32 + - `page: optional string` Opaque pagination cursor from a previous `list_tunnel_certificates` response. -### Header Parameters +#### Headers - `"anthropic-beta": optional array of AnthropicBeta`
- `"mid-conversation-tool-changes-2026-07-01"` -### Returns +#### Returns - `data: array of BetaTunnelCertificate`
A timestamp in RFC 3339 format + format: date-time + - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `expires_at: string or null` A timestamp in RFC 3339 format + format: date-time + - `fingerprint: string` Lowercase hex SHA-256 fingerprint of the certificate's DER encoding.
- `type: "tunnel_certificate"` - - `"tunnel_certificate"` - - `next_page: string or null` Pagination cursor for the next page, or null if no more results. -### Example +#### Example -```http +```bash curl https://api.anthropic.com/v1/tunnels/$TUNNEL_ID/certificates \ -H 'anthropic-version: 2023-06-01' \ -H 'anthropic-beta: mcp-tunnels-2026-06-22' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +##### Response (200) ```json {
} ``` -## Archive Tunnel Certificate +### Archive Tunnel Certificate -**post** `/v1/tunnels/{tunnel_id}/certificates/{certificate_id}/archive` +**POST** `/v1/tunnels/{tunnel_id}/certificates/{certificate_id}/archive` The Tunnels API is in research preview. It requires the `anthropic-beta: mcp-tunnels-2026-06-22` header and may change without a deprecation period. It supersedes the Admin API endpoints at `/v1/organizations/tunnels`, which remain available during a migration window. Archives a tunnel certificate, removing it from the set Anthropic trusts for the tunnel. The certificate record is retained. Archiving the last non-archived certificate is permitted; the tunnel rejects MCP traffic until a new certificate is added. -### Path Parameters +#### Path parameters - `tunnel_id: string` - `certificate_id: string` -### Header Parameters +#### Headers - `"anthropic-beta": optional array of AnthropicBeta`
- `"mid-conversation-tool-changes-2026-07-01"` -### Returns +#### Returns -- `BetaTunnelCertificate object { id, archived_at, created_at, 4 more }` +- `BetaTunnelCertificate object` A CA certificate attached to a tunnel.
A timestamp in RFC 3339 format + format: date-time + - `created_at: string` A timestamp in RFC 3339 format + format: date-time + - `expires_at: string or null` A timestamp in RFC 3339 format + format: date-time + - `fingerprint: string` Lowercase hex SHA-256 fingerprint of the certificate's DER encoding.
- `type: "tunnel_certificate"` - - `"tunnel_certificate"` +#### Example -### Example - -```http +```bash curl https://api.anthropic.com/v1/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" ``` -#### Response +##### Response (200) ```json {
"type": "tunnel_certificate" } ``` - -## Domain Types - -### Beta Tunnel Certificate - -- `BetaTunnelCertificate object { id, archived_at, created_at, 4 more }` - - A CA certificate attached to a tunnel. - - - `id: string` - - Unique identifier for the certificate, prefixed with `tcrt_`. - - - `archived_at: string or null` - - A timestamp in RFC 3339 format - - - `created_at: string` - - A timestamp in RFC 3339 format - - - `expires_at: string or null` - - A timestamp in RFC 3339 format - - - `fingerprint: string` - - Lowercase hex SHA-256 fingerprint of the certificate's DER encoding. - - - `tunnel_id: string` - - ID of the tunnel the certificate is registered against. - - - `type: "tunnel_certificate"` - - - `"tunnel_certificate"`