from line 1
11# MCP tunnels
22
3> Connect Claude to MCP servers inside your private network without opening inbound firewall ports or exposing the servers to the internet. How MCP tunnels work, what you deploy, network and plan requirements, and the security model.
3> Connect Claude to MCP servers inside your private network without opening inbound firewall ports or exposing the servers to the internet.
44
55<Note>
66 MCP tunnels are in research preview and are available to organizations on the Claude Enterprise plan by request. To request access, [submit the MCP tunnels interest form](https://claude.com/form/mcp-tunnels) or contact your Anthropic account team. The preview is provided as-is, without uptime, support, or continuity commitments, and it depends on a third-party network provider (Cloudflare) that makes no availability commitment for the underlying transport. Anthropic may modify or discontinue MCP tunnels at any time.
77</Note>
88
9MCP tunnels connect Claude to [Model Context Protocol (MCP)](/docs/connectors/building/mcp) servers that run inside your private network. You run a small tunnel stack on a host in your network, the stack opens an outbound-only connection to Anthropic, and Claude sends MCP requests to your servers over that connection. Your firewall needs no inbound rules and your MCP servers need no public endpoint. Members of your organization use the tunneled servers as [custom connectors](/docs/connectors/custom/remote-mcp) in Claude, the same way they use any other remote MCP server.
9MCP tunnels connect Claude to [Model Context Protocol (MCP)](/docs/connectors/building/mcp) servers that run inside your private network. You run a small tunnel stack on a host in your network, the stack opens an outbound-only connection to Anthropic, and Claude sends MCP requests to your servers over that connection. Your firewall needs no inbound rules and your MCP servers need no public endpoint. Members of your organization use the tunneled servers as [custom connectors](/docs/connectors/custom/add-unlisted#add-a-connector-by-url) in Claude, the same way they use any other remote MCP server.
1010
1111This section is for administrators of claude.ai organizations on the Enterprise plan and the infrastructure teams they work with. To use MCP tunnels with the Claude Console, Claude Managed Agents, or the Messages API, see [MCP tunnels in the Claude Platform docs](https://platform.claude.com/docs/en/agents-and-tools/mcp-tunnels/overview). A tunnel belongs to the organization that created it, so a tunnel created from a Console organization can't serve connectors in claude.ai, and a tunnel created from claude.ai can't serve the API.
1212
13## When to use an MCP tunnel
13## Decide when to use an MCP tunnel
1414
1515Use a tunnel when the MCP server your organization wants to reach from Claude is only reachable inside your network, and your security policy rules out giving it a public endpoint or allowlisting Anthropic's IP ranges at your edge. Internal knowledge bases, ticketing systems, and data services wrapped in an MCP server are typical candidates.
1616
17If the MCP server is already reachable from the internet, you don't need a tunnel. Add it as a [custom connector](/docs/connectors/custom/remote-mcp) directly.
17If the MCP server is already reachable from the internet, you don't need a tunnel. Add it as a [custom connector](/docs/connectors/custom/add-unlisted#add-a-connector-by-url) directly.
1818
19## How traffic flows
19## Understand how tunnel traffic flows
2020
2121The tunnel stack is two containers that you run inside your network, from images that Anthropic and Cloudflare publish:
2222
23* **cloudflared** is Cloudflare's open-source tunnel connector. It dials out from your network to the tunnel edge and keeps that connection open. It never listens on an inbound port.
24* **The proxy** (`mcp-proxy`) is Anthropic's routing component. It terminates an inner layer of TLS, checks that each destination address falls inside an allowed private range, and forwards each request to the right MCP server based on the hostname it was sent to.
23* **cloudflared** is Cloudflare's open-source tunnel connector. It dials out from your network to the tunnel edge and keeps that connection open. It never listens on an inbound port
24* **The proxy** (`mcp-proxy`) is Anthropic's routing component. It terminates an inner layer of TLS, checks that each destination address falls inside an allowed private range, and forwards each request to the right MCP server based on the hostname it was sent to
2525
2626When you create a tunnel, Anthropic assigns it a domain such as `abc123.tunnel.anthropic.com`. Each MCP server you expose gets a subdomain of that domain, chosen by you in the proxy's route configuration. A route named `docs` that points at `http://docs-mcp.example.corp:8080` makes that server reachable from Claude at `https://docs.abc123.tunnel.anthropic.com`.
2727
from line 33
3333
3434Hostnames under `tunnel.anthropic.com` accept connections only from Claude. You can't open them in a browser or test them with `curl` from your own network, so you verify a tunnel by using it from Claude.
3535
36## What you need
36## Meet the tunnel requirements
3737
38* A claude.ai organization on the Enterprise plan with MCP tunnels enabled. To request access, [submit the MCP tunnels interest form](https://claude.com/form/mcp-tunnels) or contact your Anthropic account team.
39* The Owner or Primary Owner role in that organization, to create the API key the tunnel setup uses and to add the tunneled servers as connectors.
40* A place to run the tunnel stack inside your network: a Kubernetes cluster (deployed with Helm) or a Linux host with Docker and Docker Compose. One stack serves one tunnel, and you can run replicas of it on several hosts for availability.
41* One or more MCP servers that speak the Streamable HTTP transport and are reachable from that cluster or host.
42* Outbound network access from the stack as listed under [Network requirements](#network-requirements).
38* A claude.ai organization on the Enterprise plan with MCP tunnels enabled. To request access, [submit the MCP tunnels interest form](https://claude.com/form/mcp-tunnels) or contact your Anthropic account team
39* The Owner or Primary Owner role in that organization, to create the API key the tunnel setup uses and to add the tunneled servers as connectors
40* A place to run the tunnel stack inside your network: a Kubernetes cluster (deployed with Helm) or a Linux host with Docker and Docker Compose. One stack serves one tunnel, and you can run replicas of it on several hosts for availability
41* One or more MCP servers that speak the Streamable HTTP transport and are reachable from that cluster or host
42* Outbound network access from the stack as listed under [Network requirements](#network-requirements)
4343
4444### Network requirements
4545
from line 82
8282
8383## Limits
8484
85* An organization can have up to 10 active tunnels.
86* A tunnel holds up to two active CA certificates at a time, so you can rotate without downtime.
87* The server certificate that the setup component generates is valid for 90 days.
88* The proxy connects to upstream MCP servers over IPv4 only, and by default only to addresses in the RFC 1918 private ranges (`10.0.0.0/8`, `172.16.0.0/12`, `192.168.0.0/16`).
85* An organization can have up to 10 active tunnels
86* A tunnel holds up to two active CA certificates at a time, so you can rotate without downtime
87* The server certificate that the setup component generates is valid for 90 days
88* The proxy connects to upstream MCP servers over IPv4 only, and by default only to addresses in the RFC 1918 private ranges (`10.0.0.0/8`, `172.16.0.0/12`, `192.168.0.0/16`)
8989
9090## Next steps
9191
92<Columns cols={2}>
93 <Card title="Set up an MCP tunnel" icon="rocket" href="/docs/connectors/mcp-tunnels/setup">
94 Create the API key, deploy the tunnel stack with Helm or Docker Compose, and add your servers as connectors.
95 </Card>
96
97 <Card title="Authenticate through a tunnel" icon="lock" href="/docs/connectors/mcp-tunnels/oauth">
98 Make OAuth sign-in work when your authorization server is inside your network.
99 </Card>
100
101 <Card title="Troubleshooting" icon="wrench" href="/docs/connectors/mcp-tunnels/troubleshooting">
102 Diagnose connection, certificate, routing, and sign-in failures.
103 </Card>
104
105 <Card title="Platform reference" icon="book" href="https://platform.claude.com/docs/en/agents-and-tools/mcp-tunnels/reference">
106 Proxy configuration fields, certificate requirements, and the setup component.
107 </Card>
108</Columns>
92* [Set up an MCP tunnel](/docs/connectors/mcp-tunnels/setup): create the API key, deploy the tunnel stack with Helm or Docker Compose, and add your servers as connectors
93* [Authenticate through a tunnel](/docs/connectors/mcp-tunnels/oauth): make OAuth sign-in work when your authorization server is inside your network
94* [Troubleshooting](/docs/connectors/mcp-tunnels/troubleshooting): diagnose connection, certificate, routing, and sign-in failures
95* [Platform reference](https://platform.claude.com/docs/en/agents-and-tools/mcp-tunnels/reference): proxy configuration fields, certificate requirements, and the setup component
10996
No line in this hunk matches that.