Tunnel Certificates
Create Tunnel Certificate
post /v1/organizations/tunnels/{tunnel_id}/certificates
Register a public CA certificate for the tunnel.
Anthropic verifies the gateway's server certificate against this CA when it terminates the inner TLS session. The PEM body must contain exactly one X.509 certificate and no private-key material. A tunnel holds at most two non-archived certificates.
Path Parameters
-
tunnel_id: stringID of the Tunnel.
Header Parameters
-
"anthropic-beta": array of "mcp-tunnels-2026-05-19"Required for all Tunnel endpoints.
"mcp-tunnels-2026-05-19"
Body Parameters
-
ca_certificate_pem: stringPEM-encoded X.509 CA certificate. Must contain exactly one certificate and no private-key material.
Returns
-
id: stringID of the Tunnel Certificate.
-
archived_at: stringRFC 3339 datetime string indicating when the certificate was archived, or
nullif it is not archived. -
created_at: stringRFC 3339 datetime string indicating when the certificate was registered.
-
expires_at: stringRFC 3339 datetime string indicating when the certificate expires, or
nullif it does not expire. -
fingerprint: stringThe certificate's SHA-256 fingerprint, as a lowercase hex string.
-
tunnel_id: stringID of the Tunnel this certificate is registered against.
-
type: "tunnel_certificate"Object type. Always
tunnel_certificatefor Tunnel Certificates."tunnel_certificate"
Example
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_WIF_BEARER_TOKEN" \
-d '{
"ca_certificate_pem": "-----BEGIN CERTIFICATE-----\\nMIIBexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexa\\n...illustrative placeholder, not a real certificate...\\n-----END CERTIFICATE-----\\n"
}'
Response
{
"id": "tcrt_01JmWq4ZxnBvR7tKpY2sLdH9",
"archived_at": "2024-11-01T23:59:27.427722Z",
"created_at": "2024-10-30T23:58:27.427722Z",
"expires_at": "2024-10-30T23:58:27.427722Z",
"fingerprint": "9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08",
"tunnel_id": "tnl_01Hx9Kp2RtQvMn3sWbYdLcF8",
"type": "tunnel_certificate"
}
Get Tunnel Certificate
get /v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id}
Retrieve a single certificate registered on a tunnel by ID.
Path Parameters
-
tunnel_id: stringID of the Tunnel.
-
certificate_id: stringID of the Tunnel Certificate.
Header Parameters
-
"anthropic-beta": array of "mcp-tunnels-2026-05-19"Required for all Tunnel endpoints.
"mcp-tunnels-2026-05-19"
Returns
-
id: stringID of the Tunnel Certificate.
-
archived_at: stringRFC 3339 datetime string indicating when the certificate was archived, or
nullif it is not archived. -
created_at: stringRFC 3339 datetime string indicating when the certificate was registered.
-
expires_at: stringRFC 3339 datetime string indicating when the certificate expires, or
nullif it does not expire. -
fingerprint: stringThe certificate's SHA-256 fingerprint, as a lowercase hex string.
-
tunnel_id: stringID of the Tunnel this certificate is registered against.
-
type: "tunnel_certificate"Object type. Always
tunnel_certificatefor Tunnel Certificates."tunnel_certificate"
Example
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID \
-H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_WIF_BEARER_TOKEN"
Response
{
"id": "tcrt_01JmWq4ZxnBvR7tKpY2sLdH9",
"archived_at": "2024-11-01T23:59:27.427722Z",
"created_at": "2024-10-30T23:58:27.427722Z",
"expires_at": "2024-10-30T23:58:27.427722Z",
"fingerprint": "9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08",
"tunnel_id": "tnl_01Hx9Kp2RtQvMn3sWbYdLcF8",
"type": "tunnel_certificate"
}
List Tunnel Certificates
get /v1/organizations/tunnels/{tunnel_id}/certificates
List the certificates registered on a tunnel.
Archived certificates are excluded unless include_archived is set.
Path Parameters
-
tunnel_id: stringID of the Tunnel.
Query Parameters
-
include_archived: optional booleanInclude archived certificates in the results. Archived certificates are excluded by default.
-
limit: optional numberMaximum number of certificates to return.
-
page: optional stringA tunnel has at most two active certificates, so this list is not paginated.
Header Parameters
-
"anthropic-beta": array of "mcp-tunnels-2026-05-19"Required for all Tunnel endpoints.
"mcp-tunnels-2026-05-19"
Returns
-
data: array of object { id, archived_at, created_at, 4 more }-
id: stringID of the Tunnel Certificate.
-
archived_at: stringRFC 3339 datetime string indicating when the certificate was archived, or
nullif it is not archived. -
created_at: stringRFC 3339 datetime string indicating when the certificate was registered.
-
expires_at: stringRFC 3339 datetime string indicating when the certificate expires, or
nullif it does not expire. -
fingerprint: stringThe certificate's SHA-256 fingerprint, as a lowercase hex string.
-
tunnel_id: stringID of the Tunnel this certificate is registered against.
-
type: "tunnel_certificate"Object type. Always
tunnel_certificatefor Tunnel Certificates."tunnel_certificate"
-
-
next_page: stringOpaque cursor for the next page, or
nullif there are no more results.
Example
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \
-H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_WIF_BEARER_TOKEN"
Response
{
"data": [
{
"id": "tcrt_01JmWq4ZxnBvR7tKpY2sLdH9",
"archived_at": "2024-11-01T23:59:27.427722Z",
"created_at": "2024-10-30T23:58:27.427722Z",
"expires_at": "2024-10-30T23:58:27.427722Z",
"fingerprint": "9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08",
"tunnel_id": "tnl_01Hx9Kp2RtQvMn3sWbYdLcF8",
"type": "tunnel_certificate"
}
],
"next_page": "page_MjAyNS0wNS0xNFQwMDowMDowMFo="
}
Archive Tunnel Certificate
post /v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id}/archive
Archive a certificate, removing it from the set Anthropic trusts for this tunnel.
The certificate record is retained. Archiving the last non-archived certificate is permitted; the tunnel rejects MCP traffic until a new certificate is added.
Path Parameters
-
tunnel_id: stringID of the Tunnel.
-
certificate_id: stringID of the Tunnel Certificate.
Header Parameters
-
"anthropic-beta": array of "mcp-tunnels-2026-05-19"Required for all Tunnel endpoints.
"mcp-tunnels-2026-05-19"
Returns
-
id: stringID of the Tunnel Certificate.
-
archived_at: stringRFC 3339 datetime string indicating when the certificate was archived, or
nullif it is not archived. -
created_at: stringRFC 3339 datetime string indicating when the certificate was registered.
-
expires_at: stringRFC 3339 datetime string indicating when the certificate expires, or
nullif it does not expire. -
fingerprint: stringThe certificate's SHA-256 fingerprint, as a lowercase hex string.
-
tunnel_id: stringID of the Tunnel this certificate is registered against.
-
type: "tunnel_certificate"Object type. Always
tunnel_certificatefor Tunnel Certificates."tunnel_certificate"
Example
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID/archive \
-X POST \
-H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_WIF_BEARER_TOKEN"
Response
{
"id": "tcrt_01JmWq4ZxnBvR7tKpY2sLdH9",
"archived_at": "2024-11-01T23:59:27.427722Z",
"created_at": "2024-10-30T23:58:27.427722Z",
"expires_at": "2024-10-30T23:58:27.427722Z",
"fingerprint": "9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08",
"tunnel_id": "tnl_01Hx9Kp2RtQvMn3sWbYdLcF8",
"type": "tunnel_certificate"
}
Domain Types
Tunnel Certificate Create Response
-
TunnelCertificateCreateResponse object { id, archived_at, created_at, 4 more }-
id: stringID of the Tunnel Certificate.
-
archived_at: stringRFC 3339 datetime string indicating when the certificate was archived, or
nullif it is not archived. -
created_at: stringRFC 3339 datetime string indicating when the certificate was registered.
-
expires_at: stringRFC 3339 datetime string indicating when the certificate expires, or
nullif it does not expire. -
fingerprint: stringThe certificate's SHA-256 fingerprint, as a lowercase hex string.
-
tunnel_id: stringID of the Tunnel this certificate is registered against.
-
type: "tunnel_certificate"Object type. Always
tunnel_certificatefor Tunnel Certificates."tunnel_certificate"
-
Tunnel Certificate Retrieve Response
-
TunnelCertificateRetrieveResponse object { id, archived_at, created_at, 4 more }-
id: stringID of the Tunnel Certificate.
-
archived_at: stringRFC 3339 datetime string indicating when the certificate was archived, or
nullif it is not archived. -
created_at: stringRFC 3339 datetime string indicating when the certificate was registered.
-
expires_at: stringRFC 3339 datetime string indicating when the certificate expires, or
nullif it does not expire. -
fingerprint: stringThe certificate's SHA-256 fingerprint, as a lowercase hex string.
-
tunnel_id: stringID of the Tunnel this certificate is registered against.
-
type: "tunnel_certificate"Object type. Always
tunnel_certificatefor Tunnel Certificates."tunnel_certificate"
-
Tunnel Certificate List Response
-
TunnelCertificateListResponse object { data, next_page }-
data: array of object { id, archived_at, created_at, 4 more }-
id: stringID of the Tunnel Certificate.
-
archived_at: stringRFC 3339 datetime string indicating when the certificate was archived, or
nullif it is not archived. -
created_at: stringRFC 3339 datetime string indicating when the certificate was registered.
-
expires_at: stringRFC 3339 datetime string indicating when the certificate expires, or
nullif it does not expire. -
fingerprint: stringThe certificate's SHA-256 fingerprint, as a lowercase hex string.
-
tunnel_id: stringID of the Tunnel this certificate is registered against.
-
type: "tunnel_certificate"Object type. Always
tunnel_certificatefor Tunnel Certificates."tunnel_certificate"
-
-
next_page: stringOpaque cursor for the next page, or
nullif there are no more results.
-
Tunnel Certificate Archive Response
-
TunnelCertificateArchiveResponse object { id, archived_at, created_at, 4 more }-
id: stringID of the Tunnel Certificate.
-
archived_at: stringRFC 3339 datetime string indicating when the certificate was archived, or
nullif it is not archived. -
created_at: stringRFC 3339 datetime string indicating when the certificate was registered.
-
expires_at: stringRFC 3339 datetime string indicating when the certificate expires, or
nullif it does not expire. -
fingerprint: stringThe certificate's SHA-256 fingerprint, as a lowercase hex string.
-
tunnel_id: stringID of the Tunnel this certificate is registered against.
-
type: "tunnel_certificate"Object type. Always
tunnel_certificatefor Tunnel Certificates."tunnel_certificate"
-