---
title: "List Tunnel Certificates"
method: GET
path: "/v1/organizations/tunnels/{tunnel_id}/certificates?beta=true"
deprecated: true
---

# List Tunnel Certificates

`GET /v1/organizations/tunnels/{tunnel_id}/certificates?beta=true`

> **Deprecated.**

**Deprecated.** This Admin API endpoint is superseded by `/v1/tunnels` on the Claude API and will be removed after a migration window. New integrations should use [`/v1/tunnels`](/docs/en/api/beta/tunnels) with the `anthropic-beta: mcp-tunnels-2026-06-22` header and a WIF token carrying the `workspace:manage_tunnels` scope. Existing integrations continue to work with the `mcp-tunnels-2026-05-19` header and `org:manage_tunnels` scope during the migration window.

List the certificates registered on a tunnel.

Archived certificates are excluded unless `include_archived` is set.

## Path parameters

- `tunnel_id` string, required — ID of the Tunnel.

## Query parameters

- `page` string, nullable — A tunnel has at most two active certificates, so this list is not paginated.
- `limit` integer — Maximum number of certificates to return.
- `include_archived` boolean — Include archived certificates in the results. Archived certificates are excluded by default.

## Headers

- `anthropic-beta` string, required — This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `x-api-key` string — Your unique Admin API key for authentication. This key is required in the header of all Admin API requests, to authenticate your account and access Anthropic's services. Get your Admin API key through the [Console](https://console.anthropic.com/settings/admin-keys).
- `anthropic-version` string — The version of the Claude API you want to use. Read more about versioning and our version history [here](https://platform.claude.com/docs/en/api/versioning).

## Response `200`

Successful Response

- BetaTunnelCertificateListResponse
  - `data` BetaOrganizationTunnelCertificate[], required
    - `archived_at` string, date-time, nullable, required — RFC 3339 datetime string indicating when the certificate was archived, or `null` if it is not archived.
    - `created_at` string, date-time, required — RFC 3339 datetime string indicating when the certificate was registered.
    - `expires_at` string, date-time, nullable, required — RFC 3339 datetime string indicating when the certificate expires, or `null` if it does not expire.
    - `fingerprint` string, required — The certificate's SHA-256 fingerprint, as a lowercase hex string.
    - `id` string, required — ID of the Tunnel Certificate.
    - `tunnel_id` string, required — ID of the Tunnel this certificate is registered against.
    - `type` 'tunnel_certificate', required — Object type. Always `tunnel_certificate` for Tunnel Certificates.
  - `next_page` string, nullable, required — Opaque cursor for the next page, or `null` if there are no more results.

## Other responses

- `400` — Invalid argument - The client specified an invalid argument
- `401` — Unauthenticated - The request does not have valid authentication credentials
- `403` — Permission denied - The caller does not have permission to execute the specified operation
- `404` — Not found - Some requested entity was not found
- `408` — Deadline exceeded - The deadline expired before the operation could complete
- `409` — Aborted - The operation was aborted due to concurrency issue
- `412` — Failed precondition - Operation was rejected because the system is not in required state
- `413` — Out of range - Operation was attempted past the valid range
- `429` — Resource exhausted - Some resource has been exhausted (rate limiting)
- `431` — Request header fields too large - Request metadata was too large
- `499` — Cancelled - The operation was cancelled by the client
- `500` — Internal - Internal server error
- `501` — Unimplemented - The operation is not implemented or supported
- `503` — Unavailable - The service is currently unavailable
- `504` — Deadline exceeded - Upstream service did not respond in time
- `529` — Overloaded - The service is temporarily overloaded

## Changes

- **2026-09-02** `4789294140a2` — 16 info
  - added the non-success response with the status `400`
  - added the non-success response with the status `401`
  - added the non-success response with the status `403`
  - added the non-success response with the status `404`
  - …12 more
- **2026-09-01** `d1d189d791d1` — 1 breaking
  - the `header` request parameter `anthropic-beta` became required
- **2026-08-26** `942a11636c42` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/anthropics/apis/anthropic-api/changes/v1/organizations/tunnels/:tunnel_id/certificates?beta=true/get.md)

---

[API](https://skmtc.dev/anthropics/apis/anthropic-api.md) · [All operations](https://skmtc.dev/anthropics/apis/anthropic-api/llms.txt) · [OpenAPI document](https://skmtc.dev/anthropics/apis/anthropic-api/revisions/1bb7c7a0a4a9?raw)
