Create Tunnel Certificate

Deprecated. This Admin API endpoint is superseded by /v1/tunnels on the Claude API and will be removed after a migration window. New integrations should use /v1/tunnels with the anthropic-beta: mcp-tunnels-2026-06-22 header and a WIF token carrying the workspace:manage_tunnels scope. Existing integrations continue to work with the mcp-tunnels-2026-05-19 header and org:manage_tunnels scope during the migration window.

Register a public CA certificate for the tunnel.

Anthropic verifies the gateway's server certificate against this CA when it terminates the inner TLS session. The PEM body must contain exactly one X.509 certificate and no private-key material. A tunnel holds at most two non-archived certificates.

post/v1/organizations/tunnels/{tunnel_id}/certificates?beta=true

Path parameters

tunnel_idstring required

ID of the Tunnel.

ID of the Tunnel.

Headers

anthropic-betastring required

This endpoint is in beta: requests must send mcp-tunnels-2026-05-19 in this header.

This endpoint is in beta: requests must send mcp-tunnels-2026-05-19 in this header.

anthropic-versionstring

The version of the Claude API you want to use.

Read more about versioning and our version history here.

The version of the Claude API you want to use.

Read more about versioning and our version history here.

Request body

ca_certificate_pemstring required

PEM-encoded X.509 CA certificate. Must contain exactly one certificate and no private-key material.

Example request

{
  "ca_certificate_pem": "-----BEGIN CERTIFICATE-----\nMIIBexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexa\n...illustrative placeholder, not a real certificate...\n-----END CERTIFICATE-----\n"
}

Response

Successful Response

archived_atstring date-time nullable required

RFC 3339 datetime string indicating when the certificate was archived, or null if it is not archived.

created_atstring date-time required

RFC 3339 datetime string indicating when the certificate was registered.

expires_atstring date-time nullable required

RFC 3339 datetime string indicating when the certificate expires, or null if it does not expire.

fingerprintstring required

The certificate's SHA-256 fingerprint, as a lowercase hex string.

idstring required

ID of the Tunnel Certificate.

tunnel_idstring required

ID of the Tunnel this certificate is registered against.

type'tunnel_certificate' required

Object type. Always tunnel_certificate for Tunnel Certificates.

Example response

{
  "archived_at": "2024-11-01T23:59:27.427722Z",
  "created_at": "2024-10-30T23:58:27.427722Z",
  "expires_at": "2024-10-30T23:58:27.427722Z",
  "fingerprint": "9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08",
  "id": "tcrt_01JmWq4ZxnBvR7tKpY2sLdH9",
  "tunnel_id": "tnl_01Hx9Kp2RtQvMn3sWbYdLcF8"
}

Changes