Create Tunnel Certificate

The Tunnels API is in research preview. It requires the anthropic-beta: mcp-tunnels-2026-06-22 header and may change without a deprecation period. It supersedes the Admin API endpoints at /v1/organizations/tunnels, which remain available during a migration window.

Registers a public CA certificate on a tunnel. Anthropic verifies the gateway's server certificate against this CA when it terminates the inner TLS session. A tunnel holds at most two non-archived certificates.

post/v1/tunnels/{tunnel_id}/certificates?beta=true

Path parameters

tunnel_idstring required

Path parameter tunnel_id

Headers

anthropic-versionstring
anthropic-betastring
anthropic-workspace-idstring

Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).

Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.

Request body

ca_certificate_pemstring required

PEM-encoded X.509 CA certificate. Must contain exactly one certificate and no private-key material. Maximum 8KB.

Response

Successful response (OK)

type'tunnel_certificate' required
idstring required

Unique identifier for the certificate, prefixed with tcrt_.

tunnel_idstring required

ID of the tunnel the certificate is registered against.

fingerprintstring required

Lowercase hex SHA-256 fingerprint of the certificate's DER encoding.

expires_atstring date-time required

A timestamp in RFC 3339 format

created_atstring date-time required

A timestamp in RFC 3339 format

archived_atstring date-time required

A timestamp in RFC 3339 format

Changes