---
title: "Get Tunnel Certificate"
method: GET
path: "/v1/tunnels/{tunnel_id}/certificates/{certificate_id}?beta=true"
---

# Get Tunnel Certificate

`GET /v1/tunnels/{tunnel_id}/certificates/{certificate_id}?beta=true`

The Tunnels API is in research preview. It requires the `anthropic-beta: mcp-tunnels-2026-06-22` header and may change without a deprecation period. It supersedes the Admin API endpoints at `/v1/organizations/tunnels`, which remain available during a migration window.

Fetches a tunnel certificate by ID.

## Path parameters

- `tunnel_id` string, required
- `certificate_id` string, required

## Headers

- `x-api-key` string
- `anthropic-version` string
- `anthropic-beta` string
- `anthropic-workspace-id` string

## Response `200`

Successful response (OK)

- BetaTunnelCertificate — A CA certificate attached to a tunnel.
  - `type` 'tunnel_certificate', required
  - `id` string, required — Unique identifier for the certificate, prefixed with `tcrt_`.
  - `tunnel_id` string, required — ID of the tunnel the certificate is registered against.
  - `fingerprint` string, required — Lowercase hex SHA-256 fingerprint of the certificate's DER encoding.
  - `expires_at` string, date-time, required — A timestamp in RFC 3339 format
  - `created_at` string, date-time, required — A timestamp in RFC 3339 format
  - `archived_at` string, date-time, required — A timestamp in RFC 3339 format

## Other responses

- `400` — Invalid argument - The client specified an invalid argument
- `401` — Unauthenticated - The request does not have valid authentication credentials
- `403` — Permission denied - The caller does not have permission to execute the specified operation
- `404` — Not found - Some requested entity was not found
- `408` — Deadline exceeded - The deadline expired before the operation could complete
- `409` — Aborted - The operation was aborted due to concurrency issue
- `412` — Failed precondition - Operation was rejected because the system is not in required state
- `413` — Out of range - Operation was attempted past the valid range
- `429` — Resource exhausted - Some resource has been exhausted (rate limiting)
- `431` — Request header fields too large - Request metadata was too large
- `499` — Cancelled - The operation was cancelled by the client
- `500` — Internal - Internal server error
- `501` — Unimplemented - The operation is not implemented or supported
- `503` — Unavailable - The service is currently unavailable
- `504` — Deadline exceeded - Upstream service did not respond in time

## Changes

- **2026-09-02** `4789294140a2` — 1 info
  - added the new optional `header` request parameter `anthropic-workspace-id`
- **2026-08-17** `d2b230555b7f` — 4 info
  - removed `#/components/schemas/BetaTimestamp` from the `archived_at` response property `allOf` list for the response status `200`
  - removed `#/components/schemas/BetaTimestamp` from the `expires_at` response property `allOf` list for the response status `200`
  - added `#/components/schemas/BetaTimestamp, subschema #2` to the `archived_at` response property `anyOf` list for the response status `200`
  - added `#/components/schemas/BetaTimestamp, subschema #2` to the `expires_at` response property `anyOf` list for the response status `200`
- **2026-07-17** `6fbcaa1967b2` — 2 info
  - the `type` response property const value `tunnel_certificate` was added for the status `200`
  - removed the `tunnel_certificate` enum value from the `type` response property for the response status `200`
- **2026-06-25** `52cd4fce110f` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/anthropics/apis/anthropic-api/changes/v1/tunnels/:tunnel_id/certificates/:certificate_id?beta=true/get.md)

---

[API](https://skmtc.dev/anthropics/apis/anthropic-api.md) · [All operations](https://skmtc.dev/anthropics/apis/anthropic-api/llms.txt) · [OpenAPI document](https://skmtc.dev/anthropics/apis/anthropic-api/revisions/1bb7c7a0a4a9?raw)
