Rotate Tunnel Token

The Tunnels API is in research preview. It requires the anthropic-beta: mcp-tunnels-2026-06-22 header and may change without a deprecation period. It supersedes the Admin API endpoints at /v1/organizations/tunnels, which remain available during a migration window.

Rotates a tunnel's connector token. Rotation invalidates the current token for new connections and returns a fresh value; established connections are not severed. A connector restarted after rotation must use the new value.

post/v1/tunnels/{tunnel_id}/rotate_token?beta=true

Path parameters

tunnel_idstring required

Path parameter tunnel_id

Headers

anthropic-versionstring
anthropic-betastring
anthropic-workspace-idstring

Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).

Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.

Request body

reasonstring nullable

Optional free-text reason for the rotation, recorded for audit.

Response

Successful response (OK)

type'tunnel_token' required
idstring required

Stable identifier for the current token value. Changes when the token is rotated.

tunnel_tokenstring required

The connector token used to run the tunnel. Treat as a credential.

Changes