---
title: "Create"
method: POST
path: "/edges/tls"
tags: ["EdgesTLS"]
---

# Create

`POST /edges/tls`

Create a TLS Edge

## Headers

- `ngrok-version` integer, required

## Request body

- TLSEdgeCreate
  - `description` string — human-readable description of what this edge will be used for; optional, max 255 bytes.
  - `metadata` string — arbitrary user-defined machine-readable data of this edge. Optional, max 4096 bytes.
  - `hostports` string[] — hostports served by this edge
  - `backend` EndpointBackendMutate
    - `enabled` boolean — `true` if the module will be applied to traffic, `false` to disable. default `true` if unspecified
    - `backend_id` string — backend to be used to back this endpoint
  - `ip_restriction` EndpointIPPolicyMutate
    - `enabled` boolean — `true` if the module will be applied to traffic, `false` to disable. default `true` if unspecified
    - `ip_policy_ids` string[] — list of all IP policies that will be used to check if a source IP is allowed access to the endpoint
  - `mutual_tls` EndpointMutualTLSMutate
    - `enabled` boolean — `true` if the module will be applied to traffic, `false` to disable. default `true` if unspecified
    - `certificate_authority_ids` string[] — list of certificate authorities that will be used to validate the TLS client certificate presented by the initiator of the TLS connection
  - `tls_termination` EndpointTLSTermination
    - `enabled` boolean — `true` if the module will be applied to traffic, `false` to disable. default `true` if unspecified
    - `terminate_at` string — `edge` if the ngrok edge should terminate TLS traffic, `upstream` if TLS traffic should be passed through to the upstream ngrok agent / application server for termination. if `upstream` is chosen, most other modules will be disallowed because they rely on the ngrok edge being able to access the underlying traffic.
    - `min_version` string — The minimum TLS version used for termination and advertised to the client during the TLS handshake. if unspecified, ngrok will choose an industry-safe default. This value must be null if `terminate_at` is set to `upstream`.
  - `traffic_policy` EndpointTrafficPolicy
    - `enabled` boolean — `true` if the module will be applied to traffic, `false` to disable. default `true` if unspecified
    - `value` string — the traffic policy that should be applied to the traffic on your endpoint.

## Response `201`

Create a TLS Edge

- TLSEdge
  - `id` string — unique identifier of this edge
  - `description` string — human-readable description of what this edge will be used for; optional, max 255 bytes.
  - `metadata` string — arbitrary user-defined machine-readable data of this edge. Optional, max 4096 bytes.
  - `created_at` string — timestamp when the edge configuration was created, RFC 3339 format
  - `uri` string — URI of the edge API resource
  - `hostports` string[] — hostports served by this edge
  - `backend` EndpointBackend
    - `enabled` boolean — `true` if the module will be applied to traffic, `false` to disable. default `true` if unspecified
    - `backend` Ref
      - `id` string — a resource identifier
      - `uri` string — a uri for locating a resource
  - `ip_restriction` EndpointIPPolicy
    - `enabled` boolean — `true` if the module will be applied to traffic, `false` to disable. default `true` if unspecified
    - `ip_policies` Ref[] — list of all IP policies that will be used to check if a source IP is allowed access to the endpoint
      - `id` string — a resource identifier
      - `uri` string — a uri for locating a resource
  - `mutual_tls` EndpointMutualTLS
    - `enabled` boolean — `true` if the module will be applied to traffic, `false` to disable. default `true` if unspecified
    - `certificate_authorities` Ref[] — PEM-encoded CA certificates that will be used to validate. Multiple CAs may be provided by concatenating them together.
      - `id` string — a resource identifier
      - `uri` string — a uri for locating a resource
  - `tls_termination` EndpointTLSTermination
    - `enabled` boolean — `true` if the module will be applied to traffic, `false` to disable. default `true` if unspecified
    - `terminate_at` string — `edge` if the ngrok edge should terminate TLS traffic, `upstream` if TLS traffic should be passed through to the upstream ngrok agent / application server for termination. if `upstream` is chosen, most other modules will be disallowed because they rely on the ngrok edge being able to access the underlying traffic.
    - `min_version` string — The minimum TLS version used for termination and advertised to the client during the TLS handshake. if unspecified, ngrok will choose an industry-safe default. This value must be null if `terminate_at` is set to `upstream`.
  - `traffic_policy` EndpointTrafficPolicy
    - `enabled` boolean — `true` if the module will be applied to traffic, `false` to disable. default `true` if unspecified
    - `value` string — the traffic policy that should be applied to the traffic on your endpoint.

## Other responses

- `4XX` — An error. The body carries a machine-readable error_code and a human-readable msg; every code is documented at https://ngrok.com/docs/errors. A 429 with error code ERR_NGROK_226 means the account exceeded the documented request-rate limit.
- `5XX` — An error. The body carries a machine-readable error_code and a human-readable msg; every code is documented at https://ngrok.com/docs/errors. A 429 with error code ERR_NGROK_226 means the account exceeded the documented request-rate limit.

## Changes

- **2024-10-22** `e40349f8ec6f` — 1 info
  - api operation id `EdgesTLSCreate` removed and replaced with `EdgesTlsCreate`

[Change history](https://skmtc.dev/ngrok/apis/ngrok-openapi/changes/edges/tls/post.md)

---

[API](https://skmtc.dev/ngrok/apis/ngrok-openapi.md) · [All operations](https://skmtc.dev/ngrok/apis/ngrok-openapi/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/ngrok/ngrok-openapi/revisions/c697539ac350/schema)
