---
title: "Create"
method: POST
path: "/ssh_credentials"
tags: ["SSHCredentials"]
---

# Create

`POST /ssh_credentials`

Create a new ssh_credential from an uploaded public SSH key. This ssh credential can be used to start new tunnels via ngrok's SSH gateway.

## Headers

- `ngrok-version` integer, required

## Request body

- SSHCredentialCreate
  - `description` string — human-readable description of who or what will use the ssh credential to authenticate. Optional, max 255 bytes.
  - `metadata` string — arbitrary user-defined machine-readable data of this ssh credential. Optional, max 4096 bytes.
  - `acl` string[] — optional list of ACL rules. If unspecified, the credential will have no restrictions. The only allowed ACL rule at this time is the `bind` rule. The `bind` rule allows the caller to restrict what domains, addresses, and labels the token is allowed to bind. For example, to allow the token to open a tunnel on example.ngrok.io your ACL would include the rule `bind:example.ngrok.io`. Bind rules for domains may specify a leading wildcard to match multiple domains with a common suffix. For example, you may specify a rule of `bind:*.example.com` which will allow `x.example.com`, `y.example.com`, `*.example.com`, etc. Bind rules for labels may specify a wildcard key and/or value to match multiple labels. For example, you may specify a rule of `bind:*=example` which will allow `x=example`, `y=example`, etc. A rule of `'*'` is equivalent to no acl at all and will explicitly permit all actions.
  - `public_key` string, required — the PEM-encoded public key of the SSH keypair that will be used to authenticate
  - `owner_id` string — If supplied at credential creation, ownership will be assigned to the specified User or Bot. Only admins may specify an owner other than themselves. Defaults to the authenticated User or Bot.

## Response `201`

Create a new ssh_credential from an uploaded public SSH key. This ssh credential can be used to start new tunnels via ngrok's SSH gateway.

- SSHCredential
  - `id` string — unique ssh credential resource identifier
  - `uri` string — URI of the ssh credential API resource
  - `created_at` string — timestamp when the ssh credential was created, RFC 3339 format
  - `description` string — human-readable description of who or what will use the ssh credential to authenticate. Optional, max 255 bytes.
  - `metadata` string — arbitrary user-defined machine-readable data of this ssh credential. Optional, max 4096 bytes.
  - `public_key` string — the PEM-encoded public key of the SSH keypair that will be used to authenticate
  - `acl` string[] — optional list of ACL rules. If unspecified, the credential will have no restrictions. The only allowed ACL rule at this time is the `bind` rule. The `bind` rule allows the caller to restrict what domains, addresses, and labels the token is allowed to bind. For example, to allow the token to open a tunnel on example.ngrok.io your ACL would include the rule `bind:example.ngrok.io`. Bind rules for domains may specify a leading wildcard to match multiple domains with a common suffix. For example, you may specify a rule of `bind:*.example.com` which will allow `x.example.com`, `y.example.com`, `*.example.com`, etc. Bind rules for labels may specify a wildcard key and/or value to match multiple labels. For example, you may specify a rule of `bind:*=example` which will allow `x=example`, `y=example`, etc. A rule of `'*'` is equivalent to no acl at all and will explicitly permit all actions.
  - `owner_id` string — If supplied at credential creation, ownership will be assigned to the specified User or Bot. Only admins may specify an owner other than themselves. Defaults to the authenticated User or Bot.

## Other responses

- `4XX` — An error. The body carries a machine-readable error_code and a human-readable msg; every code is documented at https://ngrok.com/docs/errors. A 429 with error code ERR_NGROK_226 means the account exceeded the documented request-rate limit.
- `5XX` — An error. The body carries a machine-readable error_code and a human-readable msg; every code is documented at https://ngrok.com/docs/errors. A 429 with error code ERR_NGROK_226 means the account exceeded the documented request-rate limit.

## Changes

- **2024-10-22** `e40349f8ec6f` — 1 info
  - api operation id `SSHCredentialsCreate` removed and replaced with `SshCredentialsCreate`

[Change history](https://skmtc.dev/ngrok/apis/ngrok-openapi/changes/ssh_credentials/post.md)

---

[API](https://skmtc.dev/ngrok/apis/ngrok-openapi.md) · [All operations](https://skmtc.dev/ngrok/apis/ngrok-openapi/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/ngrok/ngrok-openapi/revisions/c697539ac350/schema)
