---
title: "Rotate Tunnel Token"
method: POST
path: "/v1/tunnels/{tunnel_id}/rotate_token?beta=true"
---

# Rotate Tunnel Token

`POST /v1/tunnels/{tunnel_id}/rotate_token?beta=true`

The Tunnels API is in research preview. It requires the `anthropic-beta: mcp-tunnels-2026-06-22` header and may change without a deprecation period. It supersedes the Admin API endpoints at `/v1/organizations/tunnels`, which remain available during a migration window.

Rotates a tunnel's connector token. Rotation invalidates the current token for new connections and returns a fresh value; established connections are not severed. A connector restarted after rotation must use the new value.

## Path parameters

- `tunnel_id` string, required

## Headers

- `anthropic-version` string
- `anthropic-beta` string

## Request body

- BetaRotateTunnelTokenRequestBody
  - `reason` string, nullable — Optional free-text reason for the rotation, recorded for audit.

## Response `200`

Successful response (OK)

- BetaTunnelToken — A tunnel's connector token.
  - `type` 'tunnel_token', required
  - `id` string, required — Stable identifier for the current token value. Changes when the token is rotated.
  - `tunnel_token` string, required — The connector token used to run the tunnel. Treat as a credential.

## Other responses

- `400` — Invalid argument - The client specified an invalid argument
- `401` — Unauthenticated - The request does not have valid authentication credentials
- `403` — Permission denied - The caller does not have permission to execute the specified operation
- `404` — Not found - Some requested entity was not found
- `408` — Deadline exceeded - The deadline expired before the operation could complete
- `409` — Aborted - The operation was aborted due to concurrency issue
- `412` — Failed precondition - Operation was rejected because the system is not in required state
- `413` — Out of range - Operation was attempted past the valid range
- `429` — Resource exhausted - Some resource has been exhausted (rate limiting)
- `431` — Request header fields too large - Request metadata was too large
- `499` — Cancelled - The operation was cancelled by the client
- `500` — Internal - Internal server error
- `501` — Unimplemented - The operation is not implemented or supported
- `503` — Unavailable - The service is currently unavailable
- `504` — Deadline exceeded - Upstream service did not respond in time

---

[API](https://skmtc.net/anthropics/apis/anthropic-api.md) · [All operations](https://skmtc.net/anthropics/apis/anthropic-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/anthropics/anthropic-api/revisions/0042750ea1ee/schema)
