v49

latestOpenAPI 3.1.0raw.githubusercontent.com2026-07-261319281.7 MB

Create Tunnel Certificate

The Tunnels API is in research preview. It requires the anthropic-beta: mcp-tunnels-2026-06-22 header and may change without a deprecation period. It supersedes the Admin API endpoints at /v1/organizations/tunnels, which remain available during a migration window.

Registers a public CA certificate on a tunnel. Anthropic verifies the gateway's server certificate against this CA when it terminates the inner TLS session. A tunnel holds at most two non-archived certificates.

post/v1/tunnels/{tunnel_id}/certificates?beta=true

Path parameters

tunnel_idstring required

Path parameter tunnel_id

Headers

anthropic-versionstring
anthropic-betastring

Request body

ca_certificate_pemstring required

PEM-encoded X.509 CA certificate. Must contain exactly one certificate and no private-key material. Maximum 8KB.

Response

Successful response (OK)

type'tunnel_certificate' required
idstring required

Unique identifier for the certificate, prefixed with tcrt_.

tunnel_idstring required

ID of the tunnel the certificate is registered against.

fingerprintstring required

Lowercase hex SHA-256 fingerprint of the certificate's DER encoding.

expires_atstring date-time required

A timestamp in RFC 3339 format

created_atstring date-time required

A timestamp in RFC 3339 format

archived_atstring date-time required

A timestamp in RFC 3339 format