---
title: "Create"
method: POST
path: "/edges/tls"
tags: ["EdgesTLS"]
---

# Create

`POST /edges/tls`

Create a TLS Edge

## Headers

- `ngrok-version` integer, required

## Request body

- TLSEdgeCreate
  - `description` string — human-readable description of what this edge will be used for; optional, max 255 bytes.
  - `metadata` string — arbitrary user-defined machine-readable data of this edge. Optional, max 4096 bytes.
  - `hostports` string[] — hostports served by this edge
  - `backend` EndpointBackendMutate
    - `enabled` boolean — `true` if the module will be applied to traffic, `false` to disable. default `true` if unspecified
    - `backend_id` string — backend to be used to back this endpoint
  - `ip_restriction` EndpointIPPolicyMutate
    - `enabled` boolean — `true` if the module will be applied to traffic, `false` to disable. default `true` if unspecified
    - `ip_policy_ids` string[] — list of all IP policies that will be used to check if a source IP is allowed access to the endpoint
  - `mutual_tls` EndpointMutualTLSMutate
    - `enabled` boolean — `true` if the module will be applied to traffic, `false` to disable. default `true` if unspecified
    - `certificate_authority_ids` string[] — list of certificate authorities that will be used to validate the TLS client certificate presented by the initiator of the TLS connection
  - `tls_termination` EndpointTLSTermination
    - `enabled` boolean — `true` if the module will be applied to traffic, `false` to disable. default `true` if unspecified
    - `terminate_at` string — `edge` if the ngrok edge should terminate TLS traffic, `upstream` if TLS traffic should be passed through to the upstream ngrok agent / application server for termination. if `upstream` is chosen, most other modules will be disallowed because they rely on the ngrok edge being able to access the underlying traffic.
    - `min_version` string — The minimum TLS version used for termination and advertised to the client during the TLS handshake. if unspecified, ngrok will choose an industry-safe default. This value must be null if `terminate_at` is set to `upstream`.
  - `traffic_policy` EndpointTrafficPolicy
    - `enabled` boolean — `true` if the module will be applied to traffic, `false` to disable. default `true` if unspecified
    - `value` string — the traffic policy that should be applied to the traffic on your endpoint.

## Response `201`

Create a TLS Edge

- TLSEdge
  - `id` string — unique identifier of this edge
  - `description` string — human-readable description of what this edge will be used for; optional, max 255 bytes.
  - `metadata` string — arbitrary user-defined machine-readable data of this edge. Optional, max 4096 bytes.
  - `created_at` string — timestamp when the edge configuration was created, RFC 3339 format
  - `uri` string — URI of the edge API resource
  - `hostports` string[] — hostports served by this edge
  - `backend` EndpointBackend
    - `enabled` boolean — `true` if the module will be applied to traffic, `false` to disable. default `true` if unspecified
    - `backend` Ref
      - `id` string — a resource identifier
      - `uri` string — a uri for locating a resource
  - `ip_restriction` EndpointIPPolicy
    - `enabled` boolean — `true` if the module will be applied to traffic, `false` to disable. default `true` if unspecified
    - `ip_policies` Ref[] — list of all IP policies that will be used to check if a source IP is allowed access to the endpoint
      - `id` string — a resource identifier
      - `uri` string — a uri for locating a resource
  - `mutual_tls` EndpointMutualTLS
    - `enabled` boolean — `true` if the module will be applied to traffic, `false` to disable. default `true` if unspecified
    - `certificate_authorities` Ref[] — PEM-encoded CA certificates that will be used to validate. Multiple CAs may be provided by concatenating them together.
      - `id` string — a resource identifier
      - `uri` string — a uri for locating a resource
  - `tls_termination` EndpointTLSTermination
    - `enabled` boolean — `true` if the module will be applied to traffic, `false` to disable. default `true` if unspecified
    - `terminate_at` string — `edge` if the ngrok edge should terminate TLS traffic, `upstream` if TLS traffic should be passed through to the upstream ngrok agent / application server for termination. if `upstream` is chosen, most other modules will be disallowed because they rely on the ngrok edge being able to access the underlying traffic.
    - `min_version` string — The minimum TLS version used for termination and advertised to the client during the TLS handshake. if unspecified, ngrok will choose an industry-safe default. This value must be null if `terminate_at` is set to `upstream`.
  - `traffic_policy` EndpointTrafficPolicy
    - `enabled` boolean — `true` if the module will be applied to traffic, `false` to disable. default `true` if unspecified
    - `value` string — the traffic policy that should be applied to the traffic on your endpoint.

---

[API](https://skmtc.net/ngrok/apis/ngrok-openapi.md) · [All operations](https://skmtc.net/ngrok/apis/ngrok-openapi/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/ngrok/ngrok-openapi/versions/1994bbb04714/schema)
