Claude Platform Docs

Create Tunnel Certificate

beta.tunnels.certificates.create(tunnel_id, **kwargs) -> BetaTunnelCertificate
POST/v1/tunnels/{tunnel_id}/certificates

The Tunnels API is in research preview. It requires the anthropic-beta: mcp-tunnels-2026-06-22 header and may change without a deprecation period. It supersedes the Admin API endpoints at /v1/organizations/tunnels, which remain available during a migration window.

Registers a public CA certificate on a tunnel. Anthropic verifies the gateway's server certificate against this CA when it terminates the inner TLS session. A tunnel holds at most two non-archived certificates.

Parameters
tunnel_id: String
ca_certificate_pem: String

PEM-encoded X.509 CA certificate. Must contain exactly one certificate and no private-key material. Maximum 8KB.

maxLength8192
betas: Array[AnthropicBeta]

Optional header to specify the beta version(s) you want to use.

One of the following:
String = String
AnthropicBeta = :"message-batches-2024-09-24" | :"prompt-caching-2024-07-31" | :"computer-use-2024-10-22" | 38 more
One of the following:
:"message-batches-2024-09-24"
:"prompt-caching-2024-07-31"
:"computer-use-2024-10-22"
:"computer-use-2025-01-24"
:"pdfs-2024-09-25"
:"token-counting-2024-11-01"
:"token-efficient-tools-2025-02-19"
:"output-128k-2025-02-19"
:"files-api-2025-04-14"
:"mcp-client-2025-04-04"
:"mcp-client-2025-11-20"
:"dev-full-thinking-2025-05-14"
:"interleaved-thinking-2025-05-14"
:"code-execution-2025-05-22"
:"extended-cache-ttl-2025-04-11"
:"context-1m-2025-08-07"
:"context-management-2025-06-27"
:"model-context-window-exceeded-2025-08-26"
:"skills-2025-10-02"
:"fast-mode-2026-02-01"
:"output-300k-2026-03-24"
:"user-profiles-2026-03-24"
:"user-profiles-2026-08-18"
:"advisor-tool-2026-03-01"
:"managed-agents-2026-04-01"
:"cache-diagnosis-2026-04-07"
:"dreaming-2026-04-21"
:"thinking-token-count-2026-05-13"
:"server-side-fallback-2026-06-01"
:"server-side-fallback-2026-07-01"
:"fallback-credit-2026-06-01"
:"fallback-credit-2026-07-01"
:"agent-memory-2026-07-22"
:"mid-conversation-tool-changes-2026-07-01"
:"compact-2026-01-12"
:"computer-use-2025-11-24"
:"mcp-tunnels-2026-06-22"
:"structured-outputs-2025-11-13"
:"task-budgets-2026-03-13"
:"thinking-display-updates-2026-08-18"
:"ce-user-management-2026-07-13"
Returns
class BetaTunnelCertificate { id, archived_at, created_at, 4 more }

A CA certificate attached to a tunnel.

id: String

Unique identifier for the certificate, prefixed with tcrt_.

archived_at: Time

A timestamp in RFC 3339 format

formatdate-time
created_at: Time

A timestamp in RFC 3339 format

formatdate-time
expires_at: Time

A timestamp in RFC 3339 format

formatdate-time
fingerprint: String

Lowercase hex SHA-256 fingerprint of the certificate's DER encoding.

tunnel_id: String

ID of the tunnel the certificate is registered against.

type: :tunnel_certificate

Create Tunnel Certificate

require "anthropic"

anthropic = Anthropic::Client.new(api_key: "my-anthropic-api-key")

beta_tunnel_certificate = anthropic.beta.tunnels.certificates.create("tunnel_id", ca_certificate_pem: "ca_certificate_pem")

puts(beta_tunnel_certificate)
{
  "id": "id",
  "archived_at": "2019-12-27T18:11:19.117Z",
  "created_at": "2019-12-27T18:11:19.117Z",
  "expires_at": "2019-12-27T18:11:19.117Z",
  "fingerprint": "fingerprint",
  "tunnel_id": "tunnel_id",
  "type": "tunnel_certificate"
}
Returns Examples
{
  "id": "id",
  "archived_at": "2019-12-27T18:11:19.117Z",
  "created_at": "2019-12-27T18:11:19.117Z",
  "expires_at": "2019-12-27T18:11:19.117Z",
  "fingerprint": "fingerprint",
  "tunnel_id": "tunnel_id",
  "type": "tunnel_certificate"
}