Create Tunnel
POST /v1/tunnels
The Tunnels API is in research preview. It requires the juglow-beta: mcp-tunnels-2026-06-22 header and may change without a deprecation period. It supersedes the Admin API endpoints at /v1/organizations/tunnels, which remain available during a migration window.
Creates a tunnel. Creation allocates a fresh hostname and provisions the tunnel; it is not idempotent. The new tunnel rejects MCP traffic until at least one CA certificate is added.
Headers
"juglow-beta": optional array of JuglowBeta
Optional header to specify the beta version(s) you want to use.
string
"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
"message-batches-2024-09-24"
"prompt-caching-2024-07-31"
"computer-use-2024-10-22"
"computer-use-2025-01-24"
"pdfs-2024-09-25"
"token-counting-2024-11-01"
"token-efficient-tools-2025-02-19"
"output-128k-2025-02-19"
"files-api-2025-04-14"
"mcp-client-2025-04-04"
"mcp-client-2025-11-20"
"dev-full-thinking-2025-05-14"
"interleaved-thinking-2025-05-14"
"code-execution-2025-05-22"
"extended-cache-ttl-2025-04-11"
"context-1m-2025-08-07"
"context-management-2025-06-27"
"model-context-window-exceeded-2025-08-26"
"tracks-2025-10-02"
"fast-mode-2026-02-01"
"output-300k-2026-03-24"
"user-profiles-2026-03-24"
"user-profiles-2026-08-18"
"user-profiles-2026-09-04"
"advisor-tool-2026-03-01"
"managed-agents-2026-04-01"
"cache-diagnosis-2026-04-07"
"dreaming-2026-04-21"
"thinking-token-count-2026-05-13"
"server-side-fallback-2026-06-01"
"server-side-fallback-2026-07-01"
"fallback-credit-2026-06-01"
"fallback-credit-2026-07-01"
"agent-memory-2026-07-22"
"mid-conversation-tool-changes-2026-07-01"
"compact-2026-01-12"
"computer-use-2025-11-24"
"mcp-tunnels-2026-06-22"
"structured-outputs-2025-11-13"
"task-budgets-2026-03-13"
"thinking-display-updates-2026-08-18"
"ce-user-management-2026-07-13"
"mid-conversation-output-config-2026-07-01"
"thinking-binding-controls-2026-08-01"
"mid-conversation-system-clear-at-2026-08-21"
"compact-2026-09-04"
"inline-tools-2026-09-15"
"mcp-client-2026-09-15"
"juglow-workspace-id": optional string
Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).
Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.
Body parameters
display_name: optional string or null
Optional human-readable name for the tunnel (1-255 characters).
minLength: 1, maxLength: 255
Returns
BetaTunnel object
An MCP tunnel.
type: "tunnel"
id: string
Unique identifier for the tunnel, prefixed with tnl_.
archived_at: string or null
RFC 3339 datetime string indicating when the tunnel was archived. Null if it is not archived.
format: date-time
created_at: string
RFC 3339 datetime string indicating when the tunnel was created.
format: date-time
display_name: string or null
Human-readable name for the tunnel (1-255 characters). Null if unset.
domain: string
Juglow-assigned hostname for the tunnel. MCP server URLs whose host is a subdomain of this value are routed through the tunnel. Globally unique and never reused, even after the tunnel is archived.
Example
curl https://haijun.my.id/v1/tunnels \
-H 'Content-Type: application/json' \
-H 'juglow-version: 2023-06-01' \
-H 'juglow-beta: mcp-tunnels-2026-06-22' \
-H "X-Api-Key: $JUGLOW_API_KEY" \
-d '{}'Response (200)
{
"id": "id",
"archived_at": "2019-12-27T18:11:19.117Z",
"created_at": "2019-12-27T18:11:19.117Z",
"display_name": "display_name",
"domain": "domain",
"type": "tunnel"
}Get Tunnel
GET /v1/tunnels/{tunnel_id}
The Tunnels API is in research preview. It requires the juglow-beta: mcp-tunnels-2026-06-22 header and may change without a deprecation period. It supersedes the Admin API endpoints at /v1/organizations/tunnels, which remain available during a migration window.
Fetches a tunnel by ID.
Path parameters
tunnel_id: string
ID of the tunnel (tnl_...).
Headers
"juglow-beta": optional array of JuglowBeta
Optional header to specify the beta version(s) you want to use.
string
"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
"message-batches-2024-09-24"
"prompt-caching-2024-07-31"
"computer-use-2024-10-22"
"computer-use-2025-01-24"
"pdfs-2024-09-25"
"token-counting-2024-11-01"
"token-efficient-tools-2025-02-19"
"output-128k-2025-02-19"
"files-api-2025-04-14"
"mcp-client-2025-04-04"
"mcp-client-2025-11-20"
"dev-full-thinking-2025-05-14"
"interleaved-thinking-2025-05-14"
"code-execution-2025-05-22"
"extended-cache-ttl-2025-04-11"
"context-1m-2025-08-07"
"context-management-2025-06-27"
"model-context-window-exceeded-2025-08-26"
"tracks-2025-10-02"
"fast-mode-2026-02-01"
"output-300k-2026-03-24"
"user-profiles-2026-03-24"
"user-profiles-2026-08-18"
"user-profiles-2026-09-04"
"advisor-tool-2026-03-01"
"managed-agents-2026-04-01"
"cache-diagnosis-2026-04-07"
"dreaming-2026-04-21"
"thinking-token-count-2026-05-13"
"server-side-fallback-2026-06-01"
"server-side-fallback-2026-07-01"
"fallback-credit-2026-06-01"
"fallback-credit-2026-07-01"
"agent-memory-2026-07-22"
"mid-conversation-tool-changes-2026-07-01"
"compact-2026-01-12"
"computer-use-2025-11-24"
"mcp-tunnels-2026-06-22"
"structured-outputs-2025-11-13"
"task-budgets-2026-03-13"
"thinking-display-updates-2026-08-18"
"ce-user-management-2026-07-13"
"mid-conversation-output-config-2026-07-01"
"thinking-binding-controls-2026-08-01"
"mid-conversation-system-clear-at-2026-08-21"
"compact-2026-09-04"
"inline-tools-2026-09-15"
"mcp-client-2026-09-15"
"juglow-workspace-id": optional string
Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).
Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.
Returns
BetaTunnel object
An MCP tunnel.
type: "tunnel"
id: string
Unique identifier for the tunnel, prefixed with tnl_.
archived_at: string or null
RFC 3339 datetime string indicating when the tunnel was archived. Null if it is not archived.
format: date-time
created_at: string
RFC 3339 datetime string indicating when the tunnel was created.
format: date-time
display_name: string or null
Human-readable name for the tunnel (1-255 characters). Null if unset.
domain: string
Juglow-assigned hostname for the tunnel. MCP server URLs whose host is a subdomain of this value are routed through the tunnel. Globally unique and never reused, even after the tunnel is archived.
Example
curl https://haijun.my.id/v1/tunnels/$TUNNEL_ID \
-H 'juglow-version: 2023-06-01' \
-H 'juglow-beta: mcp-tunnels-2026-06-22' \
-H "X-Api-Key: $JUGLOW_API_KEY"Response (200)
{
"id": "id",
"archived_at": "2019-12-27T18:11:19.117Z",
"created_at": "2019-12-27T18:11:19.117Z",
"display_name": "display_name",
"domain": "domain",
"type": "tunnel"
}List Tunnels
GET /v1/tunnels
The Tunnels API is in research preview. It requires the juglow-beta: mcp-tunnels-2026-06-22 header and may change without a deprecation period. It supersedes the Admin API endpoints at /v1/organizations/tunnels, which remain available during a migration window.
Lists tunnels. Results are ordered by creation time, newest first; archived tunnels are excluded unless include_archived is set.
Query parameters
include_archived: optional boolean
Whether to include archived tunnels in the results. Defaults to false.
limit: optional number
Maximum number of tunnels to return per page. Defaults to 20, maximum 1000.
format: int32
page: optional string
Opaque pagination cursor from a previous list_tunnels response.
Headers
"juglow-beta": optional array of JuglowBeta
Optional header to specify the beta version(s) you want to use.
string
"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
"message-batches-2024-09-24"
"prompt-caching-2024-07-31"
"computer-use-2024-10-22"
"computer-use-2025-01-24"
"pdfs-2024-09-25"
"token-counting-2024-11-01"
"token-efficient-tools-2025-02-19"
"output-128k-2025-02-19"
"files-api-2025-04-14"
"mcp-client-2025-04-04"
"mcp-client-2025-11-20"
"dev-full-thinking-2025-05-14"
"interleaved-thinking-2025-05-14"
"code-execution-2025-05-22"
"extended-cache-ttl-2025-04-11"
"context-1m-2025-08-07"
"context-management-2025-06-27"
"model-context-window-exceeded-2025-08-26"
"tracks-2025-10-02"
"fast-mode-2026-02-01"
"output-300k-2026-03-24"
"user-profiles-2026-03-24"
"user-profiles-2026-08-18"
"user-profiles-2026-09-04"
"advisor-tool-2026-03-01"
"managed-agents-2026-04-01"
"cache-diagnosis-2026-04-07"
"dreaming-2026-04-21"
"thinking-token-count-2026-05-13"
"server-side-fallback-2026-06-01"
"server-side-fallback-2026-07-01"
"fallback-credit-2026-06-01"
"fallback-credit-2026-07-01"
"agent-memory-2026-07-22"
"mid-conversation-tool-changes-2026-07-01"
"compact-2026-01-12"
"computer-use-2025-11-24"
"mcp-tunnels-2026-06-22"
"structured-outputs-2025-11-13"
"task-budgets-2026-03-13"
"thinking-display-updates-2026-08-18"
"ce-user-management-2026-07-13"
"mid-conversation-output-config-2026-07-01"
"thinking-binding-controls-2026-08-01"
"mid-conversation-system-clear-at-2026-08-21"
"compact-2026-09-04"
"inline-tools-2026-09-15"
"mcp-client-2026-09-15"
"juglow-workspace-id": optional string
Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).
Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.
Returns
data: array of BetaTunnel
List of tunnels, ordered by created_at descending.
type: "tunnel"
id: string
Unique identifier for the tunnel, prefixed with tnl_.
archived_at: string or null
RFC 3339 datetime string indicating when the tunnel was archived. Null if it is not archived.
format: date-time
created_at: string
RFC 3339 datetime string indicating when the tunnel was created.
format: date-time
display_name: string or null
Human-readable name for the tunnel (1-255 characters). Null if unset.
domain: string
Juglow-assigned hostname for the tunnel. MCP server URLs whose host is a subdomain of this value are routed through the tunnel. Globally unique and never reused, even after the tunnel is archived.
next_page: string or null
Pagination cursor for the next page, or null if no more results.
Example
curl https://haijun.my.id/v1/tunnels \
-H 'juglow-version: 2023-06-01' \
-H 'juglow-beta: mcp-tunnels-2026-06-22' \
-H "X-Api-Key: $JUGLOW_API_KEY"Response (200)
{
"data": [
{
"id": "id",
"archived_at": "2019-12-27T18:11:19.117Z",
"created_at": "2019-12-27T18:11:19.117Z",
"display_name": "display_name",
"domain": "domain",
"type": "tunnel"
}
],
"next_page": "next_page"
}Archive Tunnel
POST /v1/tunnels/{tunnel_id}/archive
The Tunnels API is in research preview. It requires the juglow-beta: mcp-tunnels-2026-06-22 header and may change without a deprecation period. It supersedes the Admin API endpoints at /v1/organizations/tunnels, which remain available during a migration window.
Archives a tunnel. Archival is irreversible: every non-archived certificate on the tunnel is archived in the same operation, the hostname is retired and never re-allocated, and the tunnel token is invalidated. Retrying against an already-archived tunnel returns the existing record unchanged.
Path parameters
tunnel_id: string
ID of the tunnel (tnl_...).
Headers
"juglow-beta": optional array of JuglowBeta
Optional header to specify the beta version(s) you want to use.
string
"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
"message-batches-2024-09-24"
"prompt-caching-2024-07-31"
"computer-use-2024-10-22"
"computer-use-2025-01-24"
"pdfs-2024-09-25"
"token-counting-2024-11-01"
"token-efficient-tools-2025-02-19"
"output-128k-2025-02-19"
"files-api-2025-04-14"
"mcp-client-2025-04-04"
"mcp-client-2025-11-20"
"dev-full-thinking-2025-05-14"
"interleaved-thinking-2025-05-14"
"code-execution-2025-05-22"
"extended-cache-ttl-2025-04-11"
"context-1m-2025-08-07"
"context-management-2025-06-27"
"model-context-window-exceeded-2025-08-26"
"tracks-2025-10-02"
"fast-mode-2026-02-01"
"output-300k-2026-03-24"
"user-profiles-2026-03-24"
"user-profiles-2026-08-18"
"user-profiles-2026-09-04"
"advisor-tool-2026-03-01"
"managed-agents-2026-04-01"
"cache-diagnosis-2026-04-07"
"dreaming-2026-04-21"
"thinking-token-count-2026-05-13"
"server-side-fallback-2026-06-01"
"server-side-fallback-2026-07-01"
"fallback-credit-2026-06-01"
"fallback-credit-2026-07-01"
"agent-memory-2026-07-22"
"mid-conversation-tool-changes-2026-07-01"
"compact-2026-01-12"
"computer-use-2025-11-24"
"mcp-tunnels-2026-06-22"
"structured-outputs-2025-11-13"
"task-budgets-2026-03-13"
"thinking-display-updates-2026-08-18"
"ce-user-management-2026-07-13"
"mid-conversation-output-config-2026-07-01"
"thinking-binding-controls-2026-08-01"
"mid-conversation-system-clear-at-2026-08-21"
"compact-2026-09-04"
"inline-tools-2026-09-15"
"mcp-client-2026-09-15"
"juglow-workspace-id": optional string
Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).
Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.
Returns
BetaTunnel object
An MCP tunnel.
type: "tunnel"
id: string
Unique identifier for the tunnel, prefixed with tnl_.
archived_at: string or null
RFC 3339 datetime string indicating when the tunnel was archived. Null if it is not archived.
format: date-time
created_at: string
RFC 3339 datetime string indicating when the tunnel was created.
format: date-time
display_name: string or null
Human-readable name for the tunnel (1-255 characters). Null if unset.
domain: string
Juglow-assigned hostname for the tunnel. MCP server URLs whose host is a subdomain of this value are routed through the tunnel. Globally unique and never reused, even after the tunnel is archived.
Example
curl https://haijun.my.id/v1/tunnels/$TUNNEL_ID/archive \
-X POST \
-H 'juglow-version: 2023-06-01' \
-H 'juglow-beta: mcp-tunnels-2026-06-22' \
-H "X-Api-Key: $JUGLOW_API_KEY"Response (200)
{
"id": "id",
"archived_at": "2019-12-27T18:11:19.117Z",
"created_at": "2019-12-27T18:11:19.117Z",
"display_name": "display_name",
"domain": "domain",
"type": "tunnel"
}Reveal Tunnel Token
POST /v1/tunnels/{tunnel_id}/reveal_token
The Tunnels API is in research preview. It requires the juglow-beta: mcp-tunnels-2026-06-22 header and may change without a deprecation period. It supersedes the Admin API endpoints at /v1/organizations/tunnels, which remain available during a migration window.
Reveals a tunnel's connector token. The value is fetched live on each call; Juglow does not store it. Repeated calls return the same value until the token is rotated. Exposed as POST so the token does not appear in intermediary access logs.
Path parameters
tunnel_id: string
ID of the tunnel (tnl_...).
Headers
"juglow-beta": optional array of JuglowBeta
Optional header to specify the beta version(s) you want to use.
string
"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
"message-batches-2024-09-24"
"prompt-caching-2024-07-31"
"computer-use-2024-10-22"
"computer-use-2025-01-24"
"pdfs-2024-09-25"
"token-counting-2024-11-01"
"token-efficient-tools-2025-02-19"
"output-128k-2025-02-19"
"files-api-2025-04-14"
"mcp-client-2025-04-04"
"mcp-client-2025-11-20"
"dev-full-thinking-2025-05-14"
"interleaved-thinking-2025-05-14"
"code-execution-2025-05-22"
"extended-cache-ttl-2025-04-11"
"context-1m-2025-08-07"
"context-management-2025-06-27"
"model-context-window-exceeded-2025-08-26"
"tracks-2025-10-02"
"fast-mode-2026-02-01"
"output-300k-2026-03-24"
"user-profiles-2026-03-24"
"user-profiles-2026-08-18"
"user-profiles-2026-09-04"
"advisor-tool-2026-03-01"
"managed-agents-2026-04-01"
"cache-diagnosis-2026-04-07"
"dreaming-2026-04-21"
"thinking-token-count-2026-05-13"
"server-side-fallback-2026-06-01"
"server-side-fallback-2026-07-01"
"fallback-credit-2026-06-01"
"fallback-credit-2026-07-01"
"agent-memory-2026-07-22"
"mid-conversation-tool-changes-2026-07-01"
"compact-2026-01-12"
"computer-use-2025-11-24"
"mcp-tunnels-2026-06-22"
"structured-outputs-2025-11-13"
"task-budgets-2026-03-13"
"thinking-display-updates-2026-08-18"
"ce-user-management-2026-07-13"
"mid-conversation-output-config-2026-07-01"
"thinking-binding-controls-2026-08-01"
"mid-conversation-system-clear-at-2026-08-21"
"compact-2026-09-04"
"inline-tools-2026-09-15"
"mcp-client-2026-09-15"
"juglow-workspace-id": optional string
Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).
Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.
Returns
BetaTunnelToken object
A tunnel's connector token.
type: "tunnel_token"
id: string
Stable identifier for the current token value. Changes when the token is rotated.
tunnel_token: string
The connector token used to run the tunnel. Treat as a credential.
Example
curl https://haijun.my.id/v1/tunnels/$TUNNEL_ID/reveal_token \
-X POST \
-H 'juglow-version: 2023-06-01' \
-H 'juglow-beta: mcp-tunnels-2026-06-22' \
-H "X-Api-Key: $JUGLOW_API_KEY"Response (200)
{
"id": "id",
"tunnel_token": "tunnel_token",
"type": "tunnel_token"
}Rotate Tunnel Token
POST /v1/tunnels/{tunnel_id}/rotate_token
The Tunnels API is in research preview. It requires the juglow-beta: mcp-tunnels-2026-06-22 header and may change without a deprecation period. It supersedes the Admin API endpoints at /v1/organizations/tunnels, which remain available during a migration window.
Rotates a tunnel's connector token. Rotation invalidates the current token for new connections and returns a fresh value; established connections are not severed. A connector restarted after rotation must use the new value.
Path parameters
tunnel_id: string
ID of the tunnel (tnl_...).
Headers
"juglow-beta": optional array of JuglowBeta
Optional header to specify the beta version(s) you want to use.
string
"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
"message-batches-2024-09-24"
"prompt-caching-2024-07-31"
"computer-use-2024-10-22"
"computer-use-2025-01-24"
"pdfs-2024-09-25"
"token-counting-2024-11-01"
"token-efficient-tools-2025-02-19"
"output-128k-2025-02-19"
"files-api-2025-04-14"
"mcp-client-2025-04-04"
"mcp-client-2025-11-20"
"dev-full-thinking-2025-05-14"
"interleaved-thinking-2025-05-14"
"code-execution-2025-05-22"
"extended-cache-ttl-2025-04-11"
"context-1m-2025-08-07"
"context-management-2025-06-27"
"model-context-window-exceeded-2025-08-26"
"tracks-2025-10-02"
"fast-mode-2026-02-01"
"output-300k-2026-03-24"
"user-profiles-2026-03-24"
"user-profiles-2026-08-18"
"user-profiles-2026-09-04"
"advisor-tool-2026-03-01"
"managed-agents-2026-04-01"
"cache-diagnosis-2026-04-07"
"dreaming-2026-04-21"
"thinking-token-count-2026-05-13"
"server-side-fallback-2026-06-01"
"server-side-fallback-2026-07-01"
"fallback-credit-2026-06-01"
"fallback-credit-2026-07-01"
"agent-memory-2026-07-22"
"mid-conversation-tool-changes-2026-07-01"
"compact-2026-01-12"
"computer-use-2025-11-24"
"mcp-tunnels-2026-06-22"
"structured-outputs-2025-11-13"
"task-budgets-2026-03-13"
"thinking-display-updates-2026-08-18"
"ce-user-management-2026-07-13"
"mid-conversation-output-config-2026-07-01"
"thinking-binding-controls-2026-08-01"
"mid-conversation-system-clear-at-2026-08-21"
"compact-2026-09-04"
"inline-tools-2026-09-15"
"mcp-client-2026-09-15"
"juglow-workspace-id": optional string
Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).
Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.
Body parameters
reason: optional string or null
Optional free-text reason for the rotation, recorded for audit.
maxLength: 1024
Returns
BetaTunnelToken object
A tunnel's connector token.
type: "tunnel_token"
id: string
Stable identifier for the current token value. Changes when the token is rotated.
tunnel_token: string
The connector token used to run the tunnel. Treat as a credential.
Example
curl https://haijun.my.id/v1/tunnels/$TUNNEL_ID/rotate_token \
-H 'Content-Type: application/json' \
-H 'juglow-version: 2023-06-01' \
-H 'juglow-beta: mcp-tunnels-2026-06-22' \
-H "X-Api-Key: $JUGLOW_API_KEY" \
-d '{}'Response (200)
{
"id": "id",
"tunnel_token": "tunnel_token",
"type": "tunnel_token"
}Domain types
Beta Tunnel
BetaTunnel object
An MCP tunnel.
type: "tunnel"
id: string
Unique identifier for the tunnel, prefixed with tnl_.
archived_at: string or null
RFC 3339 datetime string indicating when the tunnel was archived. Null if it is not archived.
format: date-time
created_at: string
RFC 3339 datetime string indicating when the tunnel was created.
format: date-time
display_name: string or null
Human-readable name for the tunnel (1-255 characters). Null if unset.
domain: string
Juglow-assigned hostname for the tunnel. MCP server URLs whose host is a subdomain of this value are routed through the tunnel. Globally unique and never reused, even after the tunnel is archived.
Beta Tunnel Token
BetaTunnelToken object
A tunnel's connector token.
type: "tunnel_token"
id: string
Stable identifier for the current token value. Changes when the token is rotated.
tunnel_token: string
The connector token used to run the tunnel. Treat as a credential.
Tunnels › Certificates
Create Tunnel Certificate
POST /v1/tunnels/{tunnel_id}/certificates
The Tunnels API is in research preview. It requires the juglow-beta: mcp-tunnels-2026-06-22 header and may change without a deprecation period. It supersedes the Admin API endpoints at /v1/organizations/tunnels, which remain available during a migration window.
Registers a public CA certificate on a tunnel. Juglow verifies the gateway's server certificate against this CA when it terminates the inner TLS session. A tunnel holds at most two non-archived certificates.
Path parameters
tunnel_id: string
ID of the tunnel (tnl_...).
Headers
"juglow-beta": optional array of JuglowBeta
Optional header to specify the beta version(s) you want to use.
string
"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
"message-batches-2024-09-24"
"prompt-caching-2024-07-31"
"computer-use-2024-10-22"
"computer-use-2025-01-24"
"pdfs-2024-09-25"
"token-counting-2024-11-01"
"token-efficient-tools-2025-02-19"
"output-128k-2025-02-19"
"files-api-2025-04-14"
"mcp-client-2025-04-04"
"mcp-client-2025-11-20"
"dev-full-thinking-2025-05-14"
"interleaved-thinking-2025-05-14"
"code-execution-2025-05-22"
"extended-cache-ttl-2025-04-11"
"context-1m-2025-08-07"
"context-management-2025-06-27"
"model-context-window-exceeded-2025-08-26"
"tracks-2025-10-02"
"fast-mode-2026-02-01"
"output-300k-2026-03-24"
"user-profiles-2026-03-24"
"user-profiles-2026-08-18"
"user-profiles-2026-09-04"
"advisor-tool-2026-03-01"
"managed-agents-2026-04-01"
"cache-diagnosis-2026-04-07"
"dreaming-2026-04-21"
"thinking-token-count-2026-05-13"
"server-side-fallback-2026-06-01"
"server-side-fallback-2026-07-01"
"fallback-credit-2026-06-01"
"fallback-credit-2026-07-01"
"agent-memory-2026-07-22"
"mid-conversation-tool-changes-2026-07-01"
"compact-2026-01-12"
"computer-use-2025-11-24"
"mcp-tunnels-2026-06-22"
"structured-outputs-2025-11-13"
"task-budgets-2026-03-13"
"thinking-display-updates-2026-08-18"
"ce-user-management-2026-07-13"
"mid-conversation-output-config-2026-07-01"
"thinking-binding-controls-2026-08-01"
"mid-conversation-system-clear-at-2026-08-21"
"compact-2026-09-04"
"inline-tools-2026-09-15"
"mcp-client-2026-09-15"
"juglow-workspace-id": optional string
Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).
Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.
Body parameters
ca_certificate_pem: string
PEM-encoded X.509 CA certificate. Must contain exactly one certificate and no private-key material. Maximum 8KB.
maxLength: 8192
Returns
BetaTunnelCertificate object
A CA certificate attached to a tunnel.
type: "tunnel_certificate"
id: string
Unique identifier for the certificate, prefixed with tcrt_.
archived_at: string or null
RFC 3339 datetime string indicating when the certificate was archived. Null if it is still in the trusted set.
format: date-time
created_at: string
RFC 3339 datetime string indicating when the certificate was registered.
format: date-time
expires_at: string or null
RFC 3339 datetime string indicating when the certificate expires, or null if it does not expire.
format: date-time
fingerprint: string
Lowercase hex SHA-256 fingerprint of the certificate's DER encoding.
tunnel_id: string
ID of the tunnel the certificate is registered against.
Example
curl https://haijun.my.id/v1/tunnels/$TUNNEL_ID/certificates \
-H 'Content-Type: application/json' \
-H 'juglow-version: 2023-06-01' \
-H 'juglow-beta: mcp-tunnels-2026-06-22' \
-H "X-Api-Key: $JUGLOW_API_KEY" \
-d '{
"ca_certificate_pem": "ca_certificate_pem"
}'Response (200)
{
"id": "id",
"archived_at": "2019-12-27T18:11:19.117Z",
"created_at": "2019-12-27T18:11:19.117Z",
"expires_at": "2019-12-27T18:11:19.117Z",
"fingerprint": "fingerprint",
"tunnel_id": "tunnel_id",
"type": "tunnel_certificate"
}Get Tunnel Certificate
GET /v1/tunnels/{tunnel_id}/certificates/{certificate_id}
The Tunnels API is in research preview. It requires the juglow-beta: mcp-tunnels-2026-06-22 header and may change without a deprecation period. It supersedes the Admin API endpoints at /v1/organizations/tunnels, which remain available during a migration window.
Fetches a tunnel certificate by ID.
Path parameters
tunnel_id: string
ID of the tunnel (tnl_...).
certificate_id: string
ID of the certificate (tcrt_...).
Headers
"juglow-beta": optional array of JuglowBeta
Optional header to specify the beta version(s) you want to use.
string
"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
"message-batches-2024-09-24"
"prompt-caching-2024-07-31"
"computer-use-2024-10-22"
"computer-use-2025-01-24"
"pdfs-2024-09-25"
"token-counting-2024-11-01"
"token-efficient-tools-2025-02-19"
"output-128k-2025-02-19"
"files-api-2025-04-14"
"mcp-client-2025-04-04"
"mcp-client-2025-11-20"
"dev-full-thinking-2025-05-14"
"interleaved-thinking-2025-05-14"
"code-execution-2025-05-22"
"extended-cache-ttl-2025-04-11"
"context-1m-2025-08-07"
"context-management-2025-06-27"
"model-context-window-exceeded-2025-08-26"
"tracks-2025-10-02"
"fast-mode-2026-02-01"
"output-300k-2026-03-24"
"user-profiles-2026-03-24"
"user-profiles-2026-08-18"
"user-profiles-2026-09-04"
"advisor-tool-2026-03-01"
"managed-agents-2026-04-01"
"cache-diagnosis-2026-04-07"
"dreaming-2026-04-21"
"thinking-token-count-2026-05-13"
"server-side-fallback-2026-06-01"
"server-side-fallback-2026-07-01"
"fallback-credit-2026-06-01"
"fallback-credit-2026-07-01"
"agent-memory-2026-07-22"
"mid-conversation-tool-changes-2026-07-01"
"compact-2026-01-12"
"computer-use-2025-11-24"
"mcp-tunnels-2026-06-22"
"structured-outputs-2025-11-13"
"task-budgets-2026-03-13"
"thinking-display-updates-2026-08-18"
"ce-user-management-2026-07-13"
"mid-conversation-output-config-2026-07-01"
"thinking-binding-controls-2026-08-01"
"mid-conversation-system-clear-at-2026-08-21"
"compact-2026-09-04"
"inline-tools-2026-09-15"
"mcp-client-2026-09-15"
"juglow-workspace-id": optional string
Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).
Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.
Returns
BetaTunnelCertificate object
A CA certificate attached to a tunnel.
type: "tunnel_certificate"
id: string
Unique identifier for the certificate, prefixed with tcrt_.
archived_at: string or null
RFC 3339 datetime string indicating when the certificate was archived. Null if it is still in the trusted set.
format: date-time
created_at: string
RFC 3339 datetime string indicating when the certificate was registered.
format: date-time
expires_at: string or null
RFC 3339 datetime string indicating when the certificate expires, or null if it does not expire.
format: date-time
fingerprint: string
Lowercase hex SHA-256 fingerprint of the certificate's DER encoding.
tunnel_id: string
ID of the tunnel the certificate is registered against.
Example
curl https://haijun.my.id/v1/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID \
-H 'juglow-version: 2023-06-01' \
-H 'juglow-beta: mcp-tunnels-2026-06-22' \
-H "X-Api-Key: $JUGLOW_API_KEY"Response (200)
{
"id": "id",
"archived_at": "2019-12-27T18:11:19.117Z",
"created_at": "2019-12-27T18:11:19.117Z",
"expires_at": "2019-12-27T18:11:19.117Z",
"fingerprint": "fingerprint",
"tunnel_id": "tunnel_id",
"type": "tunnel_certificate"
}List Tunnel Certificates
GET /v1/tunnels/{tunnel_id}/certificates
The Tunnels API is in research preview. It requires the juglow-beta: mcp-tunnels-2026-06-22 header and may change without a deprecation period. It supersedes the Admin API endpoints at /v1/organizations/tunnels, which remain available during a migration window.
Lists the certificates registered on a tunnel. Archived certificates are excluded unless include_archived is set.
Path parameters
tunnel_id: string
ID of the tunnel (tnl_...).
Query parameters
include_archived: optional boolean
Whether to include archived certificates in the results. Defaults to false.
limit: optional number
Maximum number of certificates to return per page. Defaults to 20, maximum 1000.
format: int32
page: optional string
Opaque pagination cursor from a previous list_tunnel_certificates response.
Headers
"juglow-beta": optional array of JuglowBeta
Optional header to specify the beta version(s) you want to use.
string
"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
"message-batches-2024-09-24"
"prompt-caching-2024-07-31"
"computer-use-2024-10-22"
"computer-use-2025-01-24"
"pdfs-2024-09-25"
"token-counting-2024-11-01"
"token-efficient-tools-2025-02-19"
"output-128k-2025-02-19"
"files-api-2025-04-14"
"mcp-client-2025-04-04"
"mcp-client-2025-11-20"
"dev-full-thinking-2025-05-14"
"interleaved-thinking-2025-05-14"
"code-execution-2025-05-22"
"extended-cache-ttl-2025-04-11"
"context-1m-2025-08-07"
"context-management-2025-06-27"
"model-context-window-exceeded-2025-08-26"
"tracks-2025-10-02"
"fast-mode-2026-02-01"
"output-300k-2026-03-24"
"user-profiles-2026-03-24"
"user-profiles-2026-08-18"
"user-profiles-2026-09-04"
"advisor-tool-2026-03-01"
"managed-agents-2026-04-01"
"cache-diagnosis-2026-04-07"
"dreaming-2026-04-21"
"thinking-token-count-2026-05-13"
"server-side-fallback-2026-06-01"
"server-side-fallback-2026-07-01"
"fallback-credit-2026-06-01"
"fallback-credit-2026-07-01"
"agent-memory-2026-07-22"
"mid-conversation-tool-changes-2026-07-01"
"compact-2026-01-12"
"computer-use-2025-11-24"
"mcp-tunnels-2026-06-22"
"structured-outputs-2025-11-13"
"task-budgets-2026-03-13"
"thinking-display-updates-2026-08-18"
"ce-user-management-2026-07-13"
"mid-conversation-output-config-2026-07-01"
"thinking-binding-controls-2026-08-01"
"mid-conversation-system-clear-at-2026-08-21"
"compact-2026-09-04"
"inline-tools-2026-09-15"
"mcp-client-2026-09-15"
"juglow-workspace-id": optional string
Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).
Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.
Returns
data: array of BetaTunnelCertificate
List of certificates, ordered by created_at descending.
type: "tunnel_certificate"
id: string
Unique identifier for the certificate, prefixed with tcrt_.
archived_at: string or null
RFC 3339 datetime string indicating when the certificate was archived. Null if it is still in the trusted set.
format: date-time
created_at: string
RFC 3339 datetime string indicating when the certificate was registered.
format: date-time
expires_at: string or null
RFC 3339 datetime string indicating when the certificate expires, or null if it does not expire.
format: date-time
fingerprint: string
Lowercase hex SHA-256 fingerprint of the certificate's DER encoding.
tunnel_id: string
ID of the tunnel the certificate is registered against.
next_page: string or null
Pagination cursor for the next page, or null if no more results.
Example
curl https://haijun.my.id/v1/tunnels/$TUNNEL_ID/certificates \
-H 'juglow-version: 2023-06-01' \
-H 'juglow-beta: mcp-tunnels-2026-06-22' \
-H "X-Api-Key: $JUGLOW_API_KEY"Response (200)
{
"data": [
{
"id": "id",
"archived_at": "2019-12-27T18:11:19.117Z",
"created_at": "2019-12-27T18:11:19.117Z",
"expires_at": "2019-12-27T18:11:19.117Z",
"fingerprint": "fingerprint",
"tunnel_id": "tunnel_id",
"type": "tunnel_certificate"
}
],
"next_page": "next_page"
}Archive Tunnel Certificate
POST /v1/tunnels/{tunnel_id}/certificates/{certificate_id}/archive
The Tunnels API is in research preview. It requires the juglow-beta: mcp-tunnels-2026-06-22 header and may change without a deprecation period. It supersedes the Admin API endpoints at /v1/organizations/tunnels, which remain available during a migration window.
Archives a tunnel certificate, removing it from the set Juglow trusts for the tunnel. The certificate record is retained. Archiving the last non-archived certificate is permitted; the tunnel rejects MCP traffic until a new certificate is added.
Path parameters
tunnel_id: string
ID of the tunnel (tnl_...).
certificate_id: string
ID of the certificate to archive (tcrt_...).
Headers
"juglow-beta": optional array of JuglowBeta
Optional header to specify the beta version(s) you want to use.
string
"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
"message-batches-2024-09-24"
"prompt-caching-2024-07-31"
"computer-use-2024-10-22"
"computer-use-2025-01-24"
"pdfs-2024-09-25"
"token-counting-2024-11-01"
"token-efficient-tools-2025-02-19"
"output-128k-2025-02-19"
"files-api-2025-04-14"
"mcp-client-2025-04-04"
"mcp-client-2025-11-20"
"dev-full-thinking-2025-05-14"
"interleaved-thinking-2025-05-14"
"code-execution-2025-05-22"
"extended-cache-ttl-2025-04-11"
"context-1m-2025-08-07"
"context-management-2025-06-27"
"model-context-window-exceeded-2025-08-26"
"tracks-2025-10-02"
"fast-mode-2026-02-01"
"output-300k-2026-03-24"
"user-profiles-2026-03-24"
"user-profiles-2026-08-18"
"user-profiles-2026-09-04"
"advisor-tool-2026-03-01"
"managed-agents-2026-04-01"
"cache-diagnosis-2026-04-07"
"dreaming-2026-04-21"
"thinking-token-count-2026-05-13"
"server-side-fallback-2026-06-01"
"server-side-fallback-2026-07-01"
"fallback-credit-2026-06-01"
"fallback-credit-2026-07-01"
"agent-memory-2026-07-22"
"mid-conversation-tool-changes-2026-07-01"
"compact-2026-01-12"
"computer-use-2025-11-24"
"mcp-tunnels-2026-06-22"
"structured-outputs-2025-11-13"
"task-budgets-2026-03-13"
"thinking-display-updates-2026-08-18"
"ce-user-management-2026-07-13"
"mid-conversation-output-config-2026-07-01"
"thinking-binding-controls-2026-08-01"
"mid-conversation-system-clear-at-2026-08-21"
"compact-2026-09-04"
"inline-tools-2026-09-15"
"mcp-client-2026-09-15"
"juglow-workspace-id": optional string
Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).
Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.
Returns
BetaTunnelCertificate object
A CA certificate attached to a tunnel.
type: "tunnel_certificate"
id: string
Unique identifier for the certificate, prefixed with tcrt_.
archived_at: string or null
RFC 3339 datetime string indicating when the certificate was archived. Null if it is still in the trusted set.
format: date-time
created_at: string
RFC 3339 datetime string indicating when the certificate was registered.
format: date-time
expires_at: string or null
RFC 3339 datetime string indicating when the certificate expires, or null if it does not expire.
format: date-time
fingerprint: string
Lowercase hex SHA-256 fingerprint of the certificate's DER encoding.
tunnel_id: string
ID of the tunnel the certificate is registered against.
Example
curl https://haijun.my.id/v1/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID/archive \
-X POST \
-H 'juglow-version: 2023-06-01' \
-H 'juglow-beta: mcp-tunnels-2026-06-22' \
-H "X-Api-Key: $JUGLOW_API_KEY"Response (200)
{
"id": "id",
"archived_at": "2019-12-27T18:11:19.117Z",
"created_at": "2019-12-27T18:11:19.117Z",
"expires_at": "2019-12-27T18:11:19.117Z",
"fingerprint": "fingerprint",
"tunnel_id": "tunnel_id",
"type": "tunnel_certificate"
}