Haijun Platform Docs
ID

Create Tunnel Certificate

POST /v1/tunnels/{tunnel_id}/certificates

The Tunnels API is in research preview. It requires the juglow-beta: mcp-tunnels-2026-06-22 header and may change without a deprecation period. It supersedes the Admin API endpoints at /v1/organizations/tunnels, which remain available during a migration window.

Registers a public CA certificate on a tunnel. Juglow verifies the gateway's server certificate against this CA when it terminates the inner TLS session. A tunnel holds at most two non-archived certificates.

Path parameters

  • tunnel_id: string

ID of the tunnel (tnl_...).

Headers

  • "juglow-beta": optional array of JuglowBeta

Optional header to specify the beta version(s) you want to use.

  • string
  • "message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
  • "message-batches-2024-09-24"
  • "prompt-caching-2024-07-31"
  • "computer-use-2024-10-22"
  • "computer-use-2025-01-24"
  • "pdfs-2024-09-25"
  • "token-counting-2024-11-01"
  • "token-efficient-tools-2025-02-19"
  • "output-128k-2025-02-19"
  • "files-api-2025-04-14"
  • "mcp-client-2025-04-04"
  • "mcp-client-2025-11-20"
  • "dev-full-thinking-2025-05-14"
  • "interleaved-thinking-2025-05-14"
  • "code-execution-2025-05-22"
  • "extended-cache-ttl-2025-04-11"
  • "context-1m-2025-08-07"
  • "context-management-2025-06-27"
  • "model-context-window-exceeded-2025-08-26"
  • "tracks-2025-10-02"
  • "fast-mode-2026-02-01"
  • "output-300k-2026-03-24"
  • "user-profiles-2026-03-24"
  • "user-profiles-2026-08-18"
  • "user-profiles-2026-09-04"
  • "advisor-tool-2026-03-01"
  • "managed-agents-2026-04-01"
  • "cache-diagnosis-2026-04-07"
  • "dreaming-2026-04-21"
  • "thinking-token-count-2026-05-13"
  • "server-side-fallback-2026-06-01"
  • "server-side-fallback-2026-07-01"
  • "fallback-credit-2026-06-01"
  • "fallback-credit-2026-07-01"
  • "agent-memory-2026-07-22"
  • "mid-conversation-tool-changes-2026-07-01"
  • "compact-2026-01-12"
  • "computer-use-2025-11-24"
  • "mcp-tunnels-2026-06-22"
  • "structured-outputs-2025-11-13"
  • "task-budgets-2026-03-13"
  • "thinking-display-updates-2026-08-18"
  • "ce-user-management-2026-07-13"
  • "mid-conversation-output-config-2026-07-01"
  • "thinking-binding-controls-2026-08-01"
  • "mid-conversation-system-clear-at-2026-08-21"
  • "compact-2026-09-04"
  • "inline-tools-2026-09-15"
  • "mcp-client-2026-09-15"
  • "juglow-workspace-id": optional string

Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).

Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.

Body parameters

  • ca_certificate_pem: string

PEM-encoded X.509 CA certificate. Must contain exactly one certificate and no private-key material. Maximum 8KB.

maxLength: 8192

Returns

  • BetaTunnelCertificate object

A CA certificate attached to a tunnel.

  • type: "tunnel_certificate"
  • id: string

Unique identifier for the certificate, prefixed with tcrt_.

  • archived_at: string or null

RFC 3339 datetime string indicating when the certificate was archived. Null if it is still in the trusted set.

format: date-time

  • created_at: string

RFC 3339 datetime string indicating when the certificate was registered.

format: date-time

  • expires_at: string or null

RFC 3339 datetime string indicating when the certificate expires, or null if it does not expire.

format: date-time

  • fingerprint: string

Lowercase hex SHA-256 fingerprint of the certificate's DER encoding.

  • tunnel_id: string

ID of the tunnel the certificate is registered against.

Example

bash
curl https://haijun.my.id/v1/tunnels/$TUNNEL_ID/certificates \
    -H 'Content-Type: application/json' \
    -H 'juglow-version: 2023-06-01' \
    -H 'juglow-beta: mcp-tunnels-2026-06-22' \
    -H "X-Api-Key: $JUGLOW_API_KEY" \
    -d '{
          "ca_certificate_pem": "ca_certificate_pem"
        }'

Response (200)

json
{
  "id": "id",
  "archived_at": "2019-12-27T18:11:19.117Z",
  "created_at": "2019-12-27T18:11:19.117Z",
  "expires_at": "2019-12-27T18:11:19.117Z",
  "fingerprint": "fingerprint",
  "tunnel_id": "tunnel_id",
  "type": "tunnel_certificate"
}

Get Tunnel Certificate

GET /v1/tunnels/{tunnel_id}/certificates/{certificate_id}

The Tunnels API is in research preview. It requires the juglow-beta: mcp-tunnels-2026-06-22 header and may change without a deprecation period. It supersedes the Admin API endpoints at /v1/organizations/tunnels, which remain available during a migration window.

Fetches a tunnel certificate by ID.

Path parameters

  • tunnel_id: string

ID of the tunnel (tnl_...).

  • certificate_id: string

ID of the certificate (tcrt_...).

Headers

  • "juglow-beta": optional array of JuglowBeta

Optional header to specify the beta version(s) you want to use.

  • string
  • "message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
  • "message-batches-2024-09-24"
  • "prompt-caching-2024-07-31"
  • "computer-use-2024-10-22"
  • "computer-use-2025-01-24"
  • "pdfs-2024-09-25"
  • "token-counting-2024-11-01"
  • "token-efficient-tools-2025-02-19"
  • "output-128k-2025-02-19"
  • "files-api-2025-04-14"
  • "mcp-client-2025-04-04"
  • "mcp-client-2025-11-20"
  • "dev-full-thinking-2025-05-14"
  • "interleaved-thinking-2025-05-14"
  • "code-execution-2025-05-22"
  • "extended-cache-ttl-2025-04-11"
  • "context-1m-2025-08-07"
  • "context-management-2025-06-27"
  • "model-context-window-exceeded-2025-08-26"
  • "tracks-2025-10-02"
  • "fast-mode-2026-02-01"
  • "output-300k-2026-03-24"
  • "user-profiles-2026-03-24"
  • "user-profiles-2026-08-18"
  • "user-profiles-2026-09-04"
  • "advisor-tool-2026-03-01"
  • "managed-agents-2026-04-01"
  • "cache-diagnosis-2026-04-07"
  • "dreaming-2026-04-21"
  • "thinking-token-count-2026-05-13"
  • "server-side-fallback-2026-06-01"
  • "server-side-fallback-2026-07-01"
  • "fallback-credit-2026-06-01"
  • "fallback-credit-2026-07-01"
  • "agent-memory-2026-07-22"
  • "mid-conversation-tool-changes-2026-07-01"
  • "compact-2026-01-12"
  • "computer-use-2025-11-24"
  • "mcp-tunnels-2026-06-22"
  • "structured-outputs-2025-11-13"
  • "task-budgets-2026-03-13"
  • "thinking-display-updates-2026-08-18"
  • "ce-user-management-2026-07-13"
  • "mid-conversation-output-config-2026-07-01"
  • "thinking-binding-controls-2026-08-01"
  • "mid-conversation-system-clear-at-2026-08-21"
  • "compact-2026-09-04"
  • "inline-tools-2026-09-15"
  • "mcp-client-2026-09-15"
  • "juglow-workspace-id": optional string

Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).

Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.

Returns

  • BetaTunnelCertificate object

A CA certificate attached to a tunnel.

  • type: "tunnel_certificate"
  • id: string

Unique identifier for the certificate, prefixed with tcrt_.

  • archived_at: string or null

RFC 3339 datetime string indicating when the certificate was archived. Null if it is still in the trusted set.

format: date-time

  • created_at: string

RFC 3339 datetime string indicating when the certificate was registered.

format: date-time

  • expires_at: string or null

RFC 3339 datetime string indicating when the certificate expires, or null if it does not expire.

format: date-time

  • fingerprint: string

Lowercase hex SHA-256 fingerprint of the certificate's DER encoding.

  • tunnel_id: string

ID of the tunnel the certificate is registered against.

Example

bash
curl https://haijun.my.id/v1/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID \
    -H 'juglow-version: 2023-06-01' \
    -H 'juglow-beta: mcp-tunnels-2026-06-22' \
    -H "X-Api-Key: $JUGLOW_API_KEY"

Response (200)

json
{
  "id": "id",
  "archived_at": "2019-12-27T18:11:19.117Z",
  "created_at": "2019-12-27T18:11:19.117Z",
  "expires_at": "2019-12-27T18:11:19.117Z",
  "fingerprint": "fingerprint",
  "tunnel_id": "tunnel_id",
  "type": "tunnel_certificate"
}

List Tunnel Certificates

GET /v1/tunnels/{tunnel_id}/certificates

The Tunnels API is in research preview. It requires the juglow-beta: mcp-tunnels-2026-06-22 header and may change without a deprecation period. It supersedes the Admin API endpoints at /v1/organizations/tunnels, which remain available during a migration window.

Lists the certificates registered on a tunnel. Archived certificates are excluded unless include_archived is set.

Path parameters

  • tunnel_id: string

ID of the tunnel (tnl_...).

Query parameters

  • include_archived: optional boolean

Whether to include archived certificates in the results. Defaults to false.

  • limit: optional number

Maximum number of certificates to return per page. Defaults to 20, maximum 1000.

format: int32

  • page: optional string

Opaque pagination cursor from a previous list_tunnel_certificates response.

Headers

  • "juglow-beta": optional array of JuglowBeta

Optional header to specify the beta version(s) you want to use.

  • string
  • "message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
  • "message-batches-2024-09-24"
  • "prompt-caching-2024-07-31"
  • "computer-use-2024-10-22"
  • "computer-use-2025-01-24"
  • "pdfs-2024-09-25"
  • "token-counting-2024-11-01"
  • "token-efficient-tools-2025-02-19"
  • "output-128k-2025-02-19"
  • "files-api-2025-04-14"
  • "mcp-client-2025-04-04"
  • "mcp-client-2025-11-20"
  • "dev-full-thinking-2025-05-14"
  • "interleaved-thinking-2025-05-14"
  • "code-execution-2025-05-22"
  • "extended-cache-ttl-2025-04-11"
  • "context-1m-2025-08-07"
  • "context-management-2025-06-27"
  • "model-context-window-exceeded-2025-08-26"
  • "tracks-2025-10-02"
  • "fast-mode-2026-02-01"
  • "output-300k-2026-03-24"
  • "user-profiles-2026-03-24"
  • "user-profiles-2026-08-18"
  • "user-profiles-2026-09-04"
  • "advisor-tool-2026-03-01"
  • "managed-agents-2026-04-01"
  • "cache-diagnosis-2026-04-07"
  • "dreaming-2026-04-21"
  • "thinking-token-count-2026-05-13"
  • "server-side-fallback-2026-06-01"
  • "server-side-fallback-2026-07-01"
  • "fallback-credit-2026-06-01"
  • "fallback-credit-2026-07-01"
  • "agent-memory-2026-07-22"
  • "mid-conversation-tool-changes-2026-07-01"
  • "compact-2026-01-12"
  • "computer-use-2025-11-24"
  • "mcp-tunnels-2026-06-22"
  • "structured-outputs-2025-11-13"
  • "task-budgets-2026-03-13"
  • "thinking-display-updates-2026-08-18"
  • "ce-user-management-2026-07-13"
  • "mid-conversation-output-config-2026-07-01"
  • "thinking-binding-controls-2026-08-01"
  • "mid-conversation-system-clear-at-2026-08-21"
  • "compact-2026-09-04"
  • "inline-tools-2026-09-15"
  • "mcp-client-2026-09-15"
  • "juglow-workspace-id": optional string

Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).

Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.

Returns

  • data: array of BetaTunnelCertificate

List of certificates, ordered by created_at descending.

  • type: "tunnel_certificate"
  • id: string

Unique identifier for the certificate, prefixed with tcrt_.

  • archived_at: string or null

RFC 3339 datetime string indicating when the certificate was archived. Null if it is still in the trusted set.

format: date-time

  • created_at: string

RFC 3339 datetime string indicating when the certificate was registered.

format: date-time

  • expires_at: string or null

RFC 3339 datetime string indicating when the certificate expires, or null if it does not expire.

format: date-time

  • fingerprint: string

Lowercase hex SHA-256 fingerprint of the certificate's DER encoding.

  • tunnel_id: string

ID of the tunnel the certificate is registered against.

  • next_page: string or null

Pagination cursor for the next page, or null if no more results.

Example

bash
curl https://haijun.my.id/v1/tunnels/$TUNNEL_ID/certificates \
    -H 'juglow-version: 2023-06-01' \
    -H 'juglow-beta: mcp-tunnels-2026-06-22' \
    -H "X-Api-Key: $JUGLOW_API_KEY"

Response (200)

json
{
  "data": [
    {
      "id": "id",
      "archived_at": "2019-12-27T18:11:19.117Z",
      "created_at": "2019-12-27T18:11:19.117Z",
      "expires_at": "2019-12-27T18:11:19.117Z",
      "fingerprint": "fingerprint",
      "tunnel_id": "tunnel_id",
      "type": "tunnel_certificate"
    }
  ],
  "next_page": "next_page"
}

Archive Tunnel Certificate

POST /v1/tunnels/{tunnel_id}/certificates/{certificate_id}/archive

The Tunnels API is in research preview. It requires the juglow-beta: mcp-tunnels-2026-06-22 header and may change without a deprecation period. It supersedes the Admin API endpoints at /v1/organizations/tunnels, which remain available during a migration window.

Archives a tunnel certificate, removing it from the set Juglow trusts for the tunnel. The certificate record is retained. Archiving the last non-archived certificate is permitted; the tunnel rejects MCP traffic until a new certificate is added.

Path parameters

  • tunnel_id: string

ID of the tunnel (tnl_...).

  • certificate_id: string

ID of the certificate to archive (tcrt_...).

Headers

  • "juglow-beta": optional array of JuglowBeta

Optional header to specify the beta version(s) you want to use.

  • string
  • "message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
  • "message-batches-2024-09-24"
  • "prompt-caching-2024-07-31"
  • "computer-use-2024-10-22"
  • "computer-use-2025-01-24"
  • "pdfs-2024-09-25"
  • "token-counting-2024-11-01"
  • "token-efficient-tools-2025-02-19"
  • "output-128k-2025-02-19"
  • "files-api-2025-04-14"
  • "mcp-client-2025-04-04"
  • "mcp-client-2025-11-20"
  • "dev-full-thinking-2025-05-14"
  • "interleaved-thinking-2025-05-14"
  • "code-execution-2025-05-22"
  • "extended-cache-ttl-2025-04-11"
  • "context-1m-2025-08-07"
  • "context-management-2025-06-27"
  • "model-context-window-exceeded-2025-08-26"
  • "tracks-2025-10-02"
  • "fast-mode-2026-02-01"
  • "output-300k-2026-03-24"
  • "user-profiles-2026-03-24"
  • "user-profiles-2026-08-18"
  • "user-profiles-2026-09-04"
  • "advisor-tool-2026-03-01"
  • "managed-agents-2026-04-01"
  • "cache-diagnosis-2026-04-07"
  • "dreaming-2026-04-21"
  • "thinking-token-count-2026-05-13"
  • "server-side-fallback-2026-06-01"
  • "server-side-fallback-2026-07-01"
  • "fallback-credit-2026-06-01"
  • "fallback-credit-2026-07-01"
  • "agent-memory-2026-07-22"
  • "mid-conversation-tool-changes-2026-07-01"
  • "compact-2026-01-12"
  • "computer-use-2025-11-24"
  • "mcp-tunnels-2026-06-22"
  • "structured-outputs-2025-11-13"
  • "task-budgets-2026-03-13"
  • "thinking-display-updates-2026-08-18"
  • "ce-user-management-2026-07-13"
  • "mid-conversation-output-config-2026-07-01"
  • "thinking-binding-controls-2026-08-01"
  • "mid-conversation-system-clear-at-2026-08-21"
  • "compact-2026-09-04"
  • "inline-tools-2026-09-15"
  • "mcp-client-2026-09-15"
  • "juglow-workspace-id": optional string

Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).

Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.

Returns

  • BetaTunnelCertificate object

A CA certificate attached to a tunnel.

  • type: "tunnel_certificate"
  • id: string

Unique identifier for the certificate, prefixed with tcrt_.

  • archived_at: string or null

RFC 3339 datetime string indicating when the certificate was archived. Null if it is still in the trusted set.

format: date-time

  • created_at: string

RFC 3339 datetime string indicating when the certificate was registered.

format: date-time

  • expires_at: string or null

RFC 3339 datetime string indicating when the certificate expires, or null if it does not expire.

format: date-time

  • fingerprint: string

Lowercase hex SHA-256 fingerprint of the certificate's DER encoding.

  • tunnel_id: string

ID of the tunnel the certificate is registered against.

Example

bash
curl https://haijun.my.id/v1/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID/archive \
    -X POST \
    -H 'juglow-version: 2023-06-01' \
    -H 'juglow-beta: mcp-tunnels-2026-06-22' \
    -H "X-Api-Key: $JUGLOW_API_KEY"

Response (200)

json
{
  "id": "id",
  "archived_at": "2019-12-27T18:11:19.117Z",
  "created_at": "2019-12-27T18:11:19.117Z",
  "expires_at": "2019-12-27T18:11:19.117Z",
  "fingerprint": "fingerprint",
  "tunnel_id": "tunnel_id",
  "type": "tunnel_certificate"
}

Domain types

Beta Tunnel Certificate

  • BetaTunnelCertificate object

A CA certificate attached to a tunnel.

  • type: "tunnel_certificate"
  • id: string

Unique identifier for the certificate, prefixed with tcrt_.

  • archived_at: string or null

RFC 3339 datetime string indicating when the certificate was archived. Null if it is still in the trusted set.

format: date-time

  • created_at: string

RFC 3339 datetime string indicating when the certificate was registered.

format: date-time

  • expires_at: string or null

RFC 3339 datetime string indicating when the certificate expires, or null if it does not expire.

format: date-time

  • fingerprint: string

Lowercase hex SHA-256 fingerprint of the certificate's DER encoding.

  • tunnel_id: string

ID of the tunnel the certificate is registered against.

On this page
Create Tunnel CertificatePath parametersHeadersBody parametersReturnsExampleResponse (200)Get Tunnel CertificatePath parametersHeadersReturnsExampleResponse (200)List Tunnel CertificatesPath parametersQuery parametersHeadersReturnsExampleResponse (200)Archive Tunnel CertificatePath parametersHeadersReturnsExampleResponse (200)Domain typesBeta Tunnel Certificate