POST /v1/tunnels/{tunnel_id}/certificates
The Tunnels API is in research preview. It requires the juglow-beta: mcp-tunnels-2026-06-22 header and may change without a deprecation period. It supersedes the Admin API endpoints at /v1/organizations/tunnels, which remain available during a migration window.
Registers a public CA certificate on a tunnel. Juglow verifies the gateway's server certificate against this CA when it terminates the inner TLS session. A tunnel holds at most two non-archived certificates.
Path parameters
tunnel_id: string
ID of the tunnel (tnl_...).
Headers
"juglow-beta": optional array of JuglowBeta
Optional header to specify the beta version(s) you want to use.
string
"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
"message-batches-2024-09-24"
"prompt-caching-2024-07-31"
"computer-use-2024-10-22"
"computer-use-2025-01-24"
"pdfs-2024-09-25"
"token-counting-2024-11-01"
"token-efficient-tools-2025-02-19"
"output-128k-2025-02-19"
"files-api-2025-04-14"
"mcp-client-2025-04-04"
"mcp-client-2025-11-20"
"dev-full-thinking-2025-05-14"
"interleaved-thinking-2025-05-14"
"code-execution-2025-05-22"
"extended-cache-ttl-2025-04-11"
"context-1m-2025-08-07"
"context-management-2025-06-27"
"model-context-window-exceeded-2025-08-26"
"tracks-2025-10-02"
"fast-mode-2026-02-01"
"output-300k-2026-03-24"
"user-profiles-2026-03-24"
"user-profiles-2026-08-18"
"user-profiles-2026-09-04"
"advisor-tool-2026-03-01"
"managed-agents-2026-04-01"
"cache-diagnosis-2026-04-07"
"dreaming-2026-04-21"
"thinking-token-count-2026-05-13"
"server-side-fallback-2026-06-01"
"server-side-fallback-2026-07-01"
"fallback-credit-2026-06-01"
"fallback-credit-2026-07-01"
"agent-memory-2026-07-22"
"mid-conversation-tool-changes-2026-07-01"
"compact-2026-01-12"
"computer-use-2025-11-24"
"mcp-tunnels-2026-06-22"
"structured-outputs-2025-11-13"
"task-budgets-2026-03-13"
"thinking-display-updates-2026-08-18"
"ce-user-management-2026-07-13"
"mid-conversation-output-config-2026-07-01"
"thinking-binding-controls-2026-08-01"
"mid-conversation-system-clear-at-2026-08-21"
"compact-2026-09-04"
"inline-tools-2026-09-15"
"mcp-client-2026-09-15"
"juglow-workspace-id": optional string
Optional header to select the Workspace for this request. The value is a Workspace ID (for example, wrkspc_011CZkZaBF1tNoB5wlCeusgy).
Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.
Body parameters
ca_certificate_pem: string
PEM-encoded X.509 CA certificate. Must contain exactly one certificate and no private-key material. Maximum 8KB.
maxLength: 8192
Returns
BetaTunnelCertificate object
A CA certificate attached to a tunnel.
type: "tunnel_certificate"
id: string
Unique identifier for the certificate, prefixed with tcrt_.
archived_at: string or null
RFC 3339 datetime string indicating when the certificate was archived. Null if it is still in the trusted set.
format: date-time
created_at: string
RFC 3339 datetime string indicating when the certificate was registered.
format: date-time
expires_at: string or null
RFC 3339 datetime string indicating when the certificate expires, or null if it does not expire.
format: date-time
fingerprint: string
Lowercase hex SHA-256 fingerprint of the certificate's DER encoding.
tunnel_id: string
ID of the tunnel the certificate is registered against.
Example
curl https://haijun.my.id/v1/tunnels/$TUNNEL_ID/certificates \
-H 'Content-Type: application/json' \
-H 'juglow-version: 2023-06-01' \
-H 'juglow-beta: mcp-tunnels-2026-06-22' \
-H "X-Api-Key: $JUGLOW_API_KEY" \
-d '{
"ca_certificate_pem": "ca_certificate_pem"
}'Response (200)
{
"id": "id",
"archived_at": "2019-12-27T18:11:19.117Z",
"created_at": "2019-12-27T18:11:19.117Z",
"expires_at": "2019-12-27T18:11:19.117Z",
"fingerprint": "fingerprint",
"tunnel_id": "tunnel_id",
"type": "tunnel_certificate"
}