Create a Tunnels API key
The setup component that runs alongside the tunnel stack needs a short-lived credential to create the tunnel, register its certificate authority (CA) certificate with Anthropic, and fetch the tunnel token. In claude.ai that credential is a Tunnels API key.Open Organization settings > Tunnels
Create a key
Copy the key
Deploy the tunnel stack
The deployment steps on this page are reference deployments. You are responsible for adapting them to your organization’s security requirements. For the full set of proxy options, certificate requirements, and hardening guidance, see the MCP tunnels reference and MCP tunnels security pages in the Claude Platform docs. Those pages describe the Claude Console flow, which authenticates the setup component differently. For a claude.ai organization, follow the authentication steps on this page. Choose Helm if you run Kubernetes. The chart provisions the tunnel, stores the credentials in a Secret, and renews the server certificate automatically. Choose Docker Compose for a single host or a VM, where you run the setup component and certificate renewal yourself. Both the Helm and Docker Compose paths need at least one route. A route maps a subdomain of your tunnel domain to the internal URL of an MCP server, in the formscheme://host:port with no path. The examples use docs pointing at http://docs-mcp.example.corp:8080. Replace them with your own servers.
- Helm
- Docker Compose
Fetch the default values
Configure routes
values.yaml and add a routes entry under gateway.config for each MCP server. Leave tunnel.id empty so the setup component creates the tunnel during install.docs.<your-tunnel-domain> and search.<your-tunnel-domain>. If a route targets an address outside the RFC 1918 private ranges (some managed Kubernetes distributions allocate Service IPs elsewhere), add the range under gateway.config.upstream.allowed_ips as described in Troubleshooting.Review the rendered manifests
Install
helm install blocks until the tunnel is created, the CA is registered, and the credentials are stored in the mcp-tunnel Secret. If the install fails with a hook error, see Troubleshooting.Read the tunnel domain
abc123.tunnel.anthropic.com.networkPolicy.enabled: true in values.yaml and list your MCP servers under networkPolicy.mcpServers. The policy already allows cloudflared to reach the tunnel edge. Your cluster’s network plugin must support NetworkPolicy.For later configuration changes such as routes or replica count, edit values.yaml and run helm upgrade with the same --version and -f values.yaml, without the API key. Keep a complete values.yaml rather than relying on --reuse-values, because Helm’s deep merge can silently keep a route you deleted.Verify the connection
Check the logs on your side first. cloudflared logs fourRegistered tunnel connection lines when it has reached the tunnel edge, and the proxy logs one route configured line per route.
Add tunneled servers as connectors
Each route becomes a custom connector for your organization. The connector URL is the route’s tunnel hostname plus the path your MCP server serves. Many servers serve at/mcp, and the proxy forwards the path unchanged.
Open organization connectors
Add a custom connector
Enter the tunnel URL
https://docs.abc123.tunnel.anthropic.com/mcp.Configure authentication
Add the connector
Add more servers later
Adding another MCP server later takes a new route and a new connector. No certificate or cloudflared changes are needed, because the server certificate covers every subdomain of your tunnel domain.Add a route
Apply the change
Register the connector
Rotate credentials
An MCP tunnel involves three credentials: the Tunnels API key, the tunnel token, and the server certificate. Each rotates differently.Replace the Tunnels API key
The Tunnels API key is used only while the setup component runs. Revoke it after every use and create a new one in Organization settings > Tunnels > Tunnels API when you next need to run setup.Rotate the tunnel token
The tunnel token authenticates cloudflared’s outbound connection. Rotate it on your regular schedule and immediately if you suspect exposure. Rotation does not sever connections that are already established, so you can rotate, restart cloudflared with the new value, and let the old connections drain.- Helm
- Docker Compose
Increment the token version
tunnel.tokenVersion in values.yaml.Create a Tunnels API key
Upgrade
Renew the server certificate
The server certificate the proxy presents is valid for 90 days, and you are responsible for renewing it before it expires. Renewal is local. It signs a new certificate with the CA already stored in your deployment, makes no API calls, and needs no API key. The proxy reloads the certificate file automatically, so no restart is required.- Helm
- Docker Compose
Remove a tunnel
Decommission a tunnel when you no longer need it, or as the first steps of responding to a suspected compromise. Archiving a tunnel invalidates its token, detaches its domain, and is permanent.Record the tunnel ID
Stop the tunnel stack
docker compose down --timeout 0 to sever the connection immediately.Remove the connectors
Archive the tunnel
Delete the stored credentials
Next steps
- Authenticate to MCP servers behind a tunnel: make OAuth sign-in work when your authorization server is inside your network
- Troubleshoot MCP tunnels: diagnose connection, certificate, routing, and sign-in failures
- MCP tunnels reference: proxy configuration fields, certificate requirements, and the setup component