Cisco Umbrella Organization Tunnel API

The Organization Tunnel API from Cisco Umbrella — 4 operation(s) for organization tunnel.

Operations 7

GET /tunnels List Tunnels #
POST /tunnels Create Tunnel #
GET /tunnels/{id} Get Tunnel #
PUT /tunnels/{id} Update Tunnel #
DELETE /tunnels/{id} Delete Tunnel #
POST /tunnels/{id}/keys Update and Rotate Tunnel Credentials #
GET /tunnels/{id}/policies List Policies for Tunnel #

Documentation

📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-admin-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-admin-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-managed-providers-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-managed-providers-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-providers-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-providers-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-s3-key-rotation-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-s3-key-rotation-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-users-roles-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-users-roles-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-authentication/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-authentication/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/cloudlock-api-getting-started/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/cloudlock-api-getting-started/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-internal-domains-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-internal-domains-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-internal-networks-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-internal-networks-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-network-devices-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-network-devices-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-network-tunnels-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-network-tunnels-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-networks-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-networks-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-deployment-policies-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-deployment-policies-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-roaming-computers-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-roaming-computers-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-sites-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-sites-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-swg-devices-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-swg-devices-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-tagging-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-tagging-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-virtual-appliances-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-virtual-appliances-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-investigate-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-investigate-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-application-lists-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-application-lists-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-destination-lists-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-destination-lists-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-api-usage-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-api-usage-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-app-discovery-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-app-discovery-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-reports-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-reports-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-reporting-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-reporting-overview/

Specifications

Other Resources

🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/key-admin.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/managed-providers.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/providers.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/s3-key-rotation.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/service-providers-console.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/users-roles.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/auth/token.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/cloudlock/cloudlock.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/internal-domains.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/internal-networks.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/network-devices.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/network-tunnels.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/networks.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/policies.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/roaming-computers.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/sites.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/swg-devices.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/tagging.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/virtual-appliances.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/investigate/investigate.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/policies/application-lists-internet-umb.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/policies/destination-lists.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/api-usage.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/app-discovery.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/provider-consoles.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/reporting.yaml

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/cisco-umbrella-organization-tunnel-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

cisco-umbrella-organization-tunnel-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Cisco Umbrella Network Tunnels Organization Tunnel API
  description: Manage the network tunnels in the organization.
  version: 2.0.0
  contact:
    name: Cloud Security Developer Community
  x-provenance:
    method: harvested
    authored_by: Cisco Umbrella
    harvested_by: API Evangelist
    harvested_on: '2026-08-19'
    first_party: true
    provider_published: true
    source_host: pubhub.devnetcloud.com
    note: 26 first-party OpenAPI 3.0 documents (256 operations) listed by Cisco's own docs-nav config and fetched anonymously. Byte-identity reconfirmed 2026-08-19 by SHA-256 against the live source.
  x-evidence:
  - type: source
    url: https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/umbrella-config.json
  - type: source
    url: https://developer.cisco.com/docs/cloud-security/
servers:
- url: https://api.umbrella.com/{basePath}
  variables:
    basePath:
      default: deployments/v2
security:
- oauthFlow: []
tags:
- name: Organization Tunnel
paths:
  /tunnels:
    get:
      summary: List Tunnels
      operationId: listTunnels
      description: List the tunnels for an organization.
      security:
      - oauthFlow:
        - deployments.tunnels:read
      tags:
      - Organization Tunnel
      parameters:
      - in: query
        name: includeState
        schema:
          default: false
          type: boolean
        description: Specify whether to include the tunnel state information in the response.
        required: false
      - in: query
        name: limit
        description: The number of items to return in the collection. If not set, all tunnels are returned.
        required: false
        schema:
          type: integer
      - in: query
        name: startKey
        description: 'Specify where to start reading in the tunnel collection (`startKey` correlates to the first tunnel to return).

          If the `startKey` query parameter is not included in the API request, Umbrella reads the collection from the first available tunnel.

          When the API request includes the `limit` query parameter and you have more tunnels to read,

          Umbrella returns the value of `startKey` for the next tunnel in the hypermedia Link header.'
        required: false
        schema:
          type: string
      - in: query
        name: filters
        description: "Filters the tunnel list by tunnel name, device type, service type, status, data center, or site origin ID.\nFor example:\n```\n{\n  \"name\": \"test\",\n  \"deviceType\": \"ISR\",\n  \"serviceType\": \"SIG\",\n  \"status\": \"UP\",\n  \"dataCenter\": \"pao1.edc\",\n  \"siteOriginId\": 123\n}\n```"
        required: false
        schema:
          type: string
      responses:
        '200':
          description: OKs
          headers:
            Content-Type:
              $ref: '#/components/headers/Content-Type'
            Date:
              $ref: '#/components/headers/Date'
            Total-Item-Count:
              schema:
                type: string
              description: The total number of active, inactive, and unestablished tunnels in the organization.
              example: '500'
            Total-Distinct-DC-Count:
              schema:
                type: string
              description: The number of distinct data centers in the organization.
              example: '2'
            Total-Active-Item-Count:
              schema:
                type: string
              description: The total number of active tunnels in the organization.
              example: '5'
            Total-Inactive-Item-Count:
              schema:
                type: string
              description: The total number of inactive tunnels in the organization.
              example: '10'
            Link:
              schema:
                type: string
              description: 'The hypermedia links are formatted as a string. Use to provide parameters for pagination.

                Only available if request limits the number of tunnels returned.

                The link is a relative path. The `rel` value is always `next` (pagination moves forward).'
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/TunnelResourceObjectWithState'
              example:
              - id: 1122321
                uri: /tunnels/1122321
                name: Site01Tunnel
                siteOriginId: 123456
                client:
                  deviceType: ASA
                  authentication:
                    type: PSK
                    parameters:
                      id: admin@2561066-237952254-umbrella.com
                      modifiedAt: '2018-06-13T16:07:07.222Z'
                transport:
                  protocol: IPSec
                serviceType: SIG
                networkCIDRs:
                - 123.111.222.25/24
                - 111.222.39.1/32
                meta: {}
                createdAt: '2018-06-13T16:07:07.222Z'
                modifiedAt: '2018-06-13T16:07:07.222Z'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '500':
          $ref: '#/components/responses/ServerError'
    post:
      summary: Create Tunnel
      operationId: addTunnel
      description: Add a new tunnel to the organization.
      security:
      - oauthFlow:
        - deployments.tunnels:write
      tags:
      - Organization Tunnel
      requestBody:
        description: The tunnel to create.
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                name:
                  type: string
                  description: The name of the tunnel.
                siteOriginId:
                  type: integer
                  description: The site origin ID to associate with the tunnel.
                  example: 123456
                deviceType:
                  type: string
                  description: The type of device where the tunnel originates. The default value is `other`.
                  enum:
                  - ASA
                  - FTD
                  - ISR
                  - Meraki MX
                  - Viptela cEdge
                  - Viptela vEdge
                  - other
                serviceType:
                  $ref: '#/components/schemas/serviceType'
                networkCIDRs:
                  $ref: '#/components/schemas/networkCIDRs'
                transport:
                  type: object
                  properties:
                    protocol:
                      description: The tunnel transport protocol. The default tunnel transport protocol is IPSec.
                      type: string
                      enum:
                      - IPSec
                      example: IPSec
                authentication:
                  type: object
                  properties:
                    type:
                      type: string
                      description: The authentication method. The default is pre-shared key (PSK).
                      enum:
                      - PSK
                    parameters:
                      type: object
                      properties:
                        idPrefix:
                          type: string
                          description: 'A human-readable ID for the tunnel, used to generate the ID portion of the Pre-Shared Key.

                            If omitted, the ID is generated and provided in response. Tunnels with a device type of ASA

                            must provide an IP address string for this field. Tunnels with a device type of ''other''

                            may use either an IP address or a human-readable string. PSK IDs are not automatically generated

                            for ASA devices.'
                        secret:
                          type: string
                          description: 'The secret portion of a Pre-Shared Key (PSK).

                            If omitted, a secret is generated and provided in the response.

                            Secrets are a sequence of 16 to 64 characters, and contain at least one upper

                            and lowercase letter, one number, and no special characters.'
              required:
              - name
            example:
              name: Site01Tunnel
              siteOriginId: 123456
              serviceType: SIG
              deviceType: ASA
              networkCIDRs:
              - 123.111.222.25/24
              - 111.222.39.1/32
              transport:
                protocol: IPSec
              authentication:
                type: PSK
                parameters:
                  idPrefix: prefix-string
                  secret: This123Secret
      responses:
        '200':
          description: OK
          headers:
            Content-Type:
              $ref: '#/components/headers/Content-Type'
            Date:
              $ref: '#/components/headers/Date'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TunnelResourceObjectWithSecret'
              example:
                id: 1122321
                uri: /tunnels/1122321
                name: Site01Tunnel
                siteOriginId: 123456
                client:
                  deviceType: ASA
                  authentication:
                    type: PSK
                    parameters:
                      id: admin@2561066-237952254-umbrella.com
                      modifiedAt: '2018-06-13T16:07:07.222Z'
                      secret: This123Secret
                transport:
                  protocol: IPSec
                serviceType: SIG
                networkCIDRs:
                - 123.111.222.25/24
                - 111.222.39.1/32
                meta: {}
                createdAt: '2018-06-13T16:07:07.222Z'
                modifiedAt: '2018-06-13T16:07:07.222Z'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '500':
          $ref: '#/components/responses/ServerError'
  /tunnels/{id}:
    get:
      summary: Get Tunnel
      operationId: getTunnel
      description: Get a specific tunnel.
      security:
      - oauthFlow:
        - deployments.tunnels:read
      parameters:
      - in: path
        name: id
        description: The ID of the tunnel.
        required: true
        schema:
          type: integer
      tags:
      - Organization Tunnel
      responses:
        '200':
          description: OK
          headers:
            Content-Type:
              $ref: '#/components/headers/Content-Type'
            Date:
              $ref: '#/components/headers/Date'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TunnelResourceObject'
              example:
                id: 1122321
                uri: /tunnels/1122321
                name: Site01Tunnel
                siteOriginId: 123456
                client:
                  deviceType: ASA
                  authentication:
                    type: PSK
                    parameters:
                      id: admin@2561066-237952254-umbrella.com
                      modifiedAt: '2018-06-13T16:07:07.222Z'
                transport:
                  protocol: IPSec
                serviceType: SIG
                networkCIDRs:
                - 123.111.222.25/24
                - 111.222.39.1/32
                meta: {}
                createdAt: '2018-06-13T16:07:07.222Z'
                modifiedAt: '2018-06-13T16:07:07.222Z'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '500':
          $ref: '#/components/responses/ServerError'
    put:
      summary: Update Tunnel
      operationId: updateTunnel
      security:
      - oauthFlow:
        - deployments.tunnels:write
      description: 'Update the `name`, `siteOriginId`, `networkCIDRs`, and client `deviceType` properties for a tunnel.

        Updates to read-only attributes are ignored.'
      tags:
      - Organization Tunnel
      parameters:
      - in: path
        name: id
        description: The ID of the tunnel.
        required: true
        schema:
          type: integer
      requestBody:
        description: Provide a tunnel to update.
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                name:
                  type: string
                  description: 'Display name for the tunnel. The tunnel name is required. The name can''t exceed 50 characters

                    in length and can not have any special characters other than spaces and hyphens.'
                  example: Site01Tunnel
                siteOriginId:
                  type: integer
                  description: The site origin ID that is associated with the tunnel.
                  example: 123
                networkCIDRs:
                  $ref: '#/components/schemas/networkCIDRs'
                client:
                  type: object
                  description: The configuration metadata for the client.
                  properties:
                    deviceType:
                      type: string
                      description: The type of device from which the tunnel originates. The default value is `other`.
                      enum:
                      - ASA
                      - FTD
                      - ISR
                      - Meraki MX
                      - Viptela cEdge
                      - Viptela vEdge
                      - other
                      example: ASA
                    authentication:
                      type: object
                      description: The authentication context of the client.
                      properties:
                        type:
                          type: string
                          enum:
                          - PSK
                          example: PSK
                          readOnly: true
                        parameters:
                          type: object
                          properties:
                            id:
                              type: string
                              description: The PSK ID. If an IP address is used as the ID, the IP address is returned.
                              readOnly: true
                              example: admin@2561066-237952254-umbrella.com
                            modifiedAt:
                              $ref: '#/components/schemas/modifiedAt'
              required:
              - name
              - client
            example:
              name: Site01Tunnel
              siteOriginId: 123
              networkCIDRs:
              - 123.111.222.25/24
              - 111.222.39.1/32
              client:
                deviceType: ASA
                authentication:
                  type: PSK
                  parameters:
                    id: admin@2561066-237952254-umbrella.com
                    modifiedAt: '2018-06-13T16:07:07.222Z'
      responses:
        '200':
          description: OK
          headers:
            Content-Type:
              $ref: '#/components/headers/Content-Type'
            Date:
              $ref: '#/components/headers/Date'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TunnelResourceObject'
              example:
                id: 1122321
                uri: /tunnels/1122321
                name: Site01Tunnel
                siteOriginId: 123456
                client:
                  deviceType: ASA
                  authentication:
                    type: PSK
                    parameters:
                      id: admin@2561066-237952254-umbrella.com
                      modifiedAt: '2018-06-13T16:07:07.222Z'
                transport:
                  protocol: IPSec
                serviceType: SIG
                networkCIDRs:
                - 123.111.222.25/24
                - 111.222.39.1/32
                meta: {}
                createdAt: '2018-06-13T16:07:07.222Z'
                modifiedAt: '2018-06-13T16:07:07.222Z'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '500':
          $ref: '#/components/responses/ServerError'
    delete:
      summary: Delete Tunnel
      operationId: deleteTunnel
      description: Delete a tunnel in the organization.
      security:
      - oauthFlow:
        - deployments.tunnels:write
      tags:
      - Organization Tunnel
      parameters:
      - in: path
        name: id
        description: The ID of the tunnel.
        required: true
        schema:
          type: integer
      requestBody:
        description: Provide the tunnel to delete.
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                detachPolicies:
                  type: boolean
                  default: true
                  description: Specifies whether to detach associated policies from the tunnel.
      responses:
        '200':
          description: OK
          headers:
            Content-Type:
              $ref: '#/components/headers/Content-Type'
            Date:
              $ref: '#/components/headers/Date'
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    example: Tunnel deleted successfully
              example:
                message: Tunnel deleted successfully
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          $ref: '#/components/responses/Conflict'
        '500':
          $ref: '#/components/responses/ServerError'
  /tunnels/{id}/keys:
    post:
      summary: Update and Rotate Tunnel Credentials
      description: Update and rotate the tunnel credentials.
      tags:
      - Organization Tunnel
      operationId: updateTunnelCredentials
      security:
      - oauthFlow:
        - deployments.tunnels:write
      parameters:
      - in: path
        name: id
        description: The ID of the tunnel.
        required: true
        schema:
          type: integer
      requestBody:
        description: 'The credentials and options to update and rotate the tunnel. Umbrella stores the

          previous credentials for 24 hours unless stated.'
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                deprecateCurrentKeys:
                  type: boolean
                  default: false
                  description: 'Specifies whether to deprecate any existing credentials.

                    The 24-hour window does not apply.

                    Umbrella deletes the existing keys immediately. Set either both `idPrefix` and `secret` or `autoRotate`

                    to true. The default value is false.'
                autoRotate:
                  type: boolean
                  description: 'Specifies whether to autogenerate keys.

                    The 24-hour window applies. Umbrella ignores any passed in credentials.'
                psk:
                  type: object
                  properties:
                    idPrefix:
                      type: string
                      description: 'Required if autoRotate is set to false. To be concatenated with server-side parameters

                        to generate the ID for the pre-shared key (PSK). If the value of `idPrefix` matches the current `idPrefix`,

                        then 24-hour credential storage is disabled. If the tunnel uses an IP address as the PSK ID, format the IP address as a string;

                        `autoRotate` is disabled.'
                    secret:
                      type: string
                      description: 'The secret aspect of a Pre-Shared Key. Optional, but either idPrefix OR idPrefix

                        and secret must be passed OR auto-Rotate set to true.

                        (16-64 characters, at least one upper and lowercase letter, one number, no special characters.)'
              required:
              - autoRotate
            example:
              deprecateCurrentKeys: true
              autoRotate: true
              psk:
                idPrefix: prefix-string
                secret: Secret123
      responses:
        '200':
          description: OK
          headers:
            Content-Type:
              $ref: '#/components/headers/Content-Type'
            Date:
              $ref: '#/components/headers/Date'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TunnelResourceObjectWithSecret'
              example:
                id: 1122321
                uri: /tunnels/1122321
                name: Site01Tunnel
                siteOriginId: 123456
                client:
                  deviceType: ASA
                  authentication:
                    type: PSK
                    parameters:
                      id: admin@2561066-237952254-umbrella.com
                      modifiedAt: '2018-06-13T16:07:07.222Z'
                      secret: This123Secret
                transport:
                  protocol: IPSec
                serviceType: SIG
                networkCIDRs:
                - 123.111.222.25/24
                - 111.222.39.1/32
                meta: {}
                createdAt: '2018-06-13T16:07:07.222Z'
                modifiedAt: '2018-06-13T16:07:07.222Z'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '500':
          $ref: '#/components/responses/ServerError'
  /tunnels/{id}/policies:
    get:
      summary: List Policies for Tunnel
      operationId: getTunnelPolicies
      security:
      - oauthFlow:
        - deployments.tunnels:read
      description: List the policies that include the network tunnel.
      parameters:
      - in: path
        name: id
        description: The ID of the tunnel.
        required: true
        schema:
          type: integer
      - in: query
        schema:
          type: string
          enum:
          - firewallrule
          - web
        name: type
        description: Filter the list of policies to only include the specified type.
        required: false
      - in: query
        schema:
          type: integer
        name: limit
        description: The number of items to return in the collection.
        required: false
      - in: query
        schema:
          type: integer
        name: page
        description: The number of a page in the collection. Use with the limit parameter to implement pagination.
        required: false
      tags:
      - Organization Tunnel
      responses:
        '200':
          description: OK
          headers:
            Content-Type:
              $ref: '#/components/headers/Content-Type'
            Date:
              $ref: '#/components/headers/Date'
          content:
            application/json:
              schema:
                type: array
                description: Policies associated with a tunnel.
                readOnly: true
                items:
                  type: object
                  readOnly: true
                  properties:
                    id:
                      type: integer
                      description: The resource ID. Use the ID as reference for subsequent requests.
                      example: 1122321
                    type:
                      type: string
                      description: The type of policy.
                      enum:
                      - firewallrule
                      - web
                    name:
                      type: string
                      description: The name of the policy.
                      example: Test Firewall Rule (Block Application)
                    organizationId:
                      type: integer
                      description: The organization ID.
                      example: 33451234
                    priority:
                      type: integer
                      description: An integer that represents the position of the policy in the policy list.
                      example: 4
                    isDefault:
                      type: boolean
                      description: Indicates whether the policy is the default policy.
                    isAppliedDirectly:
                      type: boolean
                      description: 'True if the tunnel is applied directly to this policy, false if the policy

                        is configured to use all tunnels.'
                    createdAt:
                      type: string
                      description: The date and time (timestamp) when the tunnel was created.
                      format: date-time
                      example: '2018-06-13T16:07:07.222Z'
                    modifiedAt:
                      $ref: '#/components/schemas/modifiedAt'
                    uri:
                      type: string
                      description: Resource URI
                      example: /v2/tunnels/8765432/policies
              example:
              - id: 1122321
                type: web
                name: Test Firewall Rule (Block Application)
                organizationId: 33451234
                priority: 4
                isDefault: true
                isAppliedDirectly: true
                createdAt: '2018-06-13T16:07:07.222Z'
                modifiedAt: '2018-06-13T16:07:07.222Z'
                uri: /v2/tunnels/8765432/policies
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '500':
          $ref: '#/components/responses/ServerError'
components:
  headers:
    Date:
      schema:
        type: string
        pattern: ^[0-90-90-90-9-0-90-9-0-90-9T0-90-9:0-90-9:0-90-9Z]+$
      description: The timestamp of the response.
      example: '2023-03-14T18:34:25Z'
    Content-Type:
      schema:
        type: string
      description: The MIME content type of the response body.
      example: application/json
  schemas:
    parametersWithSecret:
      type: object
      properties:
        id:
          type: string
          description: The PSK ID. If an IP address is used as the ID, the IP address is the value of this field.
          readOnly: true
          example: admin@2561066-237952254-umbrella.com
        modifiedAt:
          $ref: '#/components/schemas/modifiedAt'
        secret:
          $ref: '#/components/schemas/secretParameter'
    authentication:
      type: object
      description: The authentication context of the client.
      properties:
        type:
          type: string
          enum:
          - PSK
          example: PSK
          readOnly: true
        parameters:
          $ref: '#/components/schemas/parameters'
    ikeState:
      type: string
      readOnly: true
      description: "IKE SA State:\n  * CREATED\n  * CONNECTING\n  * ESTABLISHED\n  * PASSIVE\n  * REKEYING\n  * REKEYED\n  * DELETING\n  * DESTROYING\n"
      enum:
      - CREATED
      - CONNECTING
      - ESTABLISHED
      - PASSIVE
      - REKEYING
      - REKEYED
      - DELETING
      - DESTROYING
      example: ESTABLISHED
    secretParameter:
      type: string
      example: 123Secret
      description: The secret of the PSK credentials. Ensure that you save the secret. The secret is not provided at any other time.
    TunnelResourceObjectWithSecret:
      type: object
      description: The properties of the tunnel resource object.
      properties:
        id:
          type: integer
          readOnly: true
          description: The tunnel resource ID. Use this ID as a reference for subsequent requests.
          example: 1122321
        uri:
          type: string
          description: Resource URI
          readOnly: true
          example: /tunnels/1122321
        name:
          type: string
          description: 'Display the name of the tunnel. The tunnel name is required, cannot exceed 50 characters in length,

            and can''t have any special characters other than spaces and hyphens.'
          example: Site01Tunnel
        siteOriginId:
          type: integer
          description: The Site origin ID that is associated with the tunnel.
          example: 123456
        client:
          $ref: '#/components/schemas/TunnelClientMetadataWithSecret'
        transport:
          type: object
          properties:
            protocol:
              description: The tunnel transport protocol. The default transport protocol is IPSec.
              type: string
              enum:
              - IPSec
              readOnly: true
              example: IPSec
        serviceType:
          $ref: '#/components/schemas/serviceType'
        networkCIDRs:
          $ref: '#/components/schemas/networkCIDRs'
        meta:
          type: object
          description: The metadata for the tunnel object, related to service internals.
          readOnly: true
        createdAt:
          type: string
          description: The date and time (timestamp) when the tunnel was created.
          format: date-time
          readOnly: true
          example: '2018-06-13T16:07:07.222Z'
        modifiedAt:
          $ref: '#/components/schemas/modifiedAt'
      example:
        id: 1122321
        uri: /tunnels/1122321
        name: Site01Tunnel
        siteOriginId: 123456
        client:
          deviceType: ASA
          authentication:
            type: PSK
            parameters:
              id: admin@2561066-237952254-umbrella.com
              modifiedAt: '2018-06-13T16:07:07.222Z'
              secret: secretkey123
        transport:
          protocol: IPSec
        serviceType: SIG
        networkCIDRs:
        - 123.111.222.25/24
        - 111.222.39.1/32
        meta: {}
        createdAt: '2018-06-13T16:07:07.222Z'
        modifiedAt: '2018-06-13T16:07:07.222Z'
    parameters:
      type: object
      properties:
        id:
          type: string
          description: The PSK ID. If an IP address is used as the ID, the IP address is the value of this field.
          readOnly: true
          example: admin@2561066-237952254-umbrella.com
        modifiedAt:
          $ref: '#/components/schemas/modifiedAt'
    serviceType:
      type: string
      description: The type of service to associate with the tunnel. The default value is `SIG`.
      enum:
      - SIG
      - Private Access
      example: SIG
    modifiedAt:
      type: string
      format: date-time
      readOnly: true
      example: '2018-06-13T16:07:07.222Z'
      description: The data and time (timestamp) when the tunnel was updated.
    authenticationWithSecret:
      type: object
      description: The authentication context of the client.
      properties:
        type:
          type: string
          enum:
          - PSK
          example: PSK
          readOnly: true
      

# --- truncated at 32 KB (53 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cisco-umbrella/refs/heads/main/openapi/cisco-umbrella-organization-tunnel-api-openapi.yml