APIs.io Engineering Platform Magic IPsec Tunnels API

The Magic IPsec Tunnels API from APIs.io Engineering Platform — 3 operation(s) for magic ipsec tunnels.

Operations 7

GET /accounts/{account_id}/magic/ipsec_tunnels APIs.io Engineering Platform List IPsec tunnels #
POST /accounts/{account_id}/magic/ipsec_tunnels APIs.io Engineering Platform Create IPsec tunnels #
PUT /accounts/{account_id}/magic/ipsec_tunnels APIs.io Engineering Platform Update multiple IPsec tunnels #
DELETE /accounts/{account_id}/magic/ipsec_tunnels/{ipsec_tunnel_id} APIs.io Engineering Platform Delete IPsec Tunnel #
GET /accounts/{account_id}/magic/ipsec_tunnels/{ipsec_tunnel_id} APIs.io Engineering Platform List IPsec tunnel details #
PUT /accounts/{account_id}/magic/ipsec_tunnels/{ipsec_tunnel_id} APIs.io Engineering Platform Update IPsec Tunnel #
POST /accounts/{account_id}/magic/ipsec_tunnels/{ipsec_tunnel_id}/psk_generate APIs.io Engineering Platform Generate Pre Shared Key (PSK) for IPsec tunnels #

Documentation

Specifications

Other Resources

🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-1ab188a6-cc1f-490d-9413-9c6da20918d0?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-0e94f581-cbc1-48e0-b594-1f6b3d07a328?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-4517d93a-e7f7-4dc2-b572-06762bbe14de?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-88f9ddbb-3115-47dc-b6e5-7fc6f1d2a190?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-3a12caae-4945-4df4-8ab9-bb6219ba7a9f?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-863b18f0-c2f2-4e32-a5fa-0d1e6ccf77a9?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-189876d1-f207-49a2-a4bc-5c67ae78cd19?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-c1e74fd9-3f84-4d95-943d-d645d6cb82f7?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-b002164d-6e8a-4b6d-b409-4929476e7818?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-508660fd-30b8-4c9c-aede-8edbac8a514d?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-da35e0ba-f1a9-42fe-a77a-56ff0a47e341?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-1d4df7d0-9c92-4fa8-946f-2110c2b3b48d?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-2af6f54f-d259-46c0-8f86-78856f5885cd?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-cc203f31-e7f6-42ec-ad34-c5c4cde58904?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-f19285da-48dd-4691-bbdf-f7d6bec157a3?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-aa69cacc-4bbf-4724-a1d4-78cdad57fee8?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-a5858f86-04d3-4e15-ae11-b42c7516688b?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-c2052341-766c-43c7-b1dc-ed4985e4606b?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-aa777c90-8271-4809-8eac-3ec39a9a899c?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-4d5957dc-df05-4216-a5fc-d46b3ba811d8?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-28d97617-fdba-46a5-ac3e-40f3d2e0fa57?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-7429b451-d812-4abc-b497-b763372cf5c5?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-b0eafdd0-adaa-48a2-a855-6a31beb86d83?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-209f34ef-13c1-400c-bca8-fcddb304aff5?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-fb2bbbb8-d4cc-48b1-a660-c8e158bfbbea?action=share&creator=35240

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/engineering-platform-magic-ipsec-tunnels-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

engineering-platform-magic-ipsec-tunnels-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  description: 'To get started using Cloudflare''s products and services via the API, refer to [how to interact with Cloudflare](https://developers.cloudflare.com/fundamentals/basic-tasks/interact-with-cloudflare/), which covers using tools like [Terraform](https://developers.cloudflare.com/terraform/#cloudflare-terraform) and the [official SDKs](https://developers.cloudflare.com/fundamentals/api/reference/sdks/) to maintain your Cloudflare resources.


    Using the Cloudflare API requires authentication so that Cloudflare knows who is making requests and what permissions you have. Create an API token to grant access to the API to perform actions.


    To create an API token, from the Cloudflare dashboard, go to My Profile > API Tokens and select Create Token. For more information on how to create and troubleshoot API tokens, refer to

    our [API fundamentals](https://developers.cloudflare.com/fundamentals/api/).


    Totally new to Cloudflare? [Start here](https://developers.cloudflare.com/fundamentals/get-started/).'
  license:
    name: BSD-3-Clause
    url: https://opensource.org/licenses/BSD-3-Clause
  title: APIs.io Engineering Platform Cloudflare Magic IPsec Tunnels API
  version: 4.0.0
tags:
- name: Magic IPsec Tunnels
paths:
  /accounts/{account_id}/magic/ipsec_tunnels:
    get:
      description: Lists IPsec tunnels associated with an account.
      operationId: magic-ipsec-tunnels-list-ipsec-tunnels
      parameters:
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/magic_identifier'
      responses:
        4XX:
          content:
            application/json:
              schema:
                allOf:
                - $ref: '#/components/schemas/magic_schemas-tunnels_collection_response'
                - $ref: '#/components/schemas/magic_api-response-common-failure'
          description: List IPsec tunnels response failure
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/magic_schemas-tunnels_collection_response'
          description: List IPsec tunnels response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform List IPsec tunnels
      tags:
      - Magic IPsec Tunnels
      x-cfPlanAvailability:
        business: false
        enterprise: true
        free: false
        pro: false
    post:
      description: Creates new IPsec tunnels associated with an account. Use `?validate_only=true` as an optional query parameter to only run validation without persisting changes.
      operationId: magic-ipsec-tunnels-create-ipsec-tunnels
      parameters:
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/magic_identifier'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/magic_schemas-tunnel_add_request'
        required: true
      responses:
        4XX:
          content:
            application/json:
              schema:
                allOf:
                - $ref: '#/components/schemas/magic_schemas-tunnels_collection_response'
                - $ref: '#/components/schemas/magic_api-response-common-failure'
          description: Create IPsec tunnels response failure
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/magic_schemas-tunnels_collection_response'
          description: Create IPsec tunnels response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Create IPsec tunnels
      tags:
      - Magic IPsec Tunnels
      x-cfPlanAvailability:
        business: false
        enterprise: true
        free: false
        pro: false
    put:
      description: Update multiple IPsec tunnels associated with an account. Use `?validate_only=true` as an optional query parameter to only run validation without persisting changes.
      operationId: magic-ipsec-tunnels-update-multiple-ipsec-tunnels
      parameters:
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/magic_identifier'
      requestBody:
        content:
          application/json:
            schema:
              required:
              - id
        required: true
      responses:
        4XX:
          content:
            application/json:
              schema:
                allOf:
                - $ref: '#/components/schemas/magic_schemas-modified_tunnels_collection_response'
                - $ref: '#/components/schemas/magic_api-response-common-failure'
          description: Update multiple IPsec tunnels response failure
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/magic_schemas-modified_tunnels_collection_response'
          description: Update multiple IPsec tunnels response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Update multiple IPsec tunnels
      tags:
      - Magic IPsec Tunnels
      x-cfPlanAvailability:
        business: false
        enterprise: true
        free: false
        pro: false
  /accounts/{account_id}/magic/ipsec_tunnels/{ipsec_tunnel_id}:
    delete:
      description: Disables and removes a specific static IPsec Tunnel associated with an account. Use `?validate_only=true` as an optional query parameter to only run validation without persisting changes.
      operationId: magic-ipsec-tunnels-delete-ipsec-tunnel
      parameters:
      - in: path
        name: ipsec_tunnel_id
        required: true
        schema:
          $ref: '#/components/schemas/magic_identifier'
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/magic_identifier'
      requestBody:
        content:
          application/json: {}
        required: true
      responses:
        4XX:
          content:
            application/json:
              schema:
                allOf:
                - $ref: '#/components/schemas/magic_schemas-tunnel_deleted_response'
                - $ref: '#/components/schemas/magic_api-response-common-failure'
          description: Delete IPsec Tunnel response failure
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/magic_schemas-tunnel_deleted_response'
          description: Delete IPsec Tunnel response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Delete IPsec Tunnel
      tags:
      - Magic IPsec Tunnels
      x-cfPlanAvailability:
        business: false
        enterprise: true
        free: false
        pro: false
    get:
      description: Lists details for a specific IPsec tunnel.
      operationId: magic-ipsec-tunnels-list-ipsec-tunnel-details
      parameters:
      - in: path
        name: ipsec_tunnel_id
        required: true
        schema:
          $ref: '#/components/schemas/magic_identifier'
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/magic_identifier'
      responses:
        4XX:
          content:
            application/json:
              schema:
                allOf:
                - $ref: '#/components/schemas/magic_schemas-tunnel_single_response'
                - $ref: '#/components/schemas/magic_api-response-common-failure'
          description: List IPsec tunnel details response failure
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/magic_schemas-tunnel_single_response'
          description: List IPsec tunnel details response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform List IPsec tunnel details
      tags:
      - Magic IPsec Tunnels
      x-cfPlanAvailability:
        business: false
        enterprise: true
        free: false
        pro: false
    put:
      description: Updates a specific IPsec tunnel associated with an account. Use `?validate_only=true` as an optional query parameter to only run validation without persisting changes.
      operationId: magic-ipsec-tunnels-update-ipsec-tunnel
      parameters:
      - in: path
        name: ipsec_tunnel_id
        required: true
        schema:
          $ref: '#/components/schemas/magic_identifier'
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/magic_identifier'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/magic_schemas-tunnel_update_request'
        required: true
      responses:
        4XX:
          content:
            application/json:
              schema:
                allOf:
                - $ref: '#/components/schemas/magic_schemas-tunnel_modified_response'
                - $ref: '#/components/schemas/magic_api-response-common-failure'
          description: Update IPsec Tunnel response failure
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/magic_schemas-tunnel_modified_response'
          description: Update IPsec Tunnel response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Update IPsec Tunnel
      tags:
      - Magic IPsec Tunnels
      x-cfPlanAvailability:
        business: false
        enterprise: true
        free: false
        pro: false
  /accounts/{account_id}/magic/ipsec_tunnels/{ipsec_tunnel_id}/psk_generate:
    post:
      description: Generates a Pre Shared Key for a specific IPsec tunnel used in the IKE session. Use `?validate_only=true` as an optional query parameter to only run validation without persisting changes. After a PSK is generated, the PSK is immediately persisted to Cloudflare's edge and cannot be retrieved later. Note the PSK in a safe place.
      operationId: magic-ipsec-tunnels-generate-pre-shared-key-(-psk)-for-ipsec-tunnels
      parameters:
      - in: path
        name: ipsec_tunnel_id
        required: true
        schema:
          $ref: '#/components/schemas/magic_identifier'
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/magic_identifier'
      requestBody:
        content:
          application/json: {}
        required: true
      responses:
        4XX:
          content:
            application/json:
              schema:
                allOf:
                - $ref: '#/components/schemas/magic_psk_generation_response'
                - $ref: '#/components/schemas/magic_api-response-common-failure'
          description: Generate Pre Shared Key (PSK) for IPsec tunnels response failure
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/magic_psk_generation_response'
          description: Generate Pre Shared Key (PSK) for IPsec tunnels response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Generate Pre Shared Key (PSK) for IPsec tunnels
      tags:
      - Magic IPsec Tunnels
      x-cfPlanAvailability:
        business: false
        enterprise: true
        free: false
        pro: false
components:
  schemas:
    magic_schemas-tunnel_add_request:
      allOf:
      - $ref: '#/components/schemas/magic_schemas-tunnel_add_single_request'
    magic_cloudflare_ipsec_endpoint:
      description: The IP address assigned to the Cloudflare side of the IPsec tunnel.
      example: 203.0.113.1
      type: string
    magic_schemas-tunnel_add_single_request:
      properties:
        cloudflare_endpoint:
          $ref: '#/components/schemas/magic_cloudflare_ipsec_endpoint'
        customer_endpoint:
          $ref: '#/components/schemas/magic_customer_ipsec_endpoint'
        description:
          $ref: '#/components/schemas/magic_components-schemas-description'
        health_check:
          $ref: '#/components/schemas/magic_health_check'
        interface_address:
          $ref: '#/components/schemas/magic_interface_address'
        name:
          $ref: '#/components/schemas/magic_schemas-name'
        psk:
          $ref: '#/components/schemas/magic_psk'
        replay_protection:
          $ref: '#/components/schemas/magic_replay_protection'
      required:
      - name
      - cloudflare_endpoint
      - interface_address
      type: object
    magic_schemas-created_on:
      description: The date and time the tunnel was created.
      example: '2017-06-14T00:00:00Z'
      format: date-time
      readOnly: true
      type: string
    magic_components-schemas-description:
      description: An optional description forthe IPsec tunnel.
      example: Tunnel for ISP X
      type: string
    magic_psk_metadata:
      description: The PSK metadata that includes when the PSK was generated.
      properties:
        last_generated_on:
          $ref: '#/components/schemas/magic_schemas-modified_on'
      type: object
    magic_health_check:
      properties:
        direction:
          default: unidirectional
          description: The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the tunnel and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the tunnel. Note in the case of bidirecitonal healthchecks, the target field in health_check is ignored as the interface_address is used to send traffic into the tunnel.
          enum:
          - unidirectional
          - bidirectional
          example: bidirectional
          type: string
        enabled:
          default: true
          description: Determines whether to run healthchecks for a tunnel.
          example: true
          type: boolean
        rate:
          default: mid
          description: How frequent the health check is run. The default value is `mid`.
          enum:
          - low
          - mid
          - high
          example: low
          type: string
        target:
          description: The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to `customer_gre_endpoint address`. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target.
          example: 203.0.113.1
          type: string
        type:
          default: reply
          description: The type of healthcheck to run, reply or request. The default value is `reply`.
          enum:
          - reply
          - request
          example: request
          type: string
      type: object
    magic_schemas-name:
      description: The name of the IPsec tunnel. The name cannot share a name with other tunnels.
      example: IPsec_1
      type: string
    magic_allow_null_cipher:
      description: When `true`, the tunnel can use a null-cipher (`ENCR_NULL`) in the ESP tunnel (Phase 2).
      example: true
      type: boolean
    magic_api-response-common-failure:
      properties:
        errors:
          allOf:
          - $ref: '#/components/schemas/magic_messages'
          example:
          - code: 7003
            message: No route for the URI
          minLength: 1
        messages:
          allOf:
          - $ref: '#/components/schemas/magic_messages'
          example: []
        result:
          enum:
          - null
          type:
          - object
          - 'null'
        success:
          description: Whether the API call was successful
          enum:
          - false
          example: false
          type: boolean
      required:
      - success
      - errors
      - messages
      - result
      type: object
    magic_schemas-modified_tunnels_collection_response:
      allOf:
      - $ref: '#/components/schemas/magic_api-response-single'
      - properties:
          result:
            properties:
              modified:
                example: true
                type: boolean
              modified_ipsec_tunnels:
                items:
                  $ref: '#/components/schemas/magic_ipsec-tunnel'
                type: array
    magic_tunnel_health_check:
      properties:
        enabled:
          default: true
          description: Determines whether to run healthchecks for a tunnel.
          example: true
          type: boolean
        rate:
          default: mid
          description: How frequent the health check is run. The default value is `mid`.
          enum:
          - low
          - mid
          - high
          example: low
          type: string
        target:
          description: The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to `customer_gre_endpoint address`.
          example: 203.0.113.1
          type: string
        type:
          default: reply
          description: The type of healthcheck to run, reply or request. The default value is `reply`.
          enum:
          - reply
          - request
          example: request
          type: string
      type: object
    magic_schemas-tunnel_modified_response:
      allOf:
      - $ref: '#/components/schemas/magic_api-response-single'
      - properties:
          result:
            properties:
              modified:
                example: true
                type: boolean
              modified_ipsec_tunnel:
                $ref: '#/components/schemas/magic_ipsec-tunnel'
            type: object
    magic_schemas-modified_on:
      description: The date and time the tunnel was last modified.
      example: '2017-06-14T05:20:00Z'
      format: date-time
      readOnly: true
      type: string
    magic_messages:
      example: []
      items:
        properties:
          code:
            minimum: 1000
            type: integer
          message:
            type: string
        required:
        - code
        - message
        type: object
        uniqueItems: true
      type: array
    magic_interface_address:
      description: 'A 31-bit prefix (/31 in CIDR notation) supporting two hosts, one for each side of the tunnel. Select the subnet from the following private IP space: 10.0.0.0–10.255.255.255, 172.16.0.0–172.31.255.255, 192.168.0.0–192.168.255.255.'
      example: 192.0.2.0/31
      type: string
    magic_psk_generation_response:
      allOf:
      - $ref: '#/components/schemas/magic_api-response-single'
      - properties:
          result:
            properties:
              ipsec_tunnel_id:
                $ref: '#/components/schemas/magic_identifier'
              psk:
                $ref: '#/components/schemas/magic_psk'
              psk_metadata:
                $ref: '#/components/schemas/magic_psk_metadata'
    magic_replay_protection:
      default: false
      description: If `true`, then IPsec replay protection will be supported in the Cloudflare-to-customer direction.
      example: false
      type: boolean
    magic_schemas-tunnel_deleted_response:
      allOf:
      - $ref: '#/components/schemas/magic_api-response-single'
      - properties:
          result:
            properties:
              deleted:
                example: true
                type: boolean
              deleted_ipsec_tunnel:
                $ref: '#/components/schemas/magic_ipsec-tunnel'
            type: object
    magic_schemas-tunnel_single_response:
      allOf:
      - $ref: '#/components/schemas/magic_api-response-single'
      - properties:
          result:
            properties:
              ipsec_tunnel:
                $ref: '#/components/schemas/magic_ipsec-tunnel'
            type: object
    magic_psk:
      description: A randomly generated or provided string for use in the IPsec tunnel.
      example: O3bwKSjnaoCxDoUxjcq4Rk8ZKkezQUiy
      type: string
    magic_schemas-tunnels_collection_response:
      allOf:
      - $ref: '#/components/schemas/magic_api-response-single'
      - properties:
          result:
            properties:
              ipsec_tunnels:
                items:
                  $ref: '#/components/schemas/magic_ipsec-tunnel'
                type: array
    magic_api-response-single:
      allOf:
      - $ref: '#/components/schemas/magic_api-response-common'
      - properties:
          result:
            anyOf:
            - type:
              - object
              - 'null'
            - type:
              - string
              - 'null'
      type: object
    magic_ipsec-tunnel:
      properties:
        allow_null_cipher:
          $ref: '#/components/schemas/magic_allow_null_cipher'
        cloudflare_endpoint:
          $ref: '#/components/schemas/magic_cloudflare_ipsec_endpoint'
        created_on:
          $ref: '#/components/schemas/magic_schemas-created_on'
        customer_endpoint:
          $ref: '#/components/schemas/magic_customer_ipsec_endpoint'
        description:
          $ref: '#/components/schemas/magic_components-schemas-description'
        id:
          $ref: '#/components/schemas/magic_schemas-identifier'
        interface_address:
          $ref: '#/components/schemas/magic_interface_address'
        modified_on:
          $ref: '#/components/schemas/magic_schemas-modified_on'
        name:
          $ref: '#/components/schemas/magic_schemas-name'
        psk_metadata:
          $ref: '#/components/schemas/magic_psk_metadata'
        replay_protection:
          $ref: '#/components/schemas/magic_replay_protection'
        tunnel_health_check:
          $ref: '#/components/schemas/magic_tunnel_health_check'
      required:
      - name
      - cloudflare_endpoint
      - interface_address
      type: object
    magic_customer_ipsec_endpoint:
      description: The IP address assigned to the customer side of the IPsec tunnel. Not required, but must be set for proactive traceroutes to work.
      example: 203.0.113.1
      type: string
    magic_schemas-identifier:
      description: Tunnel identifier tag.
      example: c4a7362d577a6c3019a474fd6f485821
      maxLength: 32
      readOnly: true
      type: string
    magic_api-response-common:
      properties:
        errors:
          $ref: '#/components/schemas/magic_messages'
        messages:
          $ref: '#/components/schemas/magic_messages'
        result:
          anyOf:
          - type: object
          - items: {}
            type: array
          - type: string
        success:
          description: Whether the API call was successful
          enum:
          - true
          example: true
          type: boolean
      required:
      - success
      - errors
      - messages
      - result
      type: object
    magic_schemas-tunnel_update_request:
      allOf:
      - $ref: '#/components/schemas/magic_schemas-tunnel_add_single_request'
    magic_identifier:
      description: Identifier
      example: 023e105f4ecef8ad9ca31a8372d0c353
      maxLength: 32
      readOnly: true
      type: string
  securitySchemes:
    api_email:
      in: header
      name: X-Auth-Email
      type: apiKey
    api_key:
      in: header
      name: X-Auth-Key
      type: apiKey
    api_token:
      scheme: bearer
      type: http
    user_service_key:
      in: header
      name: X-Auth-User-Service-Key
      type: apiKey