Mcp Tunnels
Connect Claude to a private MCP server through an Anthropic MCP tunnel. Drives the Docker Compose quickstart end to end: certificates, proxy config, cloudflared, and a verifiable sample server.
- Type
- Plugin
- Repository
- anthropics/claude-plugins-official
- GitHub stars
- 37.1k
- License
- Apache-2.0
- Repo last updated
- Sep 25, 2026
- Source file
- plugins/mcp-tunnels/.claude-plugin/plugin.json
- Author
- Anthropic
What Mcp Tunnels is
Mcp Tunnels is a plugin published in the anthropics/claude-plugins-official repository on GitHub, which has about 37.1k stars. The repository describes itself as: “Official, Anthropic-managed directory of high quality Claude Code Plugins.”
A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.
Installing Mcp Tunnels adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.
How to install Mcp Tunnels
Claude Code
- Add the repository as a plugin marketplace: claude plugin marketplace add anthropics/claude-plugins-official
- Install the plugin: claude plugin install mcp-tunnels@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
- Restart the session if the new skills or commands don't appear straight away.
Claude Cowork
- Open Customize → Plugins and choose Add marketplace.
- Enter anthropics/claude-plugins-official (the owner/repo shorthand works for GitHub).
- Find Mcp Tunnels in the list, click Install, then connect any connectors it needs from its Connectors tab.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/mcp-tunnels/.claude-plugin/plugin.json, shared under the repository's Apache-2.0 license. Read the full file on GitHub.
Connect Claude to an MCP server running inside your private network through an Anthropic MCP tunnel — no inbound ports, no public exposure, no IP allowlisting on your origin. Traffic flows over an outbound-only connection.
> Research preview. MCP tunnels is provided "as-is" with no uptime or > support commitment and depends on a third-party transport provider > (Cloudflare). Review the > security model > before sending anything sensitive.
Commands
/create-docker-mcp-tunnel [deployment-dir]
Drives the MCP tunnels quickstart end to end on your machine, using Docker Compose with manually supplied credentials (the shortest path for local testing). It walks you through the parts only you can do in the Claude Console and runs everything else for you:
- Preflight — checks Docker, Docker Compose, OpenSSL, and outbound connectivity.
- Create the tunnel (Console) — you create it and copy the domain; the token stays out of the chat and goes into a locked-down, gitignored .env.
- Certificates — generates a CA and a server certificate with OpenSSL, with the exact extensions the tunnel requires.
- Register the CA (Console) — you upload ca.crt; the tunnel goes Active.
- Upstream — scaffolds a verifiable FastMCP sample server, or wires up an MCP server you already have.
- Proxy config + Compose — writes mcp-proxy.yaml and a docker-compose.yaml with digest-pinned images and the cloudflared agent.
- Start and verify — brings the stack up and checks the proxy and tunnel logs.
- Call it from Claude — shows you how to reach the server from Managed Agents and the Messages API.
It also carries a troubleshooting matrix (TLS handshake failures, the routes-must-be-a-map gotcha, the tls.key permission issue, the config-is-not-hot-reloaded trap, upstream IP validation) and the operational basics for token rotation and certificate renewal.
Usage:
/create-docker-mcp-tunnel
/create-docker-mcp-tunnel ~/work/my-tunnelCopying the CA certificate to another machine
You register the CA in the Console from a browser, which is often a different machine than the one running the stack (for example, the tunnel runs in a remote homespace but you upload ca.crt from your laptop or devbox). Only the certificate ( /data/ca.crt, ~1 KB PEM) leaves the host — never data/ca.key or data/tls.key.
For a file this small, the simplest path is to print it and paste it into the Console's certificate field directly:
cat <deployment-dir>/data/ca.crt # default: ~/mcp-tunnel/data/ca.crtTo copy it as a file with scp, run the command from whichever machine can SSH to the other (scp can't relay between two remotes). Pulling from a homespace onto your devbox — if you've run coder config-ssh, the host is coder. :
scp coder.<workspace>:<deployment-dir>/data/ca.crt .
# generic form: scp <homespace-ssh-host>:~/mcp-tunnel/data/ca.crt .Or push from the host to the devbox, if the host can reach it:
scp <deployment-dir>/data/ca.crt <user>@<devbox-host>:~/What gets built
A small container stack on your host:
When it's running, the routed server is reachable from Claude at https:// . / with nothing listening on a public port.
Requirements
- Docker and Docker Compose.
- OpenSSL 1.1.1 or newer.
- A Claude Console role that can manage MCP tunnels.
- Outbound access to api.anthropic.com:443 and the tunnel edge on 7844 TCP/UDP. No inbound ports are opened.
Scope and next steps
This plugin targets the manual-credentials, single-host, local-testing path. For a hardened single-host deployment (non-root, read-only rootfs, dropped capabilities), a Kubernetes deployment, or programmatic access via Workload Identity Federation, see the official deployment guides: Deploy with Docker Compose / Deploy with Helm.
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Mcp Tunnels?
Mcp Tunnels is a plugin for Claude Code and Claude Cowork from the anthropics/claude-plugins-official repository on GitHub. Connect Claude to a private MCP server through an Anthropic MCP tunnel. Drives the Docker Compose quickstart end to end: certificates, proxy config, cloudflared, and a verifiable sample server.
How do I install Mcp Tunnels in Claude Code?
Add the repository as a plugin marketplace: claude plugin marketplace add anthropics/claude-plugins-official Install the plugin: claude plugin install mcp-tunnels@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.
Can I use Mcp Tunnels in Claude Cowork?
Open Customize → Plugins and choose Add marketplace. Enter anthropics/claude-plugins-official (the owner/repo shorthand works for GitHub). Find Mcp Tunnels in the list, click Install, then connect any connectors it needs from its Connectors tab.
Is Mcp Tunnels safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Security Guidance Security review for Claude-generated code. Pattern-based warnings on edits, LLM-powered diff review on Stop, and an agentic commit reviewer that catches injection, XSS, SSRF, hardcoded secrets, and 25+ other vulnerability classes. Plugin · anthropics/claude-plugins-official
- Serena Semantic code analysis MCP server providing intelligent code understanding, refactoring suggestions, and codebase navigation through language server protocol integration. Plugin · anthropics/claude-plugins-official
- Skill Reviewer Use this agent when the user has created or modified a skill and needs quality review, asks to "review my skill", "check skill quality", "improve skill description", or wants to ensure skill follows best practices. Trigger proactively after skill creation. Examples: Context: User just created a new skill user: "I've created a PDF processing skill" assistant: "Great! Let me review the skill… Subagent · anthropics/claude-plugins-official
- Test Engineer Writes characterization, contract, and equivalence tests that pin down legacy behavior so transformation can be proven correct. Use before any rewrite. Subagent · anthropics/claude-plugins-official
- Playground Creates interactive HTML playgrounds — self-contained single-file explorers with visual controls, live preview, and prompt output with copy button Plugin · anthropics/claude-plugins-official
- Mcp Server Dev Skills for designing and building MCP servers that work seamlessly with Claude — guides you through deployment models (remote HTTP, MCPB, local), tool design patterns, auth, and interactive MCP apps. Plugin · anthropics/claude-plugins-official
- Playwright Browser automation and end-to-end testing MCP server by Microsoft. Enables Claude to interact with web pages, take screenshots, fill forms, click elements, and perform automated browser testing workflows. Plugin · anthropics/claude-plugins-official
- Math Olympiad Solve competition math (IMO, Putnam, USAMO) with adversarial verification that catches what self-verification misses. Fresh-context verifiers attack proofs with specific failure patterns. Calibrated abstention over bluffing. Plugin · anthropics/claude-plugins-official