cURL
curl --request PATCH \
--url https://api.rigbox.dev/api/v1/tunnels/{id}/policy \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"expected_connection_generation": 123,
"expected_policy_epoch": 123,
"visibility": "<string>",
"allowed_emails": [
"<string>"
],
"public_acknowledgment": {
"acknowledged": true,
"connection_generation": 123,
"policy_epoch": 123,
"target_fingerprint": "<string>"
}
}
'import requests
url = "https://api.rigbox.dev/api/v1/tunnels/{id}/policy"
payload = {
"expected_connection_generation": 123,
"expected_policy_epoch": 123,
"visibility": "<string>",
"allowed_emails": ["<string>"],
"public_acknowledgment": {
"acknowledged": True,
"connection_generation": 123,
"policy_epoch": 123,
"target_fingerprint": "<string>"
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
expected_connection_generation: 123,
expected_policy_epoch: 123,
visibility: '<string>',
allowed_emails: ['<string>'],
public_acknowledgment: {
acknowledged: true,
connection_generation: 123,
policy_epoch: 123,
target_fingerprint: '<string>'
}
})
};
fetch('https://api.rigbox.dev/api/v1/tunnels/{id}/policy', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.rigbox.dev/api/v1/tunnels/{id}/policy",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'expected_connection_generation' => 123,
'expected_policy_epoch' => 123,
'visibility' => '<string>',
'allowed_emails' => [
'<string>'
],
'public_acknowledgment' => [
'acknowledged' => true,
'connection_generation' => 123,
'policy_epoch' => 123,
'target_fingerprint' => '<string>'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.rigbox.dev/api/v1/tunnels/{id}/policy"
payload := strings.NewReader("{\n \"expected_connection_generation\": 123,\n \"expected_policy_epoch\": 123,\n \"visibility\": \"<string>\",\n \"allowed_emails\": [\n \"<string>\"\n ],\n \"public_acknowledgment\": {\n \"acknowledged\": true,\n \"connection_generation\": 123,\n \"policy_epoch\": 123,\n \"target_fingerprint\": \"<string>\"\n }\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://api.rigbox.dev/api/v1/tunnels/{id}/policy")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"expected_connection_generation\": 123,\n \"expected_policy_epoch\": 123,\n \"visibility\": \"<string>\",\n \"allowed_emails\": [\n \"<string>\"\n ],\n \"public_acknowledgment\": {\n \"acknowledged\": true,\n \"connection_generation\": 123,\n \"policy_epoch\": 123,\n \"target_fingerprint\": \"<string>\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.rigbox.dev/api/v1/tunnels/{id}/policy")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"expected_connection_generation\": 123,\n \"expected_policy_epoch\": 123,\n \"visibility\": \"<string>\",\n \"allowed_emails\": [\n \"<string>\"\n ],\n \"public_acknowledgment\": {\n \"acknowledged\": true,\n \"connection_generation\": 123,\n \"policy_epoch\": 123,\n \"target_fingerprint\": \"<string>\"\n }\n}"
response = http.request(request)
puts response.read_body{
"allowed_emails": [
"<string>"
],
"tunnel": {
"connection_generation": 123,
"created_at": "2023-11-07T05:31:56Z",
"expires_at": "2023-11-07T05:31:56Z",
"hostname": "<string>",
"id": "<string>",
"policy_epoch": 123,
"status": "<string>",
"target": {
"local_ip": "<string>",
"port": 123,
"scheme": "<string>",
"http_host": "<string>",
"tls_server_name": "<string>"
},
"target_fingerprint": "<string>",
"updated_at": "2023-11-07T05:31:56Z",
"user_id": "<string>",
"visibility": "<string>",
"lease_expires_at": "2023-11-07T05:31:56Z"
}
}Update tunnel access
cURL
curl --request PATCH \
--url https://api.rigbox.dev/api/v1/tunnels/{id}/policy \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"expected_connection_generation": 123,
"expected_policy_epoch": 123,
"visibility": "<string>",
"allowed_emails": [
"<string>"
],
"public_acknowledgment": {
"acknowledged": true,
"connection_generation": 123,
"policy_epoch": 123,
"target_fingerprint": "<string>"
}
}
'import requests
url = "https://api.rigbox.dev/api/v1/tunnels/{id}/policy"
payload = {
"expected_connection_generation": 123,
"expected_policy_epoch": 123,
"visibility": "<string>",
"allowed_emails": ["<string>"],
"public_acknowledgment": {
"acknowledged": True,
"connection_generation": 123,
"policy_epoch": 123,
"target_fingerprint": "<string>"
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
expected_connection_generation: 123,
expected_policy_epoch: 123,
visibility: '<string>',
allowed_emails: ['<string>'],
public_acknowledgment: {
acknowledged: true,
connection_generation: 123,
policy_epoch: 123,
target_fingerprint: '<string>'
}
})
};
fetch('https://api.rigbox.dev/api/v1/tunnels/{id}/policy', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.rigbox.dev/api/v1/tunnels/{id}/policy",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'expected_connection_generation' => 123,
'expected_policy_epoch' => 123,
'visibility' => '<string>',
'allowed_emails' => [
'<string>'
],
'public_acknowledgment' => [
'acknowledged' => true,
'connection_generation' => 123,
'policy_epoch' => 123,
'target_fingerprint' => '<string>'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.rigbox.dev/api/v1/tunnels/{id}/policy"
payload := strings.NewReader("{\n \"expected_connection_generation\": 123,\n \"expected_policy_epoch\": 123,\n \"visibility\": \"<string>\",\n \"allowed_emails\": [\n \"<string>\"\n ],\n \"public_acknowledgment\": {\n \"acknowledged\": true,\n \"connection_generation\": 123,\n \"policy_epoch\": 123,\n \"target_fingerprint\": \"<string>\"\n }\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://api.rigbox.dev/api/v1/tunnels/{id}/policy")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"expected_connection_generation\": 123,\n \"expected_policy_epoch\": 123,\n \"visibility\": \"<string>\",\n \"allowed_emails\": [\n \"<string>\"\n ],\n \"public_acknowledgment\": {\n \"acknowledged\": true,\n \"connection_generation\": 123,\n \"policy_epoch\": 123,\n \"target_fingerprint\": \"<string>\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.rigbox.dev/api/v1/tunnels/{id}/policy")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"expected_connection_generation\": 123,\n \"expected_policy_epoch\": 123,\n \"visibility\": \"<string>\",\n \"allowed_emails\": [\n \"<string>\"\n ],\n \"public_acknowledgment\": {\n \"acknowledged\": true,\n \"connection_generation\": 123,\n \"policy_epoch\": 123,\n \"target_fingerprint\": \"<string>\"\n }\n}"
response = http.request(request)
puts response.read_body{
"allowed_emails": [
"<string>"
],
"tunnel": {
"connection_generation": 123,
"created_at": "2023-11-07T05:31:56Z",
"expires_at": "2023-11-07T05:31:56Z",
"hostname": "<string>",
"id": "<string>",
"policy_epoch": 123,
"status": "<string>",
"target": {
"local_ip": "<string>",
"port": 123,
"scheme": "<string>",
"http_host": "<string>",
"tls_server_name": "<string>"
},
"target_fingerprint": "<string>",
"updated_at": "2023-11-07T05:31:56Z",
"user_id": "<string>",
"visibility": "<string>",
"lease_expires_at": "2023-11-07T05:31:56Z"
}
}Tunnels are not available to customers yet. The production service is disabled
pending browser-domain isolation, and the planned signed CLI 0.13.1 release is not
yet published. This page documents the prepared API contract; it does not enable
the service. See local tunnels for planned use and risks.
private for the owner, privileged for the owner and invited verified email identities, or public for visitors without Rigbox sign-in. An admitted visitor receives the access your local application provides, including its write and administrative features.
Submit the current policy epoch and connection generation from inspect. Public access also requires an affirmative acknowledgment of that exact target fingerprint, policy epoch, and generation. If the tunnel changes, reload and review its target before submitting another update.
The invitation list replaces the previous list and is valid only with privileged access. A policy change invalidates existing viewer sessions and closes streams admitted under the previous policy. See local tunnels for sharing behavior.Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
Body
application/json