> ## Documentation Index
> Fetch the complete documentation index at: https://docs.rigbox.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Update tunnel access

<Info>
  Tunnels are not available to customers yet. The production service is disabled
  pending browser-domain isolation, and the planned signed CLI 0.13.1 release is not
  yet published. This page documents the prepared API contract; it does not enable
  the service. See [local tunnels](/guides/local-tunnels) for planned use and risks.
</Info>

Choose `private` for the owner, `privileged` for the owner and invited verified email identities, or `public` for visitors without Rigbox sign-in. An admitted visitor receives the access your local application provides, including its write and administrative features.

Submit the current policy epoch and connection generation from [inspect](/api-reference/tunnels/get). Public access also requires an affirmative acknowledgment of that exact target fingerprint, policy epoch, and generation. If the tunnel changes, reload and review its target before submitting another update.

The invitation list replaces the previous list and is valid only with privileged access. A policy change invalidates existing viewer sessions and closes streams admitted under the previous policy. See [local tunnels](/guides/local-tunnels) for sharing behavior.


## OpenAPI

````yaml openapi/tunnels-api.json PATCH /api/v1/tunnels/{id}/policy
openapi: 3.1.0
info:
  title: Rigbox Public API
  description: >-
    Gateway-owned public API for Rigbox. The gateway composes its local
    lifecycle API with service-owned exported specs.
  contact:
    name: Rigbox
    url: https://rigbox.dev
  license:
    name: ''
  version: 1.0.0
servers:
  - url: https://api.rigbox.dev
    description: Production gateway
security: []
tags:
  - name: Tunnels
paths:
  /api/v1/tunnels/{id}/policy:
    patch:
      tags:
        - Tunnels
      operationId: policy
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateTunnelPolicyRequest'
        required: true
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TunnelDetails'
        '409':
          description: ''
      security:
        - bearer: []
components:
  schemas:
    UpdateTunnelPolicyRequest:
      type: object
      required:
        - expected_policy_epoch
        - expected_connection_generation
        - visibility
      properties:
        allowed_emails:
          type: array
          items:
            type: string
        expected_connection_generation:
          type: integer
          format: int64
        expected_policy_epoch:
          type: integer
          format: int64
        public_acknowledgment:
          oneOf:
            - type: 'null'
            - $ref: '#/components/schemas/PublicAcknowledgment'
        visibility:
          type: string
      additionalProperties: false
    TunnelDetails:
      type: object
      required:
        - tunnel
        - allowed_emails
      properties:
        allowed_emails:
          type: array
          items:
            type: string
        tunnel:
          $ref: '#/components/schemas/Tunnel'
    PublicAcknowledgment:
      type: object
      required:
        - target_fingerprint
        - connection_generation
        - policy_epoch
        - acknowledged
      properties:
        acknowledged:
          type: boolean
        connection_generation:
          type: integer
          format: int64
        policy_epoch:
          type: integer
          format: int64
        target_fingerprint:
          type: string
      additionalProperties: false
    Tunnel:
      type: object
      required:
        - id
        - user_id
        - hostname
        - target
        - target_fingerprint
        - visibility
        - status
        - policy_epoch
        - connection_generation
        - expires_at
        - created_at
        - updated_at
      properties:
        connection_generation:
          type: integer
          format: int64
        created_at:
          type: string
          format: date-time
        expires_at:
          type: string
          format: date-time
        hostname:
          type: string
        id:
          type: string
        lease_expires_at:
          type:
            - string
            - 'null'
          format: date-time
        policy_epoch:
          type: integer
          format: int64
        status:
          type: string
        target:
          $ref: '#/components/schemas/TunnelTarget'
        target_fingerprint:
          type: string
        updated_at:
          type: string
          format: date-time
        user_id:
          type: string
        visibility:
          type: string
    TunnelTarget:
      type: object
      required:
        - local_ip
        - port
        - scheme
      properties:
        http_host:
          type:
            - string
            - 'null'
        local_ip:
          type: string
        port:
          type: integer
          format: int32
        scheme:
          type: string
        tls_server_name:
          type:
            - string
            - 'null'
      additionalProperties: false
  securitySchemes:
    bearer:
      type: http
      scheme: bearer

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.