OpenTunnel - Amazon IoT
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).


Creates a new tunnel, and returns two client access tokens for clients to use to connect to the Amazon IoT Secure Tunneling proxy server.

Requires permission to access the OpenTunnel action.

Request Syntax

{ "description": "string", "destinationConfig": { "services": [ "string" ], "thingName": "string" }, "tags": [ { "key": "string", "value": "string" } ], "timeoutConfig": { "maxLifetimeTimeoutMinutes": number } }

Request Parameters

For information about the parameters that are common to all actions, see Common Parameters.

The request accepts the following data in JSON format.


A short text description of the tunnel.

Type: String

Pattern: [^\p{C}]{1,2048}

Required: No


The destination configuration for the OpenTunnel request.

Type: DestinationConfig object

Required: No


A collection of tag metadata.

Type: Array of Tag objects

Array Members: Minimum number of 1 item. Maximum number of 200 items.

Required: No


Timeout configuration for a tunnel.

Type: TimeoutConfig object

Required: No

Response Syntax

{ "destinationAccessToken": "string", "sourceAccessToken": "string", "tunnelArn": "string", "tunnelId": "string" }

Response Elements

If the action is successful, the service sends back an HTTP 200 response.

The following data is returned in JSON format by the service.


The access token the destination local proxy uses to connect to Amazon IoT Secure Tunneling.

Type: String


The access token the source local proxy uses to connect to Amazon IoT Secure Tunneling.

Type: String


The Amazon Resource Name for the tunnel.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 1600.


A unique alpha-numeric tunnel ID.

Type: String

Pattern: [a-zA-Z0-9_\-+=:]{1,128}



Thrown when a tunnel limit is exceeded.

HTTP Status Code: 400

See Also

For more information about using this API in one of the language-specific Amazon SDKs, see the following: