curl --silent --show-error --fail-with-body --request POST \
--url 'https://api.sandbox.stateset.app/api/v1/sandbox/{id}/tunnels' \
--header "Authorization: ApiKey $STATESET_SANDBOX_API_KEY" \
--header 'Content-Type: application/json' \
--data '{
"port": 1,
"protocol": "http",
"expires_in": 60,
"public": true
}'
{
"tunnel_id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"sandbox_id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"port": 1,
"protocol": "string",
"url": "https://example.com/webhooks/stateset",
"expires_at": "2026-08-31T14:22:05Z",
"token": "YOUR_API_KEY"
}
Create a tunnel
Creates a public tunnel to a sandbox port Served by the live controller (answers 401 unauthenticated) but absent from its published /openapi.json — verified…
POST
/
api
/
v1
/
sandbox
/
{id}
/
tunnels
curl --silent --show-error --fail-with-body --request POST \
--url 'https://api.sandbox.stateset.app/api/v1/sandbox/{id}/tunnels' \
--header "Authorization: ApiKey $STATESET_SANDBOX_API_KEY" \
--header 'Content-Type: application/json' \
--data '{
"port": 1,
"protocol": "http",
"expires_in": 60,
"public": true
}'
{
"tunnel_id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"sandbox_id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"port": 1,
"protocol": "string",
"url": "https://example.com/webhooks/stateset",
"expires_at": "2026-08-31T14:22:05Z",
"token": "YOUR_API_KEY"
}
Confirm your deployment before running this request. This page describes an API contract;
a published reference does not establish hosted availability. Check the dated
host report and obtain your deployment URL and credentials.
Replace the example host if your provisioned service uses a different URL.
/openapi.json — verified 2026-08-31.
Path parameters
string (uuid)
required
Unique sandbox identifier
Request body
CreateTunnelRequest
integer
required
Port to expose. Minimum:
1. Maximum: 65535.string
Protocol (http or https). Allowed values:
'http', 'https'.integer
TTL in seconds. Minimum:
60. Maximum: 86400.boolean
When true, no token is required.
Response
Tunnel
string
string
integer
string
string
string (date-time)
string
Status codes
| Code | Meaning |
|---|---|
200 | Tunnel created |
400 | — |
401 | — |
404 | — |
Using this contract
Read the source OpenAPI document for declared schemas and alternatives. This page also includes documented corrections from the spec overlays. Example IDs and values are illustrative; replace them with records from your workspace.curl --silent --show-error --fail-with-body --request POST \
--url 'https://api.sandbox.stateset.app/api/v1/sandbox/{id}/tunnels' \
--header "Authorization: ApiKey $STATESET_SANDBOX_API_KEY" \
--header 'Content-Type: application/json' \
--data '{
"port": 1,
"protocol": "http",
"expires_in": 60,
"public": true
}'
{
"tunnel_id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"sandbox_id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"port": 1,
"protocol": "string",
"url": "https://example.com/webhooks/stateset",
"expires_at": "2026-08-31T14:22:05Z",
"token": "YOUR_API_KEY"
}
Last modified on September 21, 2026