Read ngrok edges and credentials, then change routing as an approved step
Connect ngrok and Luumen can answer questions about your tunnels without you opening the dashboard: which edge routes exist, what IP restrictions and OIDC settings they carry, who holds tunnel credentials and API keys. When something needs to change — a new route, a fresh credential for an agent — Luumen shows the plan first and, by default, waits for your approval. Authentication is by API key.
102 tools: 56 read, 46 write. Reads answer instantly. Writes require approval by default. Everything is logged.
ReadGet API KeyGet the details of an API key by ID.
ReadGet CredentialsRetrieve detailed information about a tunnel authtoken credential by ID.
ReadGet Edge Route Backend ModuleRetrieves the backend module configuration for an HTTPS edge route.
ReadGet Edge Route Circuit Breaker ModuleRetrieve the circuit breaker module configuration for a specific HTTPS edge route.
ReadGet Edge Route Compression ModuleRetrieves the compression module configuration for a specific HTTPS edge route.
ReadGet Edge Route IP Restriction ModuleRetrieves the IP restriction module configuration for a specific HTTPS edge route.
ReadGet Edge Route OIDC ModuleRetrieves the OIDC (OpenID Connect) module configuration for a specific HTTPS edge route.
ReadGet Edge Route Request Headers ModuleRetrieves the request headers module configuration for a specific HTTPS edge route.
ReadGet Edge Route Response Headers ModuleGet the response headers module configuration for an HTTPS edge route.
ReadGet Edge Route SAML ModuleRetrieves the SAML authentication module configuration for a specific HTTPS edge route.
ReadGet Edge Route Traffic PolicyRetrieves the Traffic Policy module configuration for a specific HTTPS edge route.
ReadGet Edge Route User Agent Filter ModuleRetrieves the user agent filter module configuration for a specific HTTPS edge route.
ReadGet Edge Route Webhook Verification ModuleRetrieves the webhook verification module configuration for an HTTPS edge route.
ReadGet Edge Route WebSocket TCP Converter ModuleRetrieves the WebSocket TCP Converter module configuration for a specific HTTPS edge route.
ReadGet EndpointGet the status of an endpoint by ID.
ReadGet Event SourceGet an event source by type for a specific event subscription.
ReadGet HTTPS EdgeGet the details of an HTTPS edge by ID.
ReadGet HTTPS Edge Mutual TLS ModuleRetrieves the mutual TLS module configuration for an HTTPS edge.
ReadGet HTTPS Edge RouteRetrieves detailed information about a specific HTTPS edge route by its ID.
ReadGet IP Restriction DetailsRetrieves detailed information about a specific IP restriction by its ID.
ReadGet Reserved DomainGet the details of a reserved domain by ID.
ReadGet SecretRetrieve detailed information about a vault secret by ID.
ReadGet Secrets by VaultGet all secrets in a vault by vault ID.
ReadGet SSH CredentialsRetrieve detailed information about an SSH credential by ID.
ReadGet VaultGet the details of a vault by ID.
ReadList Agent IngressesList all Agent Ingresses owned by this account.
ReadList API KeysThis tool lists all API keys owned by the user.
ReadList Bot UsersList all bot users on this ngrok account.
ReadList Certificate AuthoritiesList all certificate authorities on this account.
ReadList Tunnel CredentialsList all tunnel authtoken credentials on the ngrok account.
ReadList All EndpointsList all active endpoints on the ngrok account.
ReadList Event DestinationsList all Event Destinations on the ngrok account.
ReadList Event SubscriptionsList all event subscriptions on the ngrok account.
ReadList Event Subscription SourcesList the types for which this event subscription will trigger.
ReadList Failover BackendsList all failover backends on this account.
ReadList HTTP Response BackendsList all HTTP response backends on the account.
ReadList HTTPS EdgesLists all HTTPS Edges in your ngrok account.
ReadList IP PoliciesList all IP policies on this account.
ReadList IP Policy RulesThis tool lists all IP policy rules associated with your ngrok account.
ReadList IP RestrictionsLists all IP restrictions configured on the ngrok account.
ReadList Reserved AddressesList all reserved addresses on this account.
ReadList Reserved DomainsList all reserved domains on this account.
ReadList Service UsersList all service users on this ngrok account.
ReadList SSH Certificate AuthoritiesList all SSH Certificate Authorities on this account.
ReadList SSH CredentialsList all SSH credentials on the ngrok account.
ReadList SSH Host CertificatesList all SSH Host Certificates issued on this account.
ReadList SSH User CertificatesList all SSH user certificates on the ngrok account.
ReadList Static BackendsList all static backends on the account.
ReadList TCP EdgesLists all TCP Edges in your ngrok account.
ReadList TLS CertificatesList all TLS certificates on the ngrok account.
ReadList TLS EdgesLists all TLS Edges in your ngrok account.
ReadList Active TunnelsList all active tunnels in the ngrok account.
ReadList Tunnel SessionsList all online tunnel sessions running on this account.
ReadList VaultsList all vaults owned by the ngrok account.
ReadList Vault SecretsList all vault secrets owned by the ngrok account.
ReadList Weighted BackendsList all weighted backends on the ngrok account.
WriteCreate API KeyCreates a new API key for authenticating with the ngrok API. Approval by default
WriteCreate Tunnel CredentialCreates a new tunnel authtoken credential for authenticating ngrok agents. Approval by default
WriteCreate EndpointCreate a cloud endpoint on the ngrok account. Approval by default
WriteCreate Event SourceAdd a new event source to an event subscription. Approval by default
WriteCreate Event SubscriptionCreates a new event subscription in ngrok. Approval by default
WriteCreate HTTPS EdgeCreates a new HTTPS edge in your ngrok account. Approval by default
WriteCreate HTTPS Edge RouteCreates a new route on an HTTPS edge in ngrok. Approval by default
WriteCreate SSH CredentialCreates a new SSH credential from an uploaded public SSH key. Approval by default
WriteCreate VaultCreates a new vault in your ngrok account. Approval by default
WriteCreate Vault SecretCreate a new secret in an ngrok vault for secure storage of sensitive data like API keys, passwords, or tokens. Approval by default
WriteDelete API KeyDelete an API key by its ID. Approval by default
WriteDelete CredentialsDelete a tunnel authtoken credential by ID. Approval by default
WriteDelete HTTPS Edge Route Circuit Breaker ModuleDelete the Circuit Breaker module from an HTTPS Edge Route. Approval by default
WriteDelete Edge Route Compression ModuleDelete the compression module from an HTTPS edge route. Approval by default
WriteDelete Edge Route Request Headers ModuleDelete the request headers module from an HTTPS edge route. Approval by default
WriteDelete Edge Route Response Headers ModuleDelete the response headers module from an HTTPS edge route. Approval by default
WriteDelete Edge Route SAML ModuleDelete the SAML module configuration from an HTTPS edge route. Approval by default
WriteDelete Edge Route User Agent Filter ModuleDelete the user agent filter module from an HTTPS edge route. Approval by default
WriteDelete Edge Route Webhook Verification ModuleDelete the webhook verification module from an HTTPS edge route. Approval by default
WriteDelete Edge Route WebSocket TCP Converter ModuleDelete the WebSocket TCP converter module from an HTTPS edge route. Approval by default
WriteDelete EndpointDelete an endpoint by ID. Approval by default
WriteDelete Event SourceDelete an event source from an event subscription. Approval by default
WriteDelete Event SubscriptionDelete an event subscription by ID. Approval by default
WriteDelete HTTPS EdgeDelete an HTTPS edge by ID. Approval by default
WriteDelete HTTPS Edge RouteDelete an HTTPS edge route by ID. Approval by default
WriteDelete Reserved Domain CertificateDetach the certificate attached to a reserved domain. Approval by default
WriteDelete Reserved Domain Certificate Management PolicyDetach the certificate management policy from a reserved domain. Approval by default
WriteDelete SecretDelete a vault secret by ID. Approval by default
WriteDelete SSH CredentialsDelete an SSH credential by ID. Approval by default
WriteDelete VaultDelete a vault by ID. Approval by default
WriteReplace Edge Route Circuit Breaker ModuleReplaces the circuit breaker module configuration on an HTTPS edge route. Approval by default
WriteReplace Edge Route Compression ModuleReplaces the compression module configuration for an HTTPS edge route. Approval by default
WriteReplace Edge Route Request Headers ModuleReplaces the request headers module configuration for an HTTPS edge route. Approval by default
WriteReplace Edge Route Response Headers ModuleReplaces the response headers module configuration for an HTTPS edge route. Approval by default
WriteReplace Edge Route Traffic PolicyReplaces the traffic policy module on an HTTPS edge route. Approval by default
WriteReplace Edge Route User Agent Filter ModuleReplaces the user agent filter module configuration for an HTTPS edge route. Approval by default
WriteReplace Edge Route Webhook Verification ModuleReplaces the webhook verification module configuration for an HTTPS edge route. Approval by default
WriteUpdate API KeyUpdates attributes of an API key by ID. Approval by default
WriteUpdate CredentialsUpdate attributes of a tunnel authtoken credential by ID. Approval by default
WriteUpdate EndpointUpdate an Endpoint by ID, currently available only for cloud endpoints. Approval by default
WriteUpdate Event SubscriptionUpdate attributes of an event subscription by ID. Approval by default
WriteUpdate HTTPS Edge RouteUpdate an HTTPS edge route by ID. Approval by default
WriteUpdate Reserved DomainUpdate the attributes of a reserved domain by ID. Approval by default
WriteUpdate SecretUpdate a vault secret by ID. Approval by default
WriteUpdate SSH CredentialUpdate attributes of an SSH credential by ID. Approval by default
WriteUpdate VaultUpdate attributes of a vault by ID. Approval by default
One prompt, start to finish
What a governed Ngrok run looks like inside Luumen.
Questions
How does LuumenAI connect to Ngrok?
Authorize once with API token. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.
Can LuumenAI change things in Ngrok on its own?
Read actions answer immediately. Anything that writes — create api key, create tunnel credential, create endpoint, create event source, and more — is shown as a plan and requires approval by default, including the 20 actions classified as destructive. Administrators configure that per tool, so you decide exactly which actions can ever run unattended.
Who gets access to the integration?
You decide. Actions are granted per agent, skill, and team, and per environment — production is not staging. Read access can be broad while writes stay narrow.
Is there an audit trail?
Every call to Ngrok — read or write, approved or declined — is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.