Ngrok
for LuumenAI

Read ngrok edges and credentials, then change routing as an approved step

Connect ngrok and Luumen can answer questions about your tunnels without you opening the dashboard: which edge routes exist, what IP restrictions and OIDC settings they carry, who holds tunnel credentials and API keys. When something needs to change — a new route, a fresh credential for an agent — Luumen shows the plan first and, by default, waits for your approval. Authentication is by API key.

The Ngrok toolbox

102 tools: 56 read, 46 write. Reads answer instantly. Writes require approval by default. Everything is logged.

  • ReadGet API KeyGet the details of an API key by ID.
  • ReadGet CredentialsRetrieve detailed information about a tunnel authtoken credential by ID.
  • ReadGet Edge Route Backend ModuleRetrieves the backend module configuration for an HTTPS edge route.
  • ReadGet Edge Route Circuit Breaker ModuleRetrieve the circuit breaker module configuration for a specific HTTPS edge route.
  • ReadGet Edge Route Compression ModuleRetrieves the compression module configuration for a specific HTTPS edge route.
  • ReadGet Edge Route IP Restriction ModuleRetrieves the IP restriction module configuration for a specific HTTPS edge route.
  • ReadGet Edge Route OIDC ModuleRetrieves the OIDC (OpenID Connect) module configuration for a specific HTTPS edge route.
  • ReadGet Edge Route Request Headers ModuleRetrieves the request headers module configuration for a specific HTTPS edge route.
  • ReadGet Edge Route Response Headers ModuleGet the response headers module configuration for an HTTPS edge route.
  • ReadGet Edge Route SAML ModuleRetrieves the SAML authentication module configuration for a specific HTTPS edge route.
  • ReadGet Edge Route Traffic PolicyRetrieves the Traffic Policy module configuration for a specific HTTPS edge route.
  • ReadGet Edge Route User Agent Filter ModuleRetrieves the user agent filter module configuration for a specific HTTPS edge route.
  • ReadGet Edge Route Webhook Verification ModuleRetrieves the webhook verification module configuration for an HTTPS edge route.
  • ReadGet Edge Route WebSocket TCP Converter ModuleRetrieves the WebSocket TCP Converter module configuration for a specific HTTPS edge route.
  • ReadGet EndpointGet the status of an endpoint by ID.
  • ReadGet Event SourceGet an event source by type for a specific event subscription.
  • ReadGet HTTPS EdgeGet the details of an HTTPS edge by ID.
  • ReadGet HTTPS Edge Mutual TLS ModuleRetrieves the mutual TLS module configuration for an HTTPS edge.
  • ReadGet HTTPS Edge RouteRetrieves detailed information about a specific HTTPS edge route by its ID.
  • ReadGet IP Restriction DetailsRetrieves detailed information about a specific IP restriction by its ID.
  • ReadGet Reserved DomainGet the details of a reserved domain by ID.
  • ReadGet SecretRetrieve detailed information about a vault secret by ID.
  • ReadGet Secrets by VaultGet all secrets in a vault by vault ID.
  • ReadGet SSH CredentialsRetrieve detailed information about an SSH credential by ID.
  • ReadGet VaultGet the details of a vault by ID.
  • ReadList Agent IngressesList all Agent Ingresses owned by this account.
  • ReadList API KeysThis tool lists all API keys owned by the user.
  • ReadList Bot UsersList all bot users on this ngrok account.
  • ReadList Certificate AuthoritiesList all certificate authorities on this account.
  • ReadList Tunnel CredentialsList all tunnel authtoken credentials on the ngrok account.
  • ReadList All EndpointsList all active endpoints on the ngrok account.
  • ReadList Event DestinationsList all Event Destinations on the ngrok account.
  • ReadList Event SubscriptionsList all event subscriptions on the ngrok account.
  • ReadList Event Subscription SourcesList the types for which this event subscription will trigger.
  • ReadList Failover BackendsList all failover backends on this account.
  • ReadList HTTP Response BackendsList all HTTP response backends on the account.
  • ReadList HTTPS EdgesLists all HTTPS Edges in your ngrok account.
  • ReadList IP PoliciesList all IP policies on this account.
  • ReadList IP Policy RulesThis tool lists all IP policy rules associated with your ngrok account.
  • ReadList IP RestrictionsLists all IP restrictions configured on the ngrok account.
  • ReadList Reserved AddressesList all reserved addresses on this account.
  • ReadList Reserved DomainsList all reserved domains on this account.
  • ReadList Service UsersList all service users on this ngrok account.
  • ReadList SSH Certificate AuthoritiesList all SSH Certificate Authorities on this account.
  • ReadList SSH CredentialsList all SSH credentials on the ngrok account.
  • ReadList SSH Host CertificatesList all SSH Host Certificates issued on this account.
  • ReadList SSH User CertificatesList all SSH user certificates on the ngrok account.
  • ReadList Static BackendsList all static backends on the account.
  • ReadList TCP EdgesLists all TCP Edges in your ngrok account.
  • ReadList TLS CertificatesList all TLS certificates on the ngrok account.
  • ReadList TLS EdgesLists all TLS Edges in your ngrok account.
  • ReadList Active TunnelsList all active tunnels in the ngrok account.
  • ReadList Tunnel SessionsList all online tunnel sessions running on this account.
  • ReadList VaultsList all vaults owned by the ngrok account.
  • ReadList Vault SecretsList all vault secrets owned by the ngrok account.
  • ReadList Weighted BackendsList all weighted backends on the ngrok account.
  • WriteCreate API KeyCreates a new API key for authenticating with the ngrok API. Approval by default
  • WriteCreate Tunnel CredentialCreates a new tunnel authtoken credential for authenticating ngrok agents. Approval by default
  • WriteCreate EndpointCreate a cloud endpoint on the ngrok account. Approval by default
  • WriteCreate Event SourceAdd a new event source to an event subscription. Approval by default
  • WriteCreate Event SubscriptionCreates a new event subscription in ngrok. Approval by default
  • WriteCreate HTTPS EdgeCreates a new HTTPS edge in your ngrok account. Approval by default
  • WriteCreate HTTPS Edge RouteCreates a new route on an HTTPS edge in ngrok. Approval by default
  • WriteCreate SSH CredentialCreates a new SSH credential from an uploaded public SSH key. Approval by default
  • WriteCreate VaultCreates a new vault in your ngrok account. Approval by default
  • WriteCreate Vault SecretCreate a new secret in an ngrok vault for secure storage of sensitive data like API keys, passwords, or tokens. Approval by default
  • WriteDelete API KeyDelete an API key by its ID. Approval by default
  • WriteDelete CredentialsDelete a tunnel authtoken credential by ID. Approval by default
  • WriteDelete HTTPS Edge Route Circuit Breaker ModuleDelete the Circuit Breaker module from an HTTPS Edge Route. Approval by default
  • WriteDelete Edge Route Compression ModuleDelete the compression module from an HTTPS edge route. Approval by default
  • WriteDelete Edge Route Request Headers ModuleDelete the request headers module from an HTTPS edge route. Approval by default
  • WriteDelete Edge Route Response Headers ModuleDelete the response headers module from an HTTPS edge route. Approval by default
  • WriteDelete Edge Route SAML ModuleDelete the SAML module configuration from an HTTPS edge route. Approval by default
  • WriteDelete Edge Route User Agent Filter ModuleDelete the user agent filter module from an HTTPS edge route. Approval by default
  • WriteDelete Edge Route Webhook Verification ModuleDelete the webhook verification module from an HTTPS edge route. Approval by default
  • WriteDelete Edge Route WebSocket TCP Converter ModuleDelete the WebSocket TCP converter module from an HTTPS edge route. Approval by default
  • WriteDelete EndpointDelete an endpoint by ID. Approval by default
  • WriteDelete Event SourceDelete an event source from an event subscription. Approval by default
  • WriteDelete Event SubscriptionDelete an event subscription by ID. Approval by default
  • WriteDelete HTTPS EdgeDelete an HTTPS edge by ID. Approval by default
  • WriteDelete HTTPS Edge RouteDelete an HTTPS edge route by ID. Approval by default
  • WriteDelete Reserved Domain CertificateDetach the certificate attached to a reserved domain. Approval by default
  • WriteDelete Reserved Domain Certificate Management PolicyDetach the certificate management policy from a reserved domain. Approval by default
  • WriteDelete SecretDelete a vault secret by ID. Approval by default
  • WriteDelete SSH CredentialsDelete an SSH credential by ID. Approval by default
  • WriteDelete VaultDelete a vault by ID. Approval by default
  • WriteReplace Edge Route Circuit Breaker ModuleReplaces the circuit breaker module configuration on an HTTPS edge route. Approval by default
  • WriteReplace Edge Route Compression ModuleReplaces the compression module configuration for an HTTPS edge route. Approval by default
  • WriteReplace Edge Route Request Headers ModuleReplaces the request headers module configuration for an HTTPS edge route. Approval by default
  • WriteReplace Edge Route Response Headers ModuleReplaces the response headers module configuration for an HTTPS edge route. Approval by default
  • WriteReplace Edge Route Traffic PolicyReplaces the traffic policy module on an HTTPS edge route. Approval by default
  • WriteReplace Edge Route User Agent Filter ModuleReplaces the user agent filter module configuration for an HTTPS edge route. Approval by default
  • WriteReplace Edge Route Webhook Verification ModuleReplaces the webhook verification module configuration for an HTTPS edge route. Approval by default
  • WriteUpdate API KeyUpdates attributes of an API key by ID. Approval by default
  • WriteUpdate CredentialsUpdate attributes of a tunnel authtoken credential by ID. Approval by default
  • WriteUpdate EndpointUpdate an Endpoint by ID, currently available only for cloud endpoints. Approval by default
  • WriteUpdate Event SubscriptionUpdate attributes of an event subscription by ID. Approval by default
  • WriteUpdate HTTPS Edge RouteUpdate an HTTPS edge route by ID. Approval by default
  • WriteUpdate Reserved DomainUpdate the attributes of a reserved domain by ID. Approval by default
  • WriteUpdate SecretUpdate a vault secret by ID. Approval by default
  • WriteUpdate SSH CredentialUpdate attributes of an SSH credential by ID. Approval by default
  • WriteUpdate VaultUpdate attributes of a vault by ID. Approval by default

One prompt, start to finish

What a governed Ngrok run looks like inside Luumen.

Questions

How does LuumenAI connect to Ngrok?

Authorize once with API token. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.

Can LuumenAI change things in Ngrok on its own?

Read actions answer immediately. Anything that writes — create api key, create tunnel credential, create endpoint, create event source, and more — is shown as a plan and requires approval by default, including the 20 actions classified as destructive. Administrators configure that per tool, so you decide exactly which actions can ever run unattended.

Who gets access to the integration?

You decide. Actions are granted per agent, skill, and team, and per environment — production is not staging. Read access can be broad while writes stay narrow.

Is there an audit trail?

Every call to Ngrok — read or write, approved or declined — is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.

Put Ngrok to work with Luumen

Connect in minutes. Every action scoped, approved, and audited from day one.