Skip to main content
POST
Create reverse private endpoint
Create a new reverse private endpoint.

Authorizations

Authorization
string
header
required

Use key ID and key secret obtained in ClickHouse Cloud console: https://clickhouse.com/docs/cloud/manage/openapi

Path Parameters

organizationId
string<uuid>
required

ID of the organization that owns the service.

serviceId
string<uuid>
required

ID of the service that owns the Reverse Private Endpoint.

Body

application/json
description
string

Reverse private endpoint description. Maximum length is 255 characters.

Example:

"My reverse private endpoint"

type
enum<string>

Reverse private endpoint type.

Available options:
VPC_ENDPOINT_SERVICE,
VPC_RESOURCE,
MSK_MULTI_VPC,
GCP_PSC_SERVICE_ATTACHMENT
Example:

"VPC_ENDPOINT_SERVICE"

vpcEndpointServiceName
string | null

VPC endpoint service name.

Example:

"com.amazonaws.vpce.us-east-1.vpce-svc-12345678901234567"

vpcResourceConfigurationId
string | null

VPC resource configuration ID. Required for VPC_RESOURCE type.

Example:

"rcfg-12345678901234567"

vpcResourceShareArn
string | null

VPC resource share ARN. Required for VPC_RESOURCE type.

Example:

"arn:aws:ram:us-east-1:123456789012:resource-share/share-12345678901234567"

mskClusterArn
string | null

MSK cluster ARN. Required for MSK_MULTI_VPC type.

Example:

"arn:aws:kafka:us-east-1:123456789012:cluster/my-cluster"

mskAuthentication
enum<string> | null

MSK cluster authentication type. Required for MSK_MULTI_VPC type.

Available options:
SASL_IAM,
SASL_SCRAM
Example:

"SASL_IAM"

gcpServiceAttachment
string | null

Private Preview. GCP PSC service attachment URI. Required for GCP_PSC_SERVICE_ATTACHMENT type. Format: projects/{project}/regions/{region}/serviceAttachments/{name}.

Example:

"projects/my-project/regions/us-central1/serviceAttachments/my-service"

customPrivateDnsMappings
object[]

Optional private DNS names for Reverse Private Endpoint. Can be used as data source destination address. Must be unique across the ClickHouse service. Generally available for Google Private Service Connect (PSC). For AWS PrivateLink (VPC endpoint service and VPC resource), available in Private Preview; contact ClickHouse support to enable it for your service. Not supported for MSK multi-VPC. Supports exact names and leading wildcard names such as *.example.com

Example:

Response

Successful response

status
number

HTTP status code.

Example:

200

requestId
string<uuid>

Unique id assigned to every request. UUIDv4

result
object
Last modified on July 21, 2026