All Products
Search
Document Center

VPN Gateway:API overview

Last Updated:Jul 07, 2026

API standards and multilingual preset SDKs

The OpenAPI of this product (Vpc/2016-04-28) uses the RPC signature style. We have encapsulated SDKs for common programming languages for developers. Developers can download the SDK to directly call this product's OpenAPI without worrying about technical details. If the existing SDK does not meet your needs, you can use the signature mechanism for self-signing integration. Since the details of self-signing are very complex, it may take around 5 business days. Therefore, we recommend joining our DingTalk service group (147535001692) and conducting signature integration under expert guidance.

Before using the API, you need to prepare your identity account and access key (AccessKey) to effectively access the API through client tools (such as SDK and CLI). For details, see Obtain an AccessKey.

Custom signature scenarios

If your business scenario has special requirements and you need to integrate the API through self-signing, we recommend consulting our technical support team first (DingTalk service group: 147535001692) to obtain professional guidance and ensure efficient integration.

Account and security preparation

Alibaba Cloud accounts have full administrative permissions over all resources. Once an AccessKey is compromised, all associated resources will be at risk of unauthorized access. To ensure security, it is recommended to create a RAM user with only API access permissions and configure its AccessKey, while configuring RAM policies based on the principle of least privilege (PoLP). Use the Alibaba Cloud account only in specific scenarios where Alibaba Cloud account permissions are explicitly required.

VPN gateway

API

Title

Description

DescribeVpnGateway Query details of a specified VPN gateway Queries the details of a specified VPN gateway by calling the DescribeVpnGateway operation.
DescribeVpnGateways Query created VPN gateways Queries VPN gateways created in a specified region.
DescribeVpnGatewayAvailableZones Query zones that support iPsec-VPN connection deployment in a specified region Queries the list of zones that support IPsec-VPN connection deployment in a specified region by calling the DescribeVpnGatewayAvailableZones operation.

Customer gateway

API

Title

Description

CreateVpnConnection Create an IPsec-VPN connection Invoke the CreateVpnConnection API to create an IPsec-VPN connection.
DescribeVpnConnection DescribeVpnConnection Queries the detailed information about an IPsec-VPN connection.
DescribeVpnConnections Query created iPsec-VPN connections Queries information about IPsec-VPN connections.
DownloadVpnConnectionConfig DownloadVpnConnectionConfig Queries the configuration of an IPsec-VPN connection.
VPN gateway destination-based route VPN gateway destination-based route
CreateVpnRouteEntry Create a destination route Creates a destination route for a VPN gateway instance. After the destination route is created, the VPN gateway instance matches the destination IP address of traffic against destination routes and forwards the traffic based on the matched destination route.
VPN gateway policy-based route VPN gateway policy-based route
CreateVpnPbrRouteEntry CreateVpnPbrRouteEntry Creates a policy-based route for a VPN gateway.

Bind to a VPN gateway instance

API

Title

Description

CreateVpnAttachment Create an IPsec-VPN Connection Invoke the CreateVpnAttachment API to create an IPsec-VPN connection for attaching a transit router instance.
CreateVcoRouteEntry CreateVcoRouteEntry Adds a destination-based route for an IPsec-VPN connection.
DescribeVpnAttachments Query configuration information of iPsec-VPN connections associated with transit router instances Queries the configuration information of IPsec-VPN connections that are associated with transit router instances.
Destination route Destination route
Policy route Policy route