Skip to content

Request a new TLS certificate

POST
/certs/tls
curl --request POST \
--url https://api.krakenkey.io/certs/tls \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "csrPem": "-----BEGIN CERTIFICATE REQUEST-----\n...\n-----END CERTIFICATE REQUEST-----", "names": [ "example.com", "www.example.com" ], "managedBy": "connector" }'

Send csrPem to issue a certificate now (status pending). Or send names with managedBy: 'connector' to create a certificate a connector will issue with its own key (status awaiting_csr); nothing is sent to the CA until the connector posts a CSR to POST /certs/tls/:id/renew. Exactly one of csrPem and names.

Media typeapplication/json
object
csrPem

PEM-encoded Certificate Signing Request. Required unless names is given.

string
Example
-----BEGIN CERTIFICATE REQUEST-----
...
-----END CERTIFICATE REQUEST-----
names

Instead of csrPem: the DNS names (wildcards allowed) of a certificate a connector will issue with its own key. Needs managedBy: 'connector'. Creates the certificate with status awaiting_csr; the connector completes it with POST /certs/tls/:id/renew and a CSR for exactly these names. Names get the same domain ownership checks as CSR names.

Array<string>
<= 100 items
Example
[
"example.com",
"www.example.com"
]
managedBy

Required with names, and must be ‘connector’. Not accepted with csrPem; use PATCH /certs/tls/:id to change it later.

string
Allowed values: connector

Certificate request submitted: { id, status: ‘pending’ }, or { id, status: ‘awaiting_csr’ } for a request by names

Invalid CSR or names, both or neither of csrPem and names, names without managedBy: ‘connector’, or a name outside the account’s verified domains

Unauthorized

Plan limit reached (total active, monthly or concurrent pending certificates; requests by names skip the concurrent pending limit)

Viewers cannot request certificates; API keys limited to certificates cannot request new ones, and keys limited to domains only for names under them

An identical certificate request (same CSR, or same set of names) is already being processed. Duplicate requests within 15 minutes return the original certificate instead of creating a new one.