Request a new TLS certificate
const url = 'https://api.krakenkey.io/certs/tls';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"csrPem":"-----BEGIN CERTIFICATE REQUEST-----\n...\n-----END CERTIFICATE REQUEST-----","names":["example.com","www.example.com"],"managedBy":"connector"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.krakenkey.io/certs/tls \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "csrPem": "-----BEGIN CERTIFICATE REQUEST-----\n...\n-----END CERTIFICATE REQUEST-----", "names": [ "example.com", "www.example.com" ], "managedBy": "connector" }'Send csrPem to issue a certificate now (status pending). Or send names with managedBy: 'connector' to create a certificate a connector will issue with its own key (status awaiting_csr); nothing is sent to the CA until the connector posts a CSR to POST /certs/tls/:id/renew. Exactly one of csrPem and names.
Authorizations
Section titled “Authorizations”Request Bodyrequired
Section titled “Request Bodyrequired”object
PEM-encoded Certificate Signing Request. Required unless names is given.
Example
-----BEGIN CERTIFICATE REQUEST-----...-----END CERTIFICATE REQUEST-----Instead of csrPem: the DNS names (wildcards allowed) of a certificate a connector will issue with its own key. Needs managedBy: 'connector'. Creates the certificate with status awaiting_csr; the connector completes it with POST /certs/tls/:id/renew and a CSR for exactly these names. Names get the same domain ownership checks as CSR names.
Example
[ "example.com", "www.example.com"]Required with names, and must be ‘connector’. Not accepted with csrPem; use PATCH /certs/tls/:id to change it later.
Responses
Section titled “Responses”Certificate request submitted: { id, status: ‘pending’ }, or { id, status: ‘awaiting_csr’ } for a request by names
Invalid CSR or names, both or neither of csrPem and names, names without managedBy: ‘connector’, or a name outside the account’s verified domains
Unauthorized
Plan limit reached (total active, monthly or concurrent pending certificates; requests by names skip the concurrent pending limit)
Viewers cannot request certificates; API keys limited to certificates cannot request new ones, and keys limited to domains only for names under them
An identical certificate request (same CSR, or same set of names) is already being processed. Duplicate requests within 15 minutes return the original certificate instead of creating a new one.