Skip to content

Renew a certificate

POST
/certs/tls/{id}/renew
curl --request POST \
--url https://api.krakenkey.io/certs/tls/example/renew \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "csrPem": "-----BEGIN CERTIFICATE REQUEST-----\n...\n-----END CERTIFICATE REQUEST-----" }'

Queues a renewal. Without a body the CSR stored at first issuance is used again. With { csrPem } the certificate is renewed with that CSR (for example a new key) and it replaces the stored CSR. For an awaiting_csr certificate, { csrPem } is required and its names must equal requestedNames; the certificate is then issued like a new request (status ‘pending’), and ifDue always treats it as due.

id
required
string

Certificate ID

ifDue
boolean

Only renew if the certificate is inside its renewal window (free: 5 days, paid: 30 days before expiry; at least 30 days for connector-managed certificates, which are due once their renewAfter has passed). Otherwise nothing is queued and the response has skipped: true. Default: false (always renew).

Media typeapplication/json
object
csrPem

PEM-encoded CSR to renew with, usually for a new private key. It gets the same checks as a new request, and its names (CN and DNS SANs, case-insensitive) must equal the certificate’s names. It replaces the stored CSR, so later renewals use it too. Not stored when ifDue=true skips the renewal. Required for an awaiting_csr certificate, whose names are its requestedNames; it is then issued for the first time.

string
Example
-----BEGIN CERTIFICATE REQUEST-----
...
-----END CERTIFICATE REQUEST-----

IfDue=true and the certificate is not due yet; nothing was queued (skipped: true, reason: ‘not_due’)

Certificate renewal initiated (skipped: false)

Certificate not issued or missing CSR data, invalid CSR, ‘CSR names must match the certificate’, or ‘This certificate is waiting for a CSR’ (awaiting_csr without csrPem)

Viewers cannot renew certificates

Certificate not found

The awaiting_csr certificate was completed by another request meanwhile