Renew a certificate
const url = 'https://api.krakenkey.io/certs/tls/example/renew';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"csrPem":"-----BEGIN CERTIFICATE REQUEST-----\n...\n-----END CERTIFICATE REQUEST-----"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.krakenkey.io/certs/tls/example/renew \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "csrPem": "-----BEGIN CERTIFICATE REQUEST-----\n...\n-----END CERTIFICATE REQUEST-----" }'Queues a renewal. Without a body the CSR stored at first issuance is used again. With { csrPem } the certificate is renewed with that CSR (for example a new key) and it replaces the stored CSR. For an awaiting_csr certificate, { csrPem } is required and its names must equal requestedNames; the certificate is then issued like a new request (status ‘pending’), and ifDue always treats it as due.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”Certificate ID
Query Parameters
Section titled “Query Parameters”Only renew if the certificate is inside its renewal window (free: 5 days, paid: 30 days before expiry; at least 30 days for connector-managed certificates, which are due once their renewAfter has passed). Otherwise nothing is queued and the response has skipped: true. Default: false (always renew).
Request Body
Section titled “Request Body”object
PEM-encoded CSR to renew with, usually for a new private key. It gets the same checks as a new request, and its names (CN and DNS SANs, case-insensitive) must equal the certificate’s names. It replaces the stored CSR, so later renewals use it too. Not stored when ifDue=true skips the renewal. Required for an awaiting_csr certificate, whose names are its requestedNames; it is then issued for the first time.
Example
-----BEGIN CERTIFICATE REQUEST-----...-----END CERTIFICATE REQUEST-----Responses
Section titled “Responses”IfDue=true and the certificate is not due yet; nothing was queued (skipped: true, reason: ‘not_due’)
Certificate renewal initiated (skipped: false)
Certificate not issued or missing CSR data, invalid CSR, ‘CSR names must match the certificate’, or ‘This certificate is waiting for a CSR’ (awaiting_csr without csrPem)
Viewers cannot renew certificates
Certificate not found
The awaiting_csr certificate was completed by another request meanwhile