Skip to content

Get started with KrakenKey

This guide goes from a new account to an issued TLS certificate. It usually takes under 10 minutes, most of it waiting on DNS and issuance.

You need:

  • A domain name you own (e.g. example.com)
  • Access to your domain’s DNS settings (Cloudflare, Route 53, Namecheap, etc.)
  1. Go to app.krakenkey.io and click Sign Up. After you register, you land on the dashboard.

  2. In the dashboard, scroll to Domain Management, enter your domain, and click Add Domain. Or via the API:

    Terminal window
    # Add a domain
    curl -X POST https://api.krakenkey.io/domains \
    -H "Authorization: Bearer YOUR_TOKEN" \
    -H "Content-Type: application/json" \
    -d '{"hostname": "example.com"}'

    The response includes a verificationCode you’ll need in the next step.

  3. Add two DNS records. The dashboard shows the exact values for your domain; the examples below show their shape.

    Record 1: TXT, ownership verification. Proves you control the domain. This record must stay in your DNS permanently.

    Type Name Value TTL
    TXT @ krakenkey-site-verification=abc123... Auto

    Record 2: CNAME, ACME challenge delegation. Lets KrakenKey respond to Let’s Encrypt DNS-01 challenges on your behalf, so issuing and renewing certificates needs no further DNS changes.

    Type Name Target TTL
    CNAME _acme-challenge example-com.acme.krakenkey.io Auto

    The CNAME target replaces dots with dashes in your hostname: example.com becomes example-com.acme.krakenkey.io.

  4. Wait 1–5 minutes for DNS propagation, then click Verify Now in the dashboard. You can check propagation with:

    Terminal window
    dig TXT example.com +short

    Or verify via the API:

    Terminal window
    curl -X POST https://api.krakenkey.io/domains/DOMAIN_ID/verify \
    -H "Authorization: Bearer YOUR_TOKEN"

    Once verified, the domain status changes to Verified and you can start issuing certificates.

  5. A CSR tells the certificate authority what domain(s) to include in the certificate. You have two options.

    In-browser generator. The dashboard includes a CSR generator that uses the WebCrypto API. Your private key is generated in your browser and never leaves your device. Fill in the form, click generate, and the CSR is ready to submit.

    OpenSSL. Generate a CSR on your own machine:

    Terminal window
    openssl req -new -newkey rsa:2048 \
    -nodes -keyout key.pem \
    -out csr.pem \
    -subj "/CN=example.com"

    The KrakenKey CLI can also generate the key and CSR locally and submit them in one command.

  6. Paste your CSR PEM in the dashboard and click Submit, or use the API:

    Terminal window
    # Submit CSR
    curl -X POST https://api.krakenkey.io/certs/tls \
    -H "Authorization: Bearer YOUR_TOKEN" \
    -H "Content-Type: application/json" \
    -d '{"csrPem": "-----BEGIN CERTIFICATE REQUEST-----\n...\n-----END CERTIFICATE REQUEST-----"}'

    KrakenKey creates a DNS-01 challenge record, Let’s Encrypt validates it, and your certificate is issued, typically in about 4 minutes.

    Terminal window
    # Check status and download
    curl https://api.krakenkey.io/certs/tls/CERT_ID \
    -H "Authorization: Bearer YOUR_TOKEN"

    When status is "issued", the response includes your signed certificate PEM. Download it from the dashboard or copy it from the API response.

For programmatic access, generate an API key from the dashboard under your profile. API keys use the same Authorization: Bearer header as session tokens:

Terminal window
# Generate an API key from the dashboard, then:
curl https://api.krakenkey.io/certs/tls \
-H "Authorization: Bearer kk_your_api_key_here"

See the API reference for the full endpoint documentation.

With the CLI, krakenkey auth login --web creates and stores a key for you after you approve the login in your browser.

  • To add more domains, repeat steps 2–4 for each one.
  • To issue certificates from a deployment pipeline, use the REST API or the KrakenKey CLI.
  • For a wildcard certificate, submit a CSR with *.example.com as the common name. DNS-01 supports wildcards.
  • To deploy on Azure App Service or Container Apps, see Azure Key Vault.