Get started with KrakenKey
This guide goes from a new account to an issued TLS certificate. It usually takes under 10 minutes, most of it waiting on DNS and issuance.
Before you begin
Section titled “Before you begin”You need:
- A domain name you own (e.g.
example.com) - Access to your domain’s DNS settings (Cloudflare, Route 53, Namecheap, etc.)
Issue your first certificate
Section titled “Issue your first certificate”-
Create an account
Section titled “Create an account”Go to app.krakenkey.io and click Sign Up. After you register, you land on the dashboard.
-
Add your domain
Section titled “Add your domain”In the dashboard, scroll to Domain Management, enter your domain, and click Add Domain. Or via the API:
Terminal window # Add a domaincurl -X POST https://api.krakenkey.io/domains \-H "Authorization: Bearer YOUR_TOKEN" \-H "Content-Type: application/json" \-d '{"hostname": "example.com"}'The response includes a
verificationCodeyou’ll need in the next step. -
Add DNS records
Section titled “Add DNS records”Add two DNS records. The dashboard shows the exact values for your domain; the examples below show their shape.
Record 1: TXT, ownership verification. Proves you control the domain. This record must stay in your DNS permanently.
Type Name Value TTL TXT@krakenkey-site-verification=abc123...Auto Record 2: CNAME, ACME challenge delegation. Lets KrakenKey respond to Let’s Encrypt DNS-01 challenges on your behalf, so issuing and renewing certificates needs no further DNS changes.
Type Name Target TTL CNAME_acme-challengeexample-com.acme.krakenkey.ioAuto The CNAME target replaces dots with dashes in your hostname:
example.combecomesexample-com.acme.krakenkey.io. -
Verify domain ownership
Section titled “Verify domain ownership”Wait 1–5 minutes for DNS propagation, then click Verify Now in the dashboard. You can check propagation with:
Terminal window dig TXT example.com +shortOr verify via the API:
Terminal window curl -X POST https://api.krakenkey.io/domains/DOMAIN_ID/verify \-H "Authorization: Bearer YOUR_TOKEN"Once verified, the domain status changes to Verified and you can start issuing certificates.
-
Generate a Certificate Signing Request
Section titled “Generate a Certificate Signing Request”A CSR tells the certificate authority what domain(s) to include in the certificate. You have two options.
In-browser generator. The dashboard includes a CSR generator that uses the WebCrypto API. Your private key is generated in your browser and never leaves your device. Fill in the form, click generate, and the CSR is ready to submit.
OpenSSL. Generate a CSR on your own machine:
Terminal window openssl req -new -newkey rsa:2048 \-nodes -keyout key.pem \-out csr.pem \-subj "/CN=example.com"The KrakenKey CLI can also generate the key and CSR locally and submit them in one command.
-
Submit CSR and download your certificate
Section titled “Submit CSR and download your certificate”Paste your CSR PEM in the dashboard and click Submit, or use the API:
Terminal window # Submit CSRcurl -X POST https://api.krakenkey.io/certs/tls \-H "Authorization: Bearer YOUR_TOKEN" \-H "Content-Type: application/json" \-d '{"csrPem": "-----BEGIN CERTIFICATE REQUEST-----\n...\n-----END CERTIFICATE REQUEST-----"}'KrakenKey creates a DNS-01 challenge record, Let’s Encrypt validates it, and your certificate is issued, typically in about 4 minutes.
Terminal window # Check status and downloadcurl https://api.krakenkey.io/certs/tls/CERT_ID \-H "Authorization: Bearer YOUR_TOKEN"When
statusis"issued", the response includes your signed certificate PEM. Download it from the dashboard or copy it from the API response.
Using an API key
Section titled “Using an API key”For programmatic access, generate an API key from the dashboard under your profile. API keys use the same Authorization: Bearer header as session tokens:
# Generate an API key from the dashboard, then:curl https://api.krakenkey.io/certs/tls \ -H "Authorization: Bearer kk_your_api_key_here"See the API reference for the full endpoint documentation.
With the CLI, krakenkey auth login --web creates and stores a key for you after you approve the login in your browser.
What’s next
Section titled “What’s next”- To add more domains, repeat steps 2–4 for each one.
- To issue certificates from a deployment pipeline, use the REST API or the KrakenKey CLI.
- For a wildcard certificate, submit a CSR with
*.example.comas the common name. DNS-01 supports wildcards. - To deploy on Azure App Service or Container Apps, see Azure Key Vault.