SSL Certificates

API usage instructions for SSL certificate management.

GET List SSL Certificates

/api/v1/sites/SITE_UUID/ssl-certificates

To list all SSL certificates for a site, send a GET request to /api/v1/sites/SITE_UUID/ssl-certificates.

POST Create a Let’s Encrypt OR ZeroSSL Certificate for a Site

/api/v1/sites/SITE_UUID/ssl-certificates/acme-supported-ca

To create a new Let’s Encrypt/ZeroSSL certificate, send a POST request to /api/v1/sites/SITE_UUID/ssl-certificates/acme-supported-ca.

Set provider to zerossl for a ZeroSSL certificate or letsencrypt for a Let’s Encrypt certificate.

"provider": "zerossl"

OR

"provider": "letsencrypt"

POST Create a Custom SSL Certificate for a Site

/api/v1/sites/SITE_UUID/ssl-certificates/custom-ssl

To create a new custom certificate, send a POST request to /api/v1/sites/SITE_UUID/ssl-certificates/custom-ssl.

If you run into any errors, such as {"error":{"code":"internal_error","message":"An unexpected error occurred."}}, with the above request, please send a request using the command below:

POST Create a Custom SSL Certificate (form-encoded)

/api/v1/sites/SITE_UUID/ssl-certificates/custom-ssl

Form-encoded fallback when the JSON custom SSL request returns an internal error.

POST Create CSR

/api/v1/sites/SITE_UUID/ssl-certificates/csr

To create your own certificate signing request (CSR) to use with an SSL certificate, send a POST request to /api/v1/sites/SITE_UUID/ssl-certificates/csr.

country is required. Use a 2-letter ISO 3166-1 country code (for example US or NP ). Do not send the full country name. You can also find the country code list here.

To use a certificate from a CA, send a request to create a CSR, then create a new custom SSL certificate. The API returns the private key only in the create-CSR response. If you already have a certificate and private key, skip the CSR and install the custom certificate directly.

PATCH Update a Custom SSL Certificate

/api/v1/sites/SITE_UUID/ssl-certificates/custom-ssl/SSL_UUID

To update an existing custom SSL certificate, send a PATCH request to /api/v1/sites/SITE_UUID/ssl-certificates/custom-ssl/SSL_UUID. Only for a custom certificate. certificate and privateKey are required. domains is optional.

PATCH Update a Let’s Encrypt OR ZeroSSL Certificate

/api/v1/sites/SITE_UUID/ssl-certificates/acme-supported-ca/SSL_UUID

To update an existing Let’s Encrypt or ZeroSSL certificate, send a PATCH request to /api/v1/sites/SITE_UUID/ssl-certificates/acme-supported-ca/SSL_UUID. Does not change the provider. Returns 202. For wildcard certificates, also send dnsProfileUuid.

PATCH Check SSL Certificate Validity

/api/v1/sites/SITE_UUID/ssl-certificates/SSL_UUID/check-validity

To check the validity of an SSL certificate, send a PATCH request to /api/v1/sites/SITE_UUID/ssl-certificates/SSL_UUID/check-validity.

PATCH Check SSL Certificate Status

/api/v1/sites/SITE_UUID/ssl-certificates/SSL_UUID/check-status

To check DNS and the status of an SSL certificate, send a PATCH request to /api/v1/sites/SITE_UUID/ssl-certificates/SSL_UUID/check-status.

DELETE Delete SSL Certificate

/api/v1/sites/SITE_UUID/ssl-certificates/SSL_UUID

To delete an SSL certificate, send a DELETE request to /api/v1/sites/SITE_UUID/ssl-certificates/SSL_UUID.

Note

domains is a comma-separated list of hostnames. Do not include https:// . First value is the primary domain (the site domain). Any following values are alternate domains ( www , other hostnames). Example: blog.example.com,www.blog.example.com .

Ensure that alternate domains have their DNS pointed to the server’s IP address and are included in the Domain Aliases section.

Wait until DNS has propagated. Each domain’s A record must point to the server’s public IP. If the domain is proxied, temporarily disable proxy until after SSL has been applied.