# v2 (https://developer.godaddy.com/en/docs/references/rest/certificates/v2)

---
title: v2
description: ''
full: true
---

## GET /v2/certificates

Search for certificate details by entitlement

Once the certificate order has been created, this method can be used to check the status of the certificate. This method can also be used to retrieve details of the certificates associated to an entitlement.

### Query parameters

| Name | Type | Required | Description |
|------|------|----------|-------------|
| `entitlementId` | string | yes | Entitlement id to lookup |
| `latest` | boolean | no | Fetch only the most recent certificate |

### Responses

**200** — Certificate details retrieved

Content-Type: `application/json`

Schema:

- array
  - items:

**400** — Request was malformed

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**401** — Authentication info not sent or invalid

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**403** — Authenticated user is not allowed access

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**422** — Entitlement id not provided

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**500** — Internal server error

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

## POST /v2/certificates

Create a pending order for certificate

<p>Creating a certificate order for a subscription can be a long running asynchronous operation in the PKI workflow. The PKI API supports 2 options for getting the completion stateful actions for this asynchronous operations: 1) by polling operations -- see /v1/certificates/{certificateId}/actions 2) via WebHook style callback -- see '/v1/certificates/{certificateId}/callback'.</p>

### Header parameters

| Name | Type | Required | Description |
|------|------|----------|-------------|
| `X-Market-Id` | string | no | Setting locale for communications such as emails and error messages |

### Request body (required)

The certificate order information

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/SubscriptionCertificateCreate`

### Responses

**202** — Request was successful

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/SubscriptionCertificateIdentifier`

**400** — Request was malformed

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**401** — Authentication info not sent or invalid

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**403** — Authenticated user is not allowed access

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**409** — Certificate state does not allow renew

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**422** — `email` is not empty<br>`csr` is invalid

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**500** — Internal server error

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

## POST /v2/certificates/{certificateId}/reissue

Reissue active certificate

<p>Rekeying is the process by which the private and public key is changed for a certificate. It is a simplified reissue,where only the CSR is changed. Reissue extends validity of the existing certificate by requesting a new certificate with all the same values as existing issued certificate. Once a request is validated and approved, the certificate will be reissued with the same common name and sans specified from existing certificate. Unlimited reissues are available during the lifetime of the certificate.If this API call is made before a previous pending reissue has been validated and issued, the previous reissue request is automatically rejected and replaced with the current request.</p>

### Path parameters

| Name | Type | Required | Description |
|------|------|----------|-------------|
| `certificateId` | string | yes | Certificate id to reissue |

### Request body

The reissue request info

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/CertificateReissueV2`

### Responses

**202** — Reissue request created

**400** — Request was malformed

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**401** — Authentication info not sent or invalid

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**403** — Authenticated user is not allowed access

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**404** — Certificate id not found

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**409** — Certificate state does not allow reissue

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**422** — `csr` is invalid<br>Delay revocation exceeds maximum

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**500** — Internal server error

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

## GET /v2/certificates/download

Download certificate by entitlement

### Query parameters

| Name | Type | Required | Description |
|------|------|----------|-------------|
| `entitlementId` | string | yes | Entitlement id to download |

### Responses

**200** — Certificate retrieved

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/CertificateBundle`

**400** — Request was malformed

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**401** — Authentication info not sent or invalid

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**403** — Authenticated user is not allowed access

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**404** — Entitlement id not found

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**409** — Certificate state does not allow download

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**422** — Entitlement id not provided

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

**500** — Internal server error

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/Error`

## GET /v2/customers/{customerId}/certificates

Retrieve customer's certificates

This method can be used to retrieve a list of certificates for a specified customer. <ul><li>**shopperId** is **not the same** as **customerId**.  **shopperId** is a number of max length 10 digits (*ex:* 1234567890) whereas **customerId** is a UUIDv4 (*ex:* 295e3bc3-b3b9-4d95-aae5-ede41a994d13)</li></ul>

### Path parameters

| Name | Type | Required | Description |
|------|------|----------|-------------|
| `customerId` | string | yes | An identifier for a customer |

### Query parameters

| Name | Type | Required | Description |
|------|------|----------|-------------|
| `offset` | integer <integer-positive> | no | Number of results to skip for pagination |
| `limit` | integer <integer-positive> | no | Maximum number of items to return |

### Responses

**200** — Customer certificate information retrieved.

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/CertificateSummariesV2`

**401** — Authentication info not sent or is invalid

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

**403** — Authenticated user is not allowed access

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

**422** — Application-specific request error

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

**429** — Too many requests received within interval

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/ErrorLimit`

**500** — Internal server error

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

## GET /v2/customers/{customerId}/certificates/{certificateId}

Retrieve individual certificate details

Once the certificate order has been created, this method can be used to check the status of the certificate. This method can also be used to retrieve details of the certificate. <ul><li>**shopperId** is **not the same** as **customerId**. **shopperId** is a number of max length 10 digits (*ex:* 1234567890) whereas **customerId** is a UUIDv4 (*ex:* 295e3bc3-b3b9-4d95-aae5-ede41a994d13)</li></ul>

### Path parameters

| Name | Type | Required | Description |
|------|------|----------|-------------|
| `customerId` | string | yes | An identifier for a customer |
| `certificateId` | string | yes | Certificate id to lookup |

### Responses

**200** — Certificate details retrieved

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/CertificateDetailV2`

**401** — Authentication info not sent or is invalid

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

**403** — Authenticated user is not allowed access

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

**404** — Resource not found

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

**422** — Application-specific request error

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

**429** — Too many requests received within interval

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/ErrorLimit`

**500** — Internal server error

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

## GET /v2/customers/{customerId}/certificates/{certificateId}/domainVerifications

Retrieve domain verification status

This method can be used to retrieve the domain verification status for a certificate request.<ul><li>**shopperId** is **not the same** as **customerId**.  **shopperId** is a number of max length 10 digits (*ex:* 1234567890) whereas **customerId** is a UUIDv4 (*ex:* 295e3bc3-b3b9-4d95-aae5-ede41a994d13)</li></ul>"

### Path parameters

| Name | Type | Required | Description |
|------|------|----------|-------------|
| `customerId` | string | yes | An identifier for a customer |
| `certificateId` | string | yes | Certificate id to lookup |

### Responses

**200** — Domain verification status list for specified certificateId.

Content-Type: `application/json`

Schema:

- array
  - items:

**401** — Authentication info not sent or is invalid

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

**403** — Authenticated user is not allowed access

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

**404** — Resource not found

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

**422** — Application-specific request error

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

**429** — Too many requests received within interval

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/ErrorLimit`

**500** — Internal server error

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

## GET /v2/customers/{customerId}/certificates/{certificateId}/domainVerifications/{domain}

Retrieve detailed information for supplied domain

Retrieve detailed information for supplied domain, including domain verification details and Certificate Authority Authorization (CAA) verification details. <ul><li>**shopperId** is **not the same** as **customerId**.  **shopperId** is a number of max length 10 digits (*ex:* 1234567890) whereas **customerId** is a UUIDv4 (*ex:* 295e3bc3-b3b9-4d95-aae5-ede41a994d13)</li></ul>

### Path parameters

| Name | Type | Required | Description |
|------|------|----------|-------------|
| `customerId` | string | yes | An identifier for a customer |
| `certificateId` | string | yes | Certificate id to lookup |
| `domain` | string <domain> | yes | A valid domain name in the certificate request |

### Responses

**200** — Retrieve detailed information for supplied domain, including domain verification details and Certificate Authority Authorization (CAA) verification details.

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/DomainVerificationDetail`

**401** — Authentication info not sent or is invalid

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

**403** — Authenticated user is not allowed access

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

**404** — Resource not found

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

**422** — Application-specific request error

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

**429** — Too many requests received within interval

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/ErrorLimit`

**500** — Internal server error

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

## GET /v2/customers/{customerId}/certificates/acme/externalAccountBinding

Retrieves the external account binding for the specified customer

Use this endpoint to retrieve a key identifier and Hash-based Message Authentication Code (HMAC) key for Automated Certificate Management Environment (ACME) External Account Binding (EAB). These credentials can be used with an ACME client that supports EAB (ex. CertBot) to automate the issuance request and deployment of DV SSL certificates

### Path parameters

| Name | Type | Required | Description |
|------|------|----------|-------------|
| `customerId` | string | yes | An identifier for a customer |

### Responses

**200** — Acme key identifier and HMAC key for the external account binding. Directory URI is also provided for making ACME requests.

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/ExternalAccountBinding`

**401** — Authentication info not sent or is invalid

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

**403** — Authenticated user is not allowed access

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

**404** — Resource not found

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

**422** — Application-specific request error

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

**429** — Too many requests received within interval

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/ErrorLimit`

**500** — Internal server error

Content-Type: `*/*`

Schema:

- schema reference: `#/components/schemas/Error`

## GET /v2/certificates/subscriptions/search

Get a page of subscriptions by domain

The pagination starts at page 1. Each page contains a page of *subscriptions*, not certificates. This endpoint is meant for paging the subscriptions under the authorized user's account. Each subscription contains a snapshot of certificates contained within the subscription. To fetch further certificates under a subscription, use the /v2/certificates/subscription/{guid} endpoint with the subscription GUID obtained from this call. If any filtering is applied, subscriptions without any certificates will be omitted.

### Query parameters

| Name | Type | Required | Description |
|------|------|----------|-------------|
| `pageSize` | integer <int32> | no | The number of records to return per query. |
| `page` | integer <int32> | no | The page number. <b>(First page is <i>one</i> instead of zero.)</b> |
| `domain` | string | no | Filter by domain name / common name. This will look for the text inside the content of the domain. This is not a "find domains that start with x" search. |
| `status` | string | no | The certificate lifecycle stage. <br> Active, Expired, and Revoked are all Issued certificates. <br> Active means the validity period includes today. <br> Expired means the validity period was prior to today. <br> Revoked means that the certificate has been revoked. <br> Pending means that the certificate is still going through the issuance process and has not been signed or issued yet. <br> Denied means that the certificate went from pending to denied for any valid denial reason.  (Customer canceled request, CAA records exist for the domain, fraud, etc...) |
| `type` | string | no | The type of certificate in terms of the number of applicable domains. |
| `validation` | string | no | The validation type for the certificate.  Standard/Basic Validation (DV).  Organizational/Deluxe Vetting (OV). Extended/Premium Validation (EV). |

### Responses

**200** — OK

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/CertificatesByDomainPage`

## GET /v2/certificates/subscription/{guid}

GET a page of certificates for a specific domain product

### Path parameters

| Name | Type | Required | Description |
|------|------|----------|-------------|
| `guid` | string | yes | The Subscription GUID containing the certificates being requested. |

### Query parameters

| Name | Type | Required | Description |
|------|------|----------|-------------|
| `pageSize` | integer <int32> | no | The number of records to return per query. |
| `page` | integer <int32> | no | The page number. <b>(First page is <i>one</i> instead of zero.)</b> |
| `domain` | string | no | Filter by domain name / common name. This will look for the text inside the content of the domain. This is not a "find domains that start with x" search. |
| `status` | string | no | The certificate lifecycle stage. <br> Active, Expired, and Revoked are all Issued certificates. <br> Active means the validity period includes today. <br> Expired means the validity period was prior to today. <br> Revoked means that the certificate has been revoked. <br> Pending means that the certificate is still going through the issuance process and has not been signed or issued yet. <br> Denied means that the certificate went from pending to denied for any valid denial reason.  (Customer canceled request, CAA records exist for the domain, fraud, etc...) |
| `type` | string | no | The type of certificate in terms of the number of applicable domains. |
| `validation` | string | no | The validation type for the certificate.  Standard/Basic Validation (DV).  Organizational/Deluxe Vetting (OV). Extended/Premium Validation (EV). |

### Responses

**200** — OK

Content-Type: `application/json`

Schema:

- schema reference: `#/components/schemas/CertificatesByDomainPaged`
