Inductive Automation server-pki-certificate-management API
Server PKI certificate management
Server PKI certificate management
openapi: 3.0.3
info:
title: Ignition Gateway REST access-control server-pki-certificate-management API
description: The Ignition Gateway REST API (Ignition 8.3+) provides an OpenAPI-compliant HTTP interface to Gateway configuration resources including tags, projects, modules, device connections, historian data, user management (SCIM), alarm notification, OPC connections, and more. The specification is dynamically generated based on installed modules. Authentication uses API keys exchanged for time-limited tokens via the X-Ignition-API-Token header. Mutative requests are audit-logged. Supports Kubernetes and Helm-based cloud-native deployments.
version: 8.3.0
contact:
name: Inductive Automation Support
url: https://support.inductiveautomation.com/
license:
name: Commercial
url: https://inductiveautomation.com/pricing/
x-postman-collection: https://raw.githubusercontent.com/inductiveautomation/83-api/main/postman/8.3.postman_collection_v2.json
servers:
- url: http://{gateway-host}:{port}
description: Ignition Gateway (HTTP)
variables:
gateway-host:
default: localhost
description: Hostname or IP address of the Ignition Gateway
port:
default: '8088'
description: Gateway HTTP port (default 8088; HTTPS default 8043)
- url: https://{gateway-host}:{port}
description: Ignition Gateway (HTTPS)
variables:
gateway-host:
default: localhost
description: Hostname or IP address of the Ignition Gateway
port:
default: '8043'
description: Gateway HTTPS port
security:
- apiKeyAuth: []
tags:
- name: server-pki-certificate-management
description: Server PKI certificate management
paths:
/data/opc-ua/api/v1/server/pki/certificates/rejected:
get:
summary: Get Rejected Server Certificates
operationId: get-rejected-server-certificates-get
tags:
- server-pki-certificate-management
description: A list of all rejected server certificates.
responses:
'200':
description: Successful response
content:
application/json:
schema:
type: object
'400':
description: Bad request
'401':
description: Unauthorized
'404':
description: Not found
/data/opc-ua/api/v1/server/pki/certificates/rejected/{signature}:
get:
summary: Download Rejected Server Certificate
operationId: download-rejected-server-certificate-get
tags:
- server-pki-certificate-management
description: Download a rejected server certificate with the given signature.
parameters:
- name: signature
in: path
required: true
schema:
type: string
responses:
'200':
description: Successful response
content:
application/json:
schema:
type: object
'400':
description: Bad request
'401':
description: Unauthorized
'404':
description: Not found
delete:
summary: Delete Rejected Server Certificate
operationId: delete-rejected-server-certificate-delete
tags:
- server-pki-certificate-management
description: Delete a rejected server certificate with the given signature.
parameters:
- name: signature
in: path
required: true
schema:
type: string
responses:
'200':
description: Successful response
content:
application/json:
schema:
type: object
'400':
description: Bad request
'401':
description: Unauthorized
'404':
description: Not found
/data/opc-ua/api/v1/server/pki/certificates/trusted:
get:
summary: Get Trusted Server Certificates
operationId: get-trusted-server-certificates-get
tags:
- server-pki-certificate-management
description: A list of all trusted server certificates.
responses:
'200':
description: Successful response
content:
application/json:
schema:
type: object
'400':
description: Bad request
'401':
description: Unauthorized
'404':
description: Not found
post:
summary: Upload Trusted Server Certificates
operationId: upload-trusted-server-certificates-post
tags:
- server-pki-certificate-management
description: Upload a trusted server certificate.
responses:
'200':
description: Successful response
content:
application/json:
schema:
type: object
'400':
description: Bad request
'401':
description: Unauthorized
'404':
description: Not found
/data/opc-ua/api/v1/server/pki/certificates/trusted/{signature}:
get:
summary: Download Trusted Server Certificate
operationId: download-trusted-server-certificate-get
tags:
- server-pki-certificate-management
description: Download a trusted server certificate with the given signature.
parameters:
- name: signature
in: path
required: true
schema:
type: string
responses:
'200':
description: Successful response
content:
application/json:
schema:
type: object
'400':
description: Bad request
'401':
description: Unauthorized
'404':
description: Not found
post:
summary: Trust Rejected Server Certificate
operationId: trust-rejected-server-certificate-post
tags:
- server-pki-certificate-management
description: Trust a previously rejected server certificate with the given signature.
parameters:
- name: signature
in: path
required: true
schema:
type: string
responses:
'200':
description: Successful response
content:
application/json:
schema:
type: object
'400':
description: Bad request
'401':
description: Unauthorized
'404':
description: Not found
delete:
summary: Delete Trusted Server Certificate
operationId: delete-trusted-server-certificate-delete
tags:
- server-pki-certificate-management
description: Delete a trusted server certificate with the given signature.
parameters:
- name: signature
in: path
required: true
schema:
type: string
responses:
'200':
description: Successful response
content:
application/json:
schema:
type: object
'400':
description: Bad request
'401':
description: Unauthorized
'404':
description: Not found
components:
securitySchemes:
apiKeyAuth:
type: apiKey
in: header
name: X-Ignition-API-Token
description: Time-limited API token. Obtain by posting credentials to the token endpoint. See /data/api/v1/token for details.
externalDocs:
description: Ignition 8.3 Gateway REST API Documentation
url: https://www.docs.inductiveautomation.com/docs/8.3/platform/gateway/openapi