Kong CA Certificates API

A CA certificate object represents a trusted certificate authority. These objects are used by Kong Gateway to verify the validity of a client or server certificate.

Operations 9

POST /ca_certificates Create a new CA Certificate #
DELETE /ca_certificates/{CACertificateId} Delete a CA Certificate #
GET /ca_certificates/{CACertificateId} Get a CA Certificate #
PUT /ca_certificates/{CACertificateId} Upsert a CA Certificate #
GET /v2/control-planes/{controlPlaneId}/core-entities/ca_certificates List all CA Certificates #
POST /v2/control-planes/{controlPlaneId}/core-entities/ca_certificates Create a new CA Certificate #
DELETE /v2/control-planes/{controlPlaneId}/core-entities/ca_certificates/{CACertificateId} Delete a CA Certificate #
GET /v2/control-planes/{controlPlaneId}/core-entities/ca_certificates/{CACertificateId} Get a CA Certificate #
PUT /v2/control-planes/{controlPlaneId}/core-entities/ca_certificates/{CACertificateId} Upsert a CA Certificate #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/kong-ca-certificates-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

kong-ca-certificates-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Kong CA Certificates API
  version: 3.14.0
  contact:
    email: support@konghq.com
    name: Kong Inc
    url: https://konghq.com
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  x-refined-note:
  - x-extensions-note differs across the merged source definitions and was not carried
  - x-oas-source differs across the merged source definitions and was not carried
  - x-oas-source-link differs across the merged source definitions and was not carried
  description: 'Operations tagged CA Certificates across 2 of this provider''s published API definitions: kong-gateway-admin-api.yml, kong-konnect-platform-api.yml. Each path carries the servers of the definition it was published in.'
servers:
- description: Default Admin API URL
  url: '{protocol}://{hostname}:{port}{path}'
  variables:
    hostname:
      default: localhost
      description: Hostname for Kong's Admin API
    path:
      default: /
      description: Base path for Kong's Admin API
    port:
      default: '8001'
      description: Port for Kong's Admin API
    protocol:
      default: http
      description: Protocol for requests to Kong's Admin API
      enum:
      - http
      - https
- url: https://global.api.konghq.com
- url: https://us.api.konghq.com
- url: https://eu.api.konghq.com
- url: https://au.api.konghq.com
tags:
- description: 'A CA certificate object represents a trusted certificate authority.

    These objects are used by Kong Gateway to verify the validity of a client or server certificate.'
  name: CA Certificates
paths:
  /ca_certificates:
    post:
      x-speakeasy-entity-operation:
        terraform-datasource: null
        terraform-resource: CACertificate#create
      operationId: create-ca_certificate
      summary: Create a new CA Certificate
      description: Create a new CA Certificate
      requestBody:
        description: Description of the new CA Certificate for creation
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CACertificate'
      responses:
        '201':
          description: Successfully created CA Certificate
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CACertificate'
        '401':
          $ref: '#/components/responses/HTTP401Error'
      tags:
      - CA Certificates
      security:
      - adminToken: []
    servers:
    - description: Default Admin API URL
      url: '{protocol}://{hostname}:{port}{path}'
      variables:
        hostname:
          default: localhost
          description: Hostname for Kong's Admin API
        path:
          default: /
          description: Base path for Kong's Admin API
        port:
          default: '8001'
          description: Port for Kong's Admin API
        protocol:
          default: http
          description: Protocol for requests to Kong's Admin API
          enum:
          - http
          - https
  /ca_certificates/{CACertificateId}:
    parameters:
    - $ref: '#/components/parameters/CACertificateId'
    delete:
      x-speakeasy-entity-operation:
        terraform-datasource: null
        terraform-resource: CACertificate#delete
      operationId: delete-ca_certificate
      summary: Delete a CA Certificate
      description: Delete a CA Certificate
      parameters:
      - $ref: '#/components/parameters/CACertificateId'
      responses:
        '204':
          description: Successfully deleted CA Certificate or the resource didn't exist
        '401':
          $ref: '#/components/responses/HTTP401Error'
      tags:
      - CA Certificates
      security:
      - adminToken: []
    get:
      x-speakeasy-entity-operation:
        terraform-datasource: null
        terraform-resource: CACertificate#read
      operationId: get-ca_certificate
      summary: Get a CA Certificate
      description: Get a CA Certificate using ID.
      responses:
        '200':
          description: Successfully fetched CA Certificate
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CACertificate'
        '401':
          $ref: '#/components/responses/HTTP401Error'
        '404':
          description: Resource does not exist
      tags:
      - CA Certificates
      security:
      - adminToken: []
    put:
      x-speakeasy-entity-operation:
        terraform-datasource: null
        terraform-resource: CACertificate#update
      operationId: upsert-ca_certificate
      summary: Upsert a CA Certificate
      description: Create or Update CA Certificate using ID.
      requestBody:
        description: Description of the CA Certificate
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CACertificate'
      responses:
        '200':
          description: Successfully upserted CA Certificate
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CACertificate'
        '401':
          $ref: '#/components/responses/HTTP401Error'
      tags:
      - CA Certificates
      security:
      - adminToken: []
    servers:
    - description: Default Admin API URL
      url: '{protocol}://{hostname}:{port}{path}'
      variables:
        hostname:
          default: localhost
          description: Hostname for Kong's Admin API
        path:
          default: /
          description: Base path for Kong's Admin API
        port:
          default: '8001'
          description: Port for Kong's Admin API
        protocol:
          default: http
          description: Protocol for requests to Kong's Admin API
          enum:
          - http
          - https
  /v2/control-planes/{controlPlaneId}/core-entities/ca_certificates:
    parameters:
    - $ref: '#/components/parameters/controlPlaneId'
    get:
      operationId: list-ca_certificate
      summary: List all CA Certificates
      description: List all CA Certificates
      parameters:
      - $ref: '#/components/parameters/PaginationSize'
      - $ref: '#/components/parameters/PaginationOffset'
      - $ref: '#/components/parameters/PaginationTagsFilter'
      responses:
        '200':
          description: A successful response listing CA Certificates
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/CACertificate_2'
                  next:
                    $ref: '#/components/schemas/PaginationNextResponse'
                  offset:
                    $ref: '#/components/schemas/PaginationOffsetResponse'
        '401':
          $ref: '#/components/responses/HTTP401Error_2'
      tags:
      - CA Certificates
      security:
      - personalAccessToken: []
      - systemAccountAccessToken: []
      - konnectAccessToken: []
      - serviceAccessToken: []
    post:
      operationId: create-ca_certificate
      summary: Create a new CA Certificate
      description: Create a new CA Certificate
      requestBody:
        description: Description of the new CA Certificate for creation
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CACertificate_2'
      responses:
        '201':
          description: Successfully created CA Certificate
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CACertificate_2'
        '401':
          $ref: '#/components/responses/HTTP401Error_2'
      tags:
      - CA Certificates
      security:
      - personalAccessToken: []
      - systemAccountAccessToken: []
      - konnectAccessToken: []
      - serviceAccessToken: []
    servers:
    - url: https://global.api.konghq.com
    - url: https://us.api.konghq.com
    - url: https://eu.api.konghq.com
    - url: https://au.api.konghq.com
  /v2/control-planes/{controlPlaneId}/core-entities/ca_certificates/{CACertificateId}:
    parameters:
    - $ref: '#/components/parameters/CACertificateId_2'
    - $ref: '#/components/parameters/controlPlaneId'
    delete:
      operationId: delete-ca_certificate
      summary: Delete a CA Certificate
      description: Delete a CA Certificate
      parameters:
      - $ref: '#/components/parameters/CACertificateId_2'
      responses:
        '204':
          description: Successfully deleted CA Certificate or the resource didn't exist
        '401':
          $ref: '#/components/responses/HTTP401Error_2'
      tags:
      - CA Certificates
      security:
      - personalAccessToken: []
      - systemAccountAccessToken: []
      - konnectAccessToken: []
      - serviceAccessToken: []
    get:
      operationId: get-ca_certificate
      summary: Get a CA Certificate
      description: Get a CA Certificate using ID.
      responses:
        '200':
          description: Successfully fetched CA Certificate
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CACertificate_2'
        '401':
          $ref: '#/components/responses/HTTP401Error_2'
        '404':
          description: Resource does not exist
      tags:
      - CA Certificates
      security:
      - personalAccessToken: []
      - systemAccountAccessToken: []
      - konnectAccessToken: []
      - serviceAccessToken: []
    put:
      operationId: upsert-ca_certificate
      summary: Upsert a CA Certificate
      description: Create or Update CA Certificate using ID.
      requestBody:
        description: Description of the CA Certificate
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CACertificate_2'
      responses:
        '200':
          description: Successfully upserted CA Certificate
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CACertificate_2'
        '401':
          $ref: '#/components/responses/HTTP401Error_2'
      tags:
      - CA Certificates
      security:
      - personalAccessToken: []
      - systemAccountAccessToken: []
      - konnectAccessToken: []
      - serviceAccessToken: []
    servers:
    - url: https://global.api.konghq.com
    - url: https://us.api.konghq.com
    - url: https://eu.api.konghq.com
    - url: https://au.api.konghq.com
components:
  parameters:
    CACertificateId:
      description: ID of the CA Certificate to lookup
      example: 3c31f18a-f27a-4f9b-8cd4-bf841554612f
      in: path
      name: CACertificateId
      required: true
      schema:
        type: string
      x-speakeasy-match: id
    PaginationSize:
      description: Number of resources to be returned.
      in: query
      name: size
      schema:
        type: integer
        default: 100
        maximum: 1000
        minimum: 1
    controlPlaneId:
      name: controlPlaneId
      in: path
      required: true
      schema:
        type: string
        format: uuid
        example: 9524ec7d-36d9-465d-a8c5-83a3c9390458
      description: The UUID of your control plane. This variable is available in the Konnect manager.
      x-speakeasy-param-force-new: true
    CACertificateId_2:
      description: ID of the CA Certificate to lookup
      example: 3c31f18a-f27a-4f9b-8cd4-bf841554612f
      in: path
      name: CACertificateId
      required: true
      schema:
        type: string
    PaginationOffset:
      allowEmptyValue: true
      description: Offset from which to return the next set of resources. Use the value of the 'offset' field from the response of a list operation as input here to paginate through all the resources
      in: query
      name: offset
      schema:
        type: string
    PaginationTagsFilter:
      allowEmptyValue: true
      description: A list of tags to filter the list of resources on. Multiple tags can be concatenated using ',' to mean AND or using '/' to mean OR.
      example: tag1,tag2
      in: query
      name: tags
      schema:
        type: string
  schemas:
    GatewayUnauthorizedError:
      type: object
      properties:
        message:
          type: string
        status:
          type: integer
      required:
      - message
      - status
    CACertificate:
      x-speakeasy-entity: CACertificate
      description: A CA certificate object represents a trusted CA. These objects are used by Kong to verify the validity of a client or server certificate.
      type: object
      properties:
        cert:
          description: PEM-encoded public certificate of the CA.
          type: string
        cert_digest:
          description: SHA256 hex digest of the public certificate. This field is read-only and it cannot be set by the caller, the value is automatically computed.
          type: string
          nullable: true
        created_at:
          description: Unix epoch when the resource was created.
          type: integer
          nullable: true
        id:
          description: A string representing a UUID (universally unique identifier).
          type: string
          nullable: true
        tags:
          description: An optional set of strings associated with the Certificate for grouping and filtering.
          type: array
          items:
            description: A string representing a tag.
            type: string
          nullable: true
        updated_at:
          description: Unix epoch when the resource was last updated.
          type: integer
          nullable: true
      example:
        cert: '-----BEGIN CERTIFICATE-----

          certificate-content

          -----END CERTIFICATE-----'
        cert_digest: 9b8aaf19a276885f6c8a6bc48a30700fdb3a351d8b05374d153bfb7b178e2a9f
        created_at: 1706598432
        id: b2f34145-0343-41a4-9602-4c69dec2f260
        tags:
        - trusted
        - api
      additionalProperties: false
      required:
      - cert
    PaginationNextResponse:
      description: URI to the next page (may be null)
      type: string
    PaginationOffsetResponse:
      description: Offset is used to paginate through the API. Provide this value to the next list operation to fetch the next page
      type: string
    CACertificate_2:
      description: A CA certificate object represents a trusted CA. These objects are used by Kong to verify the validity of a client or server certificate.
      type: object
      properties:
        cert:
          description: PEM-encoded public certificate of the CA.
          type: string
        cert_digest:
          description: SHA256 hex digest of the public certificate. This field is read-only and it cannot be set by the caller, the value is automatically computed.
          type: string
          nullable: true
        created_at:
          description: Unix epoch when the resource was created.
          type: integer
          nullable: true
        id:
          description: A string representing a UUID (universally unique identifier).
          type: string
          nullable: true
        tags:
          description: An optional set of strings associated with the Certificate for grouping and filtering.
          type: array
          items:
            description: A string representing a tag.
            type: string
          nullable: true
        updated_at:
          description: Unix epoch when the resource was last updated.
          type: integer
          nullable: true
      example:
        cert: '-----BEGIN CERTIFICATE-----

          certificate-content

          -----END CERTIFICATE-----'
        cert_digest: 9b8aaf19a276885f6c8a6bc48a30700fdb3a351d8b05374d153bfb7b178e2a9f
        created_at: 1706598432
        id: b2f34145-0343-41a4-9602-4c69dec2f260
        tags:
        - trusted
        - api
      additionalProperties: false
      required:
      - cert
  responses:
    HTTP401Error:
      description: Unauthorized
      content:
        application/json:
          examples:
            DuplicateApiKey:
              summary: Duplicate API key found
              value:
                message: Duplicate API key found
                status: 401
            InvalidAuthCred:
              summary: Invalid authentication credentials
              value:
                message: Unauthorized
                status: 401
            NoAPIKey:
              summary: No API key found
              value:
                message: No API key found in request
                status: 401
          schema:
            $ref: '#/components/schemas/GatewayUnauthorizedError'
    HTTP401Error_2:
      description: Unauthorized
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/GatewayUnauthorizedError'
  securitySchemes:
    adminToken:
      in: header
      name: Kong-Admin-Token
      type: apiKey
    personalAccessToken:
      type: http
      scheme: bearer
      bearerFormat: Token
      description: The personal access token is meant to be used as an alternative to basic-auth when accessing Konnect via APIs. You can generate a Personal Access Token (PAT) from the personal access token page in the Konnect dashboard.
    systemAccountAccessToken:
      type: http
      scheme: bearer
      bearerFormat: Token
      description: 'The system account access token is meant for automations and integrations that are not directly associated with a human identity.

        You can generate a system account Access Token by creating a system account and then obtaining a system account access token for that account.

        The access token must be passed in the header of a request, for example:

        `curl -X GET ''https://global.api.konghq.com/v2/users/'' --header ''Authorization: Bearer spat_i2Ej...''`

        '
    konnectAccessToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: The Konnect access token is meant to be used by the Konnect dashboard and the decK CLI to authenticate with.
    serviceAccessToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: 'The Service access token is meant to be used between internal services.

        '
externalDocs:
  description: Documentation for Kong Gateway and its APIs
  url: https://developer.konghq.com
x-refined-from:
- kong-gateway-admin-api.yml
- kong-konnect-platform-api.yml