Kong Certificates API

A certificate object represents a public certificate, and can be optionally paired with the corresponding private key. These objects are used by Kong Gateway to handle SSL/TLS termination for encrypted requests, or for use as a trusted CA store when validating peer certificate of client/service. Certificates are optionally associated with SNI objects to tie a cert/key pair to one or more hostnames. If intermediate certificates are required in addition to the main certificate, they should be concatenated together into one string.

Operations 9

POST /{workspace}/certificates Create a new Certificate #
DELETE /{workspace}/certificates/{CertificateId} Delete a Certificate #
GET /{workspace}/certificates/{CertificateId} Get a Certificate #
PUT /{workspace}/certificates/{CertificateId} Upsert a Certificate #
GET /v2/control-planes/{controlPlaneId}/core-entities/certificates List all Certificates #
POST /v2/control-planes/{controlPlaneId}/core-entities/certificates Create a new Certificate #
DELETE /v2/control-planes/{controlPlaneId}/core-entities/certificates/{CertificateId} Delete a Certificate #
GET /v2/control-planes/{controlPlaneId}/core-entities/certificates/{CertificateId} Get a Certificate #
PUT /v2/control-planes/{controlPlaneId}/core-entities/certificates/{CertificateId} Upsert a Certificate #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/kong-certificates-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

kong-certificates-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Kong Certificates API
  version: 3.14.0
  contact:
    email: support@konghq.com
    name: Kong Inc
    url: https://konghq.com
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  x-refined-note:
  - x-extensions-note differs across the merged source definitions and was not carried
  - x-oas-source differs across the merged source definitions and was not carried
  - x-oas-source-link differs across the merged source definitions and was not carried
  description: 'Operations tagged Certificates across 2 of this provider''s published API definitions: kong-gateway-admin-api.yml, kong-konnect-platform-api.yml. Each path carries the servers of the definition it was published in.'
servers:
- description: Default Admin API URL
  url: '{protocol}://{hostname}:{port}{path}'
  variables:
    hostname:
      default: localhost
      description: Hostname for Kong's Admin API
    path:
      default: /
      description: Base path for Kong's Admin API
    port:
      default: '8001'
      description: Port for Kong's Admin API
    protocol:
      default: http
      description: Protocol for requests to Kong's Admin API
      enum:
      - http
      - https
- url: https://global.api.konghq.com
- url: https://us.api.konghq.com
- url: https://eu.api.konghq.com
- url: https://au.api.konghq.com
tags:
- description: 'A certificate object represents a public certificate, and can be optionally paired with the corresponding private key. These objects are used by Kong Gateway to handle SSL/TLS termination for encrypted requests, or for use as a trusted CA store when validating peer certificate of client/service.

    <br><br>

    Certificates are optionally associated with SNI objects to tie a cert/key pair to one or more hostnames.

    <br><br>

    If intermediate certificates are required in addition to the main certificate, they should be concatenated together into one string.

    '
  name: Certificates
paths:
  /{workspace}/certificates:
    post:
      x-speakeasy-entity-operation:
        terraform-datasource: null
        terraform-resource: Certificate#create
      operationId: create-certificate
      summary: Create a new Certificate
      description: Create a new Certificate
      parameters:
      - $ref: '#/components/parameters/Workspace'
      requestBody:
        description: Description of the new Certificate for creation
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Certificate'
      responses:
        '201':
          description: Successfully created Certificate
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Certificate'
        '401':
          $ref: '#/components/responses/HTTP401Error'
      tags:
      - Certificates
      security:
      - adminToken: []
    servers:
    - description: Default Admin API URL
      url: '{protocol}://{hostname}:{port}{path}'
      variables:
        hostname:
          default: localhost
          description: Hostname for Kong's Admin API
        path:
          default: /
          description: Base path for Kong's Admin API
        port:
          default: '8001'
          description: Port for Kong's Admin API
        protocol:
          default: http
          description: Protocol for requests to Kong's Admin API
          enum:
          - http
          - https
  /{workspace}/certificates/{CertificateId}:
    parameters:
    - $ref: '#/components/parameters/CertificateId'
    delete:
      x-speakeasy-entity-operation:
        terraform-datasource: null
        terraform-resource: Certificate#delete
      operationId: delete-certificate
      summary: Delete a Certificate
      description: Delete a Certificate
      parameters:
      - $ref: '#/components/parameters/CertificateId'
      - $ref: '#/components/parameters/Workspace'
      responses:
        '204':
          description: Successfully deleted Certificate or the resource didn't exist
        '401':
          $ref: '#/components/responses/HTTP401Error'
      tags:
      - Certificates
      security:
      - adminToken: []
    get:
      x-speakeasy-entity-operation:
        terraform-datasource: null
        terraform-resource: Certificate#read
      operationId: get-certificate
      summary: Get a Certificate
      description: Get a Certificate using ID.
      parameters:
      - $ref: '#/components/parameters/Workspace'
      responses:
        '200':
          description: Successfully fetched Certificate
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Certificate'
        '401':
          $ref: '#/components/responses/HTTP401Error'
        '404':
          description: Resource does not exist
      tags:
      - Certificates
      security:
      - adminToken: []
    put:
      x-speakeasy-entity-operation:
        terraform-datasource: null
        terraform-resource: Certificate#update
      operationId: upsert-certificate
      summary: Upsert a Certificate
      description: Create or Update Certificate using ID.
      parameters:
      - $ref: '#/components/parameters/Workspace'
      requestBody:
        description: Description of the Certificate
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Certificate'
      responses:
        '200':
          description: Successfully upserted Certificate
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Certificate'
        '401':
          $ref: '#/components/responses/HTTP401Error'
      tags:
      - Certificates
      security:
      - adminToken: []
    servers:
    - description: Default Admin API URL
      url: '{protocol}://{hostname}:{port}{path}'
      variables:
        hostname:
          default: localhost
          description: Hostname for Kong's Admin API
        path:
          default: /
          description: Base path for Kong's Admin API
        port:
          default: '8001'
          description: Port for Kong's Admin API
        protocol:
          default: http
          description: Protocol for requests to Kong's Admin API
          enum:
          - http
          - https
  /v2/control-planes/{controlPlaneId}/core-entities/certificates:
    parameters:
    - $ref: '#/components/parameters/controlPlaneId'
    get:
      operationId: list-certificate
      summary: List all Certificates
      description: List all Certificates
      parameters:
      - $ref: '#/components/parameters/PaginationSize'
      - $ref: '#/components/parameters/PaginationOffset'
      - $ref: '#/components/parameters/PaginationTagsFilter'
      responses:
        '200':
          description: A successful response listing Certificates
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/Certificate_2'
                  next:
                    $ref: '#/components/schemas/PaginationNextResponse'
                  offset:
                    $ref: '#/components/schemas/PaginationOffsetResponse'
        '401':
          $ref: '#/components/responses/HTTP401Error_2'
      tags:
      - Certificates
      security:
      - personalAccessToken: []
      - systemAccountAccessToken: []
      - konnectAccessToken: []
      - serviceAccessToken: []
    post:
      operationId: create-certificate
      summary: Create a new Certificate
      description: Create a new Certificate
      requestBody:
        description: Description of the new Certificate for creation
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Certificate_2'
      responses:
        '201':
          description: Successfully created Certificate
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Certificate_2'
        '401':
          $ref: '#/components/responses/HTTP401Error_2'
      tags:
      - Certificates
      security:
      - personalAccessToken: []
      - systemAccountAccessToken: []
      - konnectAccessToken: []
      - serviceAccessToken: []
    servers:
    - url: https://global.api.konghq.com
    - url: https://us.api.konghq.com
    - url: https://eu.api.konghq.com
    - url: https://au.api.konghq.com
  /v2/control-planes/{controlPlaneId}/core-entities/certificates/{CertificateId}:
    parameters:
    - $ref: '#/components/parameters/CertificateId_2'
    - $ref: '#/components/parameters/controlPlaneId'
    delete:
      operationId: delete-certificate
      summary: Delete a Certificate
      description: Delete a Certificate
      parameters:
      - $ref: '#/components/parameters/CertificateId_2'
      responses:
        '204':
          description: Successfully deleted Certificate or the resource didn't exist
        '401':
          $ref: '#/components/responses/HTTP401Error_2'
      tags:
      - Certificates
      security:
      - personalAccessToken: []
      - systemAccountAccessToken: []
      - konnectAccessToken: []
      - serviceAccessToken: []
    get:
      operationId: get-certificate
      summary: Get a Certificate
      description: Get a Certificate using ID.
      responses:
        '200':
          description: Successfully fetched Certificate
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Certificate_2'
        '401':
          $ref: '#/components/responses/HTTP401Error_2'
        '404':
          description: Resource does not exist
      tags:
      - Certificates
      security:
      - personalAccessToken: []
      - systemAccountAccessToken: []
      - konnectAccessToken: []
      - serviceAccessToken: []
    put:
      operationId: upsert-certificate
      summary: Upsert a Certificate
      description: Create or Update Certificate using ID.
      requestBody:
        description: Description of the Certificate
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Certificate_2'
      responses:
        '200':
          description: Successfully upserted Certificate
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Certificate_2'
        '401':
          $ref: '#/components/responses/HTTP401Error_2'
      tags:
      - Certificates
      security:
      - personalAccessToken: []
      - systemAccountAccessToken: []
      - konnectAccessToken: []
      - serviceAccessToken: []
    servers:
    - url: https://global.api.konghq.com
    - url: https://us.api.konghq.com
    - url: https://eu.api.konghq.com
    - url: https://au.api.konghq.com
components:
  schemas:
    Certificate:
      x-speakeasy-entity: Certificate
      description: 'A certificate object represents a public certificate, and can be optionally paired with the corresponding private key. These objects are used by Kong to handle SSL/TLS termination for encrypted requests, or for use as a trusted CA store when validating peer certificate of client/service. Certificates are optionally associated with SNI objects to tie a cert/key pair to one or more hostnames. If intermediate certificates are required in addition to the main certificate, they should be concatenated together into one string according to the following order: main certificate on the top, followed by any intermediates.'
      type: object
      properties:
        cert:
          description: PEM-encoded public certificate chain of the SSL key pair. This field is _referenceable_, which means it can be securely stored as a [secret](/gateway/latest/plan-and-deploy/security/secrets-management/getting-started) in a vault. References must follow a [specific format](/gateway/latest/plan-and-deploy/security/secrets-management/reference-format).
          type: string
          x-referenceable: true
        cert_alt:
          description: PEM-encoded public certificate chain of the alternate SSL key pair. This should only be set if you have both RSA and ECDSA types of certificate available and would like Kong to prefer serving using ECDSA certs when client advertises support for it. This field is _referenceable_, which means it can be securely stored as a [secret](/gateway/latest/plan-and-deploy/security/secrets-management/getting-started) in a vault. References must follow a [specific format](/gateway/latest/plan-and-deploy/security/secrets-management/reference-format).
          type: string
          nullable: true
          x-referenceable: true
        created_at:
          description: Unix epoch when the resource was created.
          type: integer
          nullable: true
        id:
          description: A string representing a UUID (universally unique identifier).
          type: string
          nullable: true
        key:
          description: PEM-encoded private key of the SSL key pair. This field is _referenceable_, which means it can be securely stored as a [secret](/gateway/latest/plan-and-deploy/security/secrets-management/getting-started) in a vault. References must follow a [specific format](/gateway/latest/plan-and-deploy/security/secrets-management/reference-format).
          type: string
          x-encrypted: true
          x-referenceable: true
        key_alt:
          description: PEM-encoded private key of the alternate SSL key pair. This should only be set if you have both RSA and ECDSA types of certificate available and would like Kong to prefer serving using ECDSA certs when client advertises support for it. This field is _referenceable_, which means it can be securely stored as a [secret](/gateway/latest/plan-and-deploy/security/secrets-management/getting-started) in a vault. References must follow a [specific format](/gateway/latest/plan-and-deploy/security/secrets-management/reference-format).
          type: string
          nullable: true
          x-encrypted: true
          x-referenceable: true
        snis:
          type: array
          items:
            description: A string representing a wildcard host name, such as *.example.com.
            type: string
          nullable: true
        tags:
          description: An optional set of strings associated with the Certificate for grouping and filtering.
          type: array
          items:
            description: A string representing a tag.
            type: string
          nullable: true
        updated_at:
          description: Unix epoch when the resource was last updated.
          type: integer
          nullable: true
      example:
        cert: '-----BEGIN CERTIFICATE-----

          certificate-content

          -----END CERTIFICATE-----'
        id: b2f34145-0343-41a4-9602-4c69dec2f269
        key: '-----BEGIN PRIVATE KEY-----

          private-key-content

          -----END PRIVATE KEY-----'
      additionalProperties: false
      required:
      - cert
      - key
    GatewayUnauthorizedError:
      type: object
      properties:
        message:
          type: string
        status:
          type: integer
      required:
      - message
      - status
    Certificate_2:
      description: 'A certificate object represents a public certificate, and can be optionally paired with the corresponding private key. These objects are used by Kong to handle SSL/TLS termination for encrypted requests, or for use as a trusted CA store when validating peer certificate of client/service. Certificates are optionally associated with SNI objects to tie a cert/key pair to one or more hostnames. If intermediate certificates are required in addition to the main certificate, they should be concatenated together into one string according to the following order: main certificate on the top, followed by any intermediates.'
      type: object
      properties:
        cert:
          description: PEM-encoded public certificate chain of the SSL key pair. This field is _referenceable_, which means it can be securely stored as a [secret](/gateway/latest/plan-and-deploy/security/secrets-management/getting-started) in a vault. References must follow a [specific format](/gateway/latest/plan-and-deploy/security/secrets-management/reference-format).
          type: string
          x-referenceable: true
        cert_alt:
          description: PEM-encoded public certificate chain of the alternate SSL key pair. This should only be set if you have both RSA and ECDSA types of certificate available and would like Kong to prefer serving using ECDSA certs when client advertises support for it. This field is _referenceable_, which means it can be securely stored as a [secret](/gateway/latest/plan-and-deploy/security/secrets-management/getting-started) in a vault. References must follow a [specific format](/gateway/latest/plan-and-deploy/security/secrets-management/reference-format).
          type: string
          nullable: true
          x-referenceable: true
        created_at:
          description: Unix epoch when the resource was created.
          type: integer
          nullable: true
        id:
          description: A string representing a UUID (universally unique identifier).
          type: string
          nullable: true
        key:
          description: PEM-encoded private key of the SSL key pair. This field is _referenceable_, which means it can be securely stored as a [secret](/gateway/latest/plan-and-deploy/security/secrets-management/getting-started) in a vault. References must follow a [specific format](/gateway/latest/plan-and-deploy/security/secrets-management/reference-format).
          type: string
          x-encrypted: true
          x-referenceable: true
        key_alt:
          description: PEM-encoded private key of the alternate SSL key pair. This should only be set if you have both RSA and ECDSA types of certificate available and would like Kong to prefer serving using ECDSA certs when client advertises support for it. This field is _referenceable_, which means it can be securely stored as a [secret](/gateway/latest/plan-and-deploy/security/secrets-management/getting-started) in a vault. References must follow a [specific format](/gateway/latest/plan-and-deploy/security/secrets-management/reference-format).
          type: string
          nullable: true
          x-encrypted: true
          x-referenceable: true
        snis:
          type: array
          items:
            description: A string representing a wildcard host name, such as *.example.com.
            type: string
          nullable: true
        tags:
          description: An optional set of strings associated with the Certificate for grouping and filtering.
          type: array
          items:
            description: A string representing a tag.
            type: string
          nullable: true
        updated_at:
          description: Unix epoch when the resource was last updated.
          type: integer
          nullable: true
      example:
        cert: '-----BEGIN CERTIFICATE-----

          certificate-content

          -----END CERTIFICATE-----'
        id: b2f34145-0343-41a4-9602-4c69dec2f269
        key: '-----BEGIN PRIVATE KEY-----

          private-key-content

          -----END PRIVATE KEY-----'
      additionalProperties: false
      required:
      - cert
      - key
    PaginationNextResponse:
      description: URI to the next page (may be null)
      type: string
    PaginationOffsetResponse:
      description: Offset is used to paginate through the API. Provide this value to the next list operation to fetch the next page
      type: string
  responses:
    HTTP401Error:
      description: Unauthorized
      content:
        application/json:
          examples:
            DuplicateApiKey:
              summary: Duplicate API key found
              value:
                message: Duplicate API key found
                status: 401
            InvalidAuthCred:
              summary: Invalid authentication credentials
              value:
                message: Unauthorized
                status: 401
            NoAPIKey:
              summary: No API key found
              value:
                message: No API key found in request
                status: 401
          schema:
            $ref: '#/components/schemas/GatewayUnauthorizedError'
    HTTP401Error_2:
      description: Unauthorized
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/GatewayUnauthorizedError'
  parameters:
    CertificateId:
      description: ID of the Certificate to lookup
      example: ddf3cdaa-3329-4961-822a-ce6dbd38eff7
      in: path
      name: CertificateId
      required: true
      schema:
        type: string
      x-speakeasy-match: id
    Workspace:
      description: The name of the workspace
      in: path
      name: workspace
      required: true
      schema:
        type: string
        example: team-payments
        default: default
    PaginationSize:
      description: Number of resources to be returned.
      in: query
      name: size
      schema:
        type: integer
        default: 100
        maximum: 1000
        minimum: 1
    controlPlaneId:
      name: controlPlaneId
      in: path
      required: true
      schema:
        type: string
        format: uuid
        example: 9524ec7d-36d9-465d-a8c5-83a3c9390458
      description: The UUID of your control plane. This variable is available in the Konnect manager.
      x-speakeasy-param-force-new: true
    CertificateId_2:
      description: ID of the Certificate to lookup
      example: ddf3cdaa-3329-4961-822a-ce6dbd38eff7
      in: path
      name: CertificateId
      required: true
      schema:
        type: string
    PaginationOffset:
      allowEmptyValue: true
      description: Offset from which to return the next set of resources. Use the value of the 'offset' field from the response of a list operation as input here to paginate through all the resources
      in: query
      name: offset
      schema:
        type: string
    PaginationTagsFilter:
      allowEmptyValue: true
      description: A list of tags to filter the list of resources on. Multiple tags can be concatenated using ',' to mean AND or using '/' to mean OR.
      example: tag1,tag2
      in: query
      name: tags
      schema:
        type: string
  securitySchemes:
    adminToken:
      in: header
      name: Kong-Admin-Token
      type: apiKey
    personalAccessToken:
      type: http
      scheme: bearer
      bearerFormat: Token
      description: The personal access token is meant to be used as an alternative to basic-auth when accessing Konnect via APIs. You can generate a Personal Access Token (PAT) from the personal access token page in the Konnect dashboard.
    systemAccountAccessToken:
      type: http
      scheme: bearer
      bearerFormat: Token
      description: 'The system account access token is meant for automations and integrations that are not directly associated with a human identity.

        You can generate a system account Access Token by creating a system account and then obtaining a system account access token for that account.

        The access token must be passed in the header of a request, for example:

        `curl -X GET ''https://global.api.konghq.com/v2/users/'' --header ''Authorization: Bearer spat_i2Ej...''`

        '
    konnectAccessToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: The Konnect access token is meant to be used by the Konnect dashboard and the decK CLI to authenticate with.
    serviceAccessToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: 'The Service access token is meant to be used between internal services.

        '
externalDocs:
  description: Documentation for Kong Gateway and its APIs
  url: https://developer.konghq.com
x-refined-from:
- kong-gateway-admin-api.yml
- kong-konnect-platform-api.yml