# Amazon Private CA

**Canonical:** https://apis.io/providers/amazon-private-ca/  
**Website:** https://aws.amazon.com/private-ca/  
**APIs profiled:** 23

AWS Private Certificate Authority (AWS Private CA) is a highly available, fully managed private CA service that helps you easily and securely manage the lifecycle of your private certificates. It allows you to create private CA hierarchies and issue X.509 certificates for your internal resources including TLS certificates for microservices, IoT devices, and user authentication.

## Kin Score — 51.3 / 100 (developing)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 51.3).

| Facet | Score |
|---|---|
| Discoverability | 68.5 |
| Contract Quality | 67.8 |
| Governance | 25.0 |
| Contract Governance | 25.0 |
| Operational Transparency | 26.3 |
| Developer Ergonomics | 47.6 |
| Commercial Clarity | 57.9 |
| Access Clarity | 57.9 |

## Agent readiness — 30.6 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | documented |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (23)

- **Amazon Private CA #X Amz Target=ACMPrivateCA.CreateCertificateAuthority API** — The #X Amz Target=ACMPrivateCA.CreateCertificateAuthority API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.createcertificateauthority.
- **Amazon Private CA #X Amz Target=ACMPrivateCA.CreateCertificateAuthorityAuditReport API** — The #X Amz Target=ACMPrivateCA.CreateCertificateAuthorityAuditReport API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.createcertificateauthorityauditre...
- **Amazon Private CA #X Amz Target=ACMPrivateCA.CreatePermission API** — The #X Amz Target=ACMPrivateCA.CreatePermission API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.createpermission.
- **Amazon Private CA #X Amz Target=ACMPrivateCA.DeleteCertificateAuthority API** — The #X Amz Target=ACMPrivateCA.DeleteCertificateAuthority API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.deletecertificateauthority.
- **Amazon Private CA #X Amz Target=ACMPrivateCA.DeletePermission API** — The #X Amz Target=ACMPrivateCA.DeletePermission API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.deletepermission.
- **Amazon Private CA #X Amz Target=ACMPrivateCA.DeletePolicy API** — The #X Amz Target=ACMPrivateCA.DeletePolicy API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.deletepolicy.
- **Amazon Private CA #X Amz Target=ACMPrivateCA.DescribeCertificateAuthority API** — The #X Amz Target=ACMPrivateCA.DescribeCertificateAuthority API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.describecertificateauthority.
- **Amazon Private CA #X Amz Target=ACMPrivateCA.DescribeCertificateAuthorityAuditReport API** — The #X Amz Target=ACMPrivateCA.DescribeCertificateAuthorityAuditReport API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.describecertificateauthorityaud...
- **Amazon Private CA #X Amz Target=ACMPrivateCA.GetCertificate API** — The #X Amz Target=ACMPrivateCA.GetCertificate API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.getcertificate.
- **Amazon Private CA #X Amz Target=ACMPrivateCA.GetCertificateAuthorityCertificate API** — The #X Amz Target=ACMPrivateCA.GetCertificateAuthorityCertificate API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.getcertificateauthoritycertificate.
- **Amazon Private CA #X Amz Target=ACMPrivateCA.GetCertificateAuthorityCsr API** — The #X Amz Target=ACMPrivateCA.GetCertificateAuthorityCsr API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.getcertificateauthoritycsr.
- **Amazon Private CA #X Amz Target=ACMPrivateCA.GetPolicy API** — The #X Amz Target=ACMPrivateCA.GetPolicy API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.getpolicy.
- **Amazon Private CA #X Amz Target=ACMPrivateCA.ImportCertificateAuthorityCertificate API** — The #X Amz Target=ACMPrivateCA.ImportCertificateAuthorityCertificate API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.importcertificateauthoritycertifi...
- **Amazon Private CA #X Amz Target=ACMPrivateCA.IssueCertificate API** — The #X Amz Target=ACMPrivateCA.IssueCertificate API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.issuecertificate.
- **Amazon Private CA #X Amz Target=ACMPrivateCA.ListCertificateAuthorities API** — The #X Amz Target=ACMPrivateCA.ListCertificateAuthorities API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.listcertificateauthorities.
- **Amazon Private CA #X Amz Target=ACMPrivateCA.ListPermissions API** — The #X Amz Target=ACMPrivateCA.ListPermissions API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.listpermissions.
- **Amazon Private CA #X Amz Target=ACMPrivateCA.ListTags API** — The #X Amz Target=ACMPrivateCA.ListTags API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.listtags.
- **Amazon Private CA #X Amz Target=ACMPrivateCA.PutPolicy API** — The #X Amz Target=ACMPrivateCA.PutPolicy API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.putpolicy.
- **Amazon Private CA #X Amz Target=ACMPrivateCA.RestoreCertificateAuthority API** — The #X Amz Target=ACMPrivateCA.RestoreCertificateAuthority API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.restorecertificateauthority.
- **Amazon Private CA #X Amz Target=ACMPrivateCA.RevokeCertificate API** — The #X Amz Target=ACMPrivateCA.RevokeCertificate API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.revokecertificate.
- **Amazon Private CA #X Amz Target=ACMPrivateCA.TagCertificateAuthority API** — The #X Amz Target=ACMPrivateCA.TagCertificateAuthority API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.tagcertificateauthority.
- **Amazon Private CA #X Amz Target=ACMPrivateCA.UntagCertificateAuthority API** — The #X Amz Target=ACMPrivateCA.UntagCertificateAuthority API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.untagcertificateauthority.
- **Amazon Private CA #X Amz Target=ACMPrivateCA.UpdateCertificateAuthority API** — The #X Amz Target=ACMPrivateCA.UpdateCertificateAuthority API from Amazon Private CA — 1 operation(s) for #x amz target=acmprivateca.updatecertificateauthority.

## Agentic access (1)

- **Amazon Private Ca Agentic Access** — 23 operations · 23 acting · 1 human-in-the-loop

## Security (4)

- **Amazon Private Ca Authentication** — apiKey · 1 scheme
- **Amazon Private Ca Domain Security** — TLSv1.3 · HSTS · DMARC
- **Amazon Private Ca Vulnerability Disclosure** — security.txt · contact published
- **Amazon Private Ca Trust Center** — PCI DSS, HIPAA, FedRAMP, GDPR, FIPS 140

## Plans (1)

- **Amazon Private Ca Plans Pricing**

## Use cases (5)

- **TLS for Internal Services** — Issue TLS certificates for microservices, APIs, and internal web applications.
- **IoT Device Authentication** — Provision unique X.509 certificates to IoT devices for mutual TLS authentication.
- **User and Workload Identity** — Issue certificates for user authentication and workload identity in zero-trust architectures.
- **Code Signing** — Sign software artifacts and container images with private CA-issued certificates.
- **VPN and Network Security** — Issue certificates for VPN clients and network devices for mutual authentication.

## Tags

Certificate Authority, Certificates, PKI, Security, X.509, TLS, IoT

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/amazon-private-ca/). Scores are computed from the provider's own public artifacts under a published rubric.
