compute

POST /v1/certificates/orders/{orderId}/submit

Buy the certificate. This spends money.

Alle compute Endpunkte

Authentifizierung

Senden Sie einen API-Schlüssel als Bearer-Token. Der Schlüssel muss über die Berechtigung billing.payment.manage verfügen; ein Schlüssel ohne diese wird mit 403 statt 404 abgelehnt.

Dieser Endpunkt erfordert keine Organisations-ID. Ihr Schlüssel identifiziert bereits die zugehörige Organisation, und die Antwort ist entsprechend eingeschränkt.

Ausprobieren

Ersetzen Sie alles in spitzen Klammern durch Ihre eigenen Werte und den Platzhalter für den Schlüssel durch einen Schlüssel aus Ihrem Dashboard.

curl -X POST https://api.zinndigital.com/v1/certificates/orders/{orderId}/submit \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "csr_pem": <string> }'

Angemeldet? Die API-Konsole in Ihrem Dashboard trägt automatisch Ihre echte Organisations-ID sowie Ihren eigenen Schlüssel ein und führt die Anfrage gegen die Live-API aus, sodass Sie die tatsächliche Antwort sehen können. Öffnen Sie diesen Endpunkt in der API-Konsole

Details

⛔⛔ **This is the call that charges.** It is a separate endpoint from the one that creates the order precisely so a client cannot buy while a form is half filled in. ⛔⛔ **The CSR is required and is checked three times** — here, in the service and in the driver. That is not belt-and-braces: the authority accepts an order **without** one, charges for it, and issues nothing. Two such orders were created against our own account on 2026-08-29 by a probe reading validation errors, and the giveaway is how unlike a purchase they look — no common name, no issue date (`docs/272` §9). ⭐ A customer-generated CSR is the better path and the one to encourage: the private key then never leaves their machine. Answers `503` when the authority could not be reached — in which case the order is recorded and reconciled rather than lost. Requires `billing.payment.manage`.

Parameter

NameTypErforderlichWas es ist
orderId (path)UuidJaThe order's id, as `listCertificateOrders` reports it. Ours (UUIDv7).

Anfragekörper

NameTypErforderlichWas es ist
csr_pemstringJaThe certificate signing request, PEM. ⛔ Required. Without it the authority has nothing to sign and the order is billed and permanently unusable.

Antwort

NameTypErforderlichWas es ist
idUuidJaUUIDv7 identifier — sortable by creation time (docs/02 §8).
product_codestringJaThe stable machine key (`positive_ssl`). ⛔ Match on this, never on `product_name` — the name is the certificate authority's marketing string and can be corrected without the pro…
product_namestringJaWhat the customer reads — the authority's own product name (`PositiveSSL`, `S/MIME Personal`, `Unified Communications Certificate (UCC)`). ⛔ Never a translation key: these are t…
statestring<pending, awaiting_validation, issued, cancelled, failed, expired>Ja⛔⛔ **`awaiting_validation` means PAID AND NOT ISSUED.** The authority charges at order time and then waits for the customer to prove they control the domain. It is deliberately…
common_namestringJaThe primary domain on the certificate.
domainsstring[]JaAdditional names (SANs). Empty for a single-domain product.
period_yearsintegerJa
price_minorintegerJaWhat the customer is charged, frozen at order. A copy rather than a join, so an operator repricing the catalogue cannot move an existing bill.
currencystringJa
validation_instructionsstringJaWhat the customer must still do, in the authority's own words. ⭐ Carried as text rather than parsed: every authority words it differently, and a half-parsed instruction is worse…
certificate_pemstringJaThe issued certificate. ⭐ Public by nature — it is served to every visitor of the site — which is why it is returned here while its **private key never is**: a customer-generate…
chain_pemstringJa
messagestringJaWhy it failed or was cancelled, in a sentence the customer reads.
ordered_atstringJa
issued_atstringJa
expires_atstringJa
days_until_expiryintegerJaWhole days until `expires_at`, negative once it has lapsed. ⛔ `null` and `0` are DIFFERENT answers and a client must not collapse them: `null` means we could not read an expiry…
renewablebooleanJaWhether to offer a re-order now — issued, inside the 30-day window, and with no renewal already in flight. ⛔ Computed here rather than left to a client to derive from `expires_a…
free_alternative_existsbooleanJaWhether Let's Encrypt issues this kind of certificate for nothing. Carried onto the renewal prompt for the same reason it is on the buy screen: say so **before** asking somebody…
renewal_ofUuidJaThe order this one renews, so a client can show the chain.
last_reminded_atstringJaWhen the renewal sweep last REACHED this order — which is not the same as when it last emailed about it. ⛔ The sweep stamps this for every row it reaches **including the ones it…

Fehler, die dieser Endpunkt zurückgeben kann

401 · 403 · 404 · 422 · 429 · 503