compute

DELETE /v1/certificates/orders/{orderId}

Cancel an order inside the authority's refund window.

All compute endpoints

Authentication

Send an API key as a bearer token. The key must carry the billing.payment.manage permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X DELETE https://api.zinndigital.com/v1/certificates/orders/{orderId} \
  -H "Authorization: Bearer zdk_live_…"

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

⛔⛔ Answers `503` and leaves the order **unchanged** if the authority cannot be reached. Reporting a cancellation we did not achieve would remove the order from every screen while the charge stands. Requires `billing.payment.manage`.

Parameters

NameTypeRequiredWhat it is
orderId (path)UuidYesThe order's id, as `listCertificateOrders` reports it. Ours (UUIDv7).

Response

NameTypeRequiredWhat it is
idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).
product_codestringYesThe stable machine key (`positive_ssl`). ⛔ Match on this, never on `product_name` — the name is the certificate authority's marketing string and can be corrected without the pro…
product_namestringYesWhat the customer reads — the authority's own product name (`PositiveSSL`, `S/MIME Personal`, `Unified Communications Certificate (UCC)`). ⛔ Never a translation key: these are t…
statestring<pending, awaiting_validation, issued, cancelled, failed, expired>Yes⛔⛔ **`awaiting_validation` means PAID AND NOT ISSUED.** The authority charges at order time and then waits for the customer to prove they control the domain. It is deliberately…
common_namestringYesThe primary domain on the certificate.
domainsstring[]YesAdditional names (SANs). Empty for a single-domain product.
period_yearsintegerYes
price_minorintegerYesWhat the customer is charged, frozen at order. A copy rather than a join, so an operator repricing the catalogue cannot move an existing bill.
currencystringYes
validation_instructionsstringYesWhat the customer must still do, in the authority's own words. ⭐ Carried as text rather than parsed: every authority words it differently, and a half-parsed instruction is worse…
certificate_pemstringYesThe issued certificate. ⭐ Public by nature — it is served to every visitor of the site — which is why it is returned here while its **private key never is**: a customer-generate…
chain_pemstringYes
messagestringYesWhy it failed or was cancelled, in a sentence the customer reads.
ordered_atstringYes
issued_atstringYes
expires_atstringYes
days_until_expiryintegerYesWhole days until `expires_at`, negative once it has lapsed. ⛔ `null` and `0` are DIFFERENT answers and a client must not collapse them: `null` means we could not read an expiry…
renewablebooleanYesWhether to offer a re-order now — issued, inside the 30-day window, and with no renewal already in flight. ⛔ Computed here rather than left to a client to derive from `expires_a…
free_alternative_existsbooleanYesWhether Let's Encrypt issues this kind of certificate for nothing. Carried onto the renewal prompt for the same reason it is on the buy screen: say so **before** asking somebody…
renewal_ofUuidYesThe order this one renews, so a client can show the chain.
last_reminded_atstringYesWhen the renewal sweep last REACHED this order — which is not the same as when it last emailed about it. ⛔ The sweep stamps this for every row it reaches **including the ones it…

Errors this endpoint can return

401 · 403 · 404 · 429 · 503