compute
POST /v1/certificates/orders/{orderId}/renew
Start the successor order for an expiring certificate.
Authentification
Envoyez une clé API en tant que jeton du porteur. La clé doit posséder l'autorisation billing.payment.manage ; une clé qui ne l'a pas est refusée avec le code 403, et non 404.
Cet endpoint ne prend aucun identifiant d'organisation. Votre clé identifie déjà l'organisation à laquelle elle appartient, et la réponse y est limitée.
Essayer
Remplacez tout ce qui se trouve entre crochets par vos propres valeurs, et le espace réservé à la clé par une clé de votre tableau de bord.
curl -X POST https://api.zinndigital.com/v1/certificates/orders/{orderId}/renew \
-H "Authorization: Bearer zdk_live_…"Connecté ? La console d'API de votre tableau de bord saisit votre véritable ID d'organisation ainsi que votre propre clé, et exécute la requête sur l'API de production afin que vous puissiez voir la réponse réelle. Ouvrir ce point de terminaison dans la console API
Détails
⛔⛔ A renewal is a FRESH ORDER with a FRESH VALIDATION, not a flag. The authority re-issues against a new CSR and re-runs domain control, so this creates a pending successor seeded from the expiring order and spends nothing. The customer then supplies a CSR to submitCertificateOrder exactly as they did the first time, which is the call that charges. Anything modelling renewal as an auto-renew toggle silently produces orders nobody validates — paid for, awaiting_validation, and never issued. ⭐ Idempotent, so it answers 200 rather than 201: a double-click, a retried activity and an impatient customer all reach this, and it returns the existing live successor rather than buying a second certificate. Requires billing.payment.manage. ⚠️ An organisation that is not in good standing is refused with a reason (§2.46), never silently — the existing certificate keeps working until it expires either way, and "my renew button does nothing" is indistinguishable from a broken product.
Paramètres
| Nom | Type | Obligatoire | Qu'est-ce que c'est |
|---|---|---|---|
orderId (path) | Uuid | Oui | The order's id, as listCertificateOrders reports it. Ours (UUIDv7). |
Réponse
| Nom | Type | Obligatoire | Qu'est-ce que c'est |
|---|---|---|---|
id | Uuid | Oui | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
product_code | string | Oui | The stable machine key (positive_ssl). ⛔ Match on this, never on product_name — the name is the certificate authority's marketing string and can be corrected without the… |
product_name | string | Oui | What the customer reads — the authority's own product name (PositiveSSL, S/MIME Personal, Unified Communications Certificate (UCC)). ⛔ Never a translation key: these are… |
state | string<pending, awaiting_validation, issued, cancelled, failed, expired> | Oui | ⛔⛔ awaiting_validation means PAID AND NOT ISSUED. The authority charges at order time and then waits for the customer to prove they control the domain. It is deliberately… |
common_name | string | Oui | The primary domain on the certificate. |
domains | string[] | Oui | Additional names (SANs). Empty for a single-domain product. |
period_years | integer | Oui | — |
price_minor | integer | Oui | What the customer is charged, frozen at order. A copy rather than a join, so an operator repricing the catalogue cannot move an existing bill. |
currency | string | Oui | — |
validation_instructions | string | Oui | What the customer must still do, in the authority's own words. ⭐ Carried as text rather than parsed: every authority words it differently, and a half-parsed instruction is worse… |
certificate_pem | string | Oui | The issued certificate. ⭐ Public by nature — it is served to every visitor of the site — which is why it is returned here while its private key never is: a customer-generated… |
chain_pem | string | Oui | — |
message | string | Oui | Why it failed or was cancelled, in a sentence the customer reads. |
ordered_at | string | Oui | — |
issued_at | string | Oui | — |
expires_at | string | Oui | — |
days_until_expiry | integer | Oui | Whole days until expires_at, negative once it has lapsed. ⛔ null and 0 are DIFFERENT answers and a client must not collapse them: null means we could not read an expiry… |
renewable | boolean | Oui | Whether to offer a re-order now — issued, inside the 30-day window, and with no renewal already in flight. ⛔ Computed here rather than left to a client to derive from… |
free_alternative_exists | boolean | Oui | Whether Let's Encrypt issues this kind of certificate for nothing. Carried onto the renewal prompt for the same reason it is on the buy screen: say so before asking somebody… |
renewal_of | Uuid | Oui | The order this one renews, so a client can show the chain. |
last_reminded_at | string | Oui | When the renewal sweep last REACHED this order — which is not the same as when it last emailed about it. ⛔ The sweep stamps this for every row it reaches… |
Erreurs que cet point de terminaison peut renvoyer
401 · 403 · 404 · 422 · 429 · 503