compute

POST /v1/certificates/orders/{orderId}/renew

Start the successor order for an expiring certificate.

כל נקודות הקצה מסוג compute

אימות

שלחו מפתח API כאסימון נושא (bearer token). על המפתח לכלול את הרשאה billing.payment.manage; מפתח שאינו כולל אותה יידחה בסטטוס 403, ולא 404.

נקודת קצה זו אינה דורשת מזהה ארגון. המפתח שלך כבר מזהה את הארגון שאליו הוא שייך, והתגובה מוגבלת אליו בלבד.

נסה זאת

החלף כל דבר בסוגריים זוויתיים בערכים משלך, ואת מציין מיקום המפתח במפתח מלוח הבקרה שלך.

curl -X POST https://api.zinndigital.com/v1/certificates/orders/{orderId}/renew \
  -H "Authorization: Bearer zdk_live_…"

מחובר? קונסולת ה-API בלוח הבקרה שלך מזינה את מזהה הארגון האמיתי שלך ואת המפתח שלך, ומריצה את הבקשה מול ה-API הפיזי כך שתוכל לראות את התגובה בפועל. פתח נקודת קצה זו במסוף ה-API

פרטים

⛔⛔ **A renewal is a FRESH ORDER with a FRESH VALIDATION, not a flag.** The authority re-issues against a new CSR and re-runs domain control, so this creates a `pending` successor seeded from the expiring order and **spends nothing**. The customer then supplies a CSR to `submitCertificateOrder` exactly as they did the first time, which is the call that charges. Anything modelling renewal as an auto-renew toggle silently produces orders nobody validates — paid for, `awaiting_validation`, and never issued. ⭐ **Idempotent**, so it answers `200` rather than `201`: a double-click, a retried activity and an impatient customer all reach this, and it returns the existing live successor rather than buying a second certificate. Requires `billing.payment.manage`. ⚠️ An organisation that is not in good standing is refused **with a reason** (§2.46), never silently — the existing certificate keeps working until it expires either way, and "my renew button does nothing" is indistinguishable from a broken product.

פרמטרים

שםסוגנדרשמה זה
orderId (path)UuidכןThe order's id, as `listCertificateOrders` reports it. Ours (UUIDv7).

תשובה

שםסוגנדרשמה זה
idUuidכןUUIDv7 identifier — sortable by creation time (docs/02 §8).
product_codestringכןThe stable machine key (`positive_ssl`). ⛔ Match on this, never on `product_name` — the name is the certificate authority's marketing string and can be corrected without the pro…
product_namestringכןWhat the customer reads — the authority's own product name (`PositiveSSL`, `S/MIME Personal`, `Unified Communications Certificate (UCC)`). ⛔ Never a translation key: these are t…
statestring<pending, awaiting_validation, issued, cancelled, failed, expired>כן⛔⛔ **`awaiting_validation` means PAID AND NOT ISSUED.** The authority charges at order time and then waits for the customer to prove they control the domain. It is deliberately…
common_namestringכןThe primary domain on the certificate.
domainsstring[]כןAdditional names (SANs). Empty for a single-domain product.
period_yearsintegerכן
price_minorintegerכןWhat the customer is charged, frozen at order. A copy rather than a join, so an operator repricing the catalogue cannot move an existing bill.
currencystringכן
validation_instructionsstringכןWhat the customer must still do, in the authority's own words. ⭐ Carried as text rather than parsed: every authority words it differently, and a half-parsed instruction is worse…
certificate_pemstringכןThe issued certificate. ⭐ Public by nature — it is served to every visitor of the site — which is why it is returned here while its **private key never is**: a customer-generate…
chain_pemstringכן
messagestringכןWhy it failed or was cancelled, in a sentence the customer reads.
ordered_atstringכן
issued_atstringכן
expires_atstringכן
days_until_expiryintegerכןWhole days until `expires_at`, negative once it has lapsed. ⛔ `null` and `0` are DIFFERENT answers and a client must not collapse them: `null` means we could not read an expiry…
renewablebooleanכןWhether to offer a re-order now — issued, inside the 30-day window, and with no renewal already in flight. ⛔ Computed here rather than left to a client to derive from `expires_a…
free_alternative_existsbooleanכןWhether Let's Encrypt issues this kind of certificate for nothing. Carried onto the renewal prompt for the same reason it is on the buy screen: say so **before** asking somebody…
renewal_ofUuidכןThe order this one renews, so a client can show the chain.
last_reminded_atstringכןWhen the renewal sweep last REACHED this order — which is not the same as when it last emailed about it. ⛔ The sweep stamps this for every row it reaches **including the ones it…

שגיאות שנקודה קצה זו עשויה להחזיר

401 · 403 · 404 · 422 · 429 · 503