compute

POST /v1/certificates/orders/{orderId}/submit

Buy the certificate. This spends money.

Բոլոր compute վերջնակետերը

Նույնականացում

Ուղարկեք API բանալին որպես bearer token: Բանալին պետք է ունենա billing.payment.manage թույլտվությունը. առանց դրա բանալին մերժվում է 403, և ոչ թե 404 կարգավիճակով:

Այս վերջնակետը կազմակերպության ID չի ընդունում: Ձեր բանալին արդեն իսկ նույնականացնում է այն կազմակերպությունը, որին պատկանում է, և պատասխանը սահմանափակված է դրանով:

Փորձել

Փոխարինեք անկյունային փակագծերում գտնվող ցանկացած բան ձեր սեփական արժեքներով, և բանալու տեղապահը՝ ձեր վահանակի բանալիով:

curl -X POST https://api.zinndigital.com/v1/certificates/orders/{orderId}/submit \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "csr_pem": <string> }'

Մուտք գործե՞լ եք: Ձեր վահանակի API վահանակը լրացնում է ձեր իրական կազմակերպության ID-ն և ձեր սեփական բանալին և գործարկում է հարցումը ուղիղ API-ի դեմ, որպեսզի կարողանաք տեսնել փաստացի պատասխանը: Բացեք այս վերջնակետը API վահանակում

Մանրամասներ

⛔⛔ **This is the call that charges.** It is a separate endpoint from the one that creates the order precisely so a client cannot buy while a form is half filled in. ⛔⛔ **The CSR is required and is checked three times** — here, in the service and in the driver. That is not belt-and-braces: the authority accepts an order **without** one, charges for it, and issues nothing. Two such orders were created against our own account on 2026-08-29 by a probe reading validation errors, and the giveaway is how unlike a purchase they look — no common name, no issue date (`docs/272` §9). ⭐ A customer-generated CSR is the better path and the one to encourage: the private key then never leaves their machine. Answers `503` when the authority could not be reached — in which case the order is recorded and reconciled rather than lost. Requires `billing.payment.manage`.

Պարամետրեր

ԱնունՏեսակՊահանջվում էԻնչ է դա
orderId (path)UuidԱյոThe order's id, as `listCertificateOrders` reports it. Ours (UUIDv7).

Հարցման մարմին

ԱնունՏեսակՊահանջվում էԻնչ է դա
csr_pemstringԱյոThe certificate signing request, PEM. ⛔ Required. Without it the authority has nothing to sign and the order is billed and permanently unusable.

Պատասխան

ԱնունՏեսակՊահանջվում էԻնչ է դա
idUuidԱյոUUIDv7 identifier — sortable by creation time (docs/02 §8).
product_codestringԱյոThe stable machine key (`positive_ssl`). ⛔ Match on this, never on `product_name` — the name is the certificate authority's marketing string and can be corrected without the pro…
product_namestringԱյոWhat the customer reads — the authority's own product name (`PositiveSSL`, `S/MIME Personal`, `Unified Communications Certificate (UCC)`). ⛔ Never a translation key: these are t…
statestring<pending, awaiting_validation, issued, cancelled, failed, expired>Այո⛔⛔ **`awaiting_validation` means PAID AND NOT ISSUED.** The authority charges at order time and then waits for the customer to prove they control the domain. It is deliberately…
common_namestringԱյոThe primary domain on the certificate.
domainsstring[]ԱյոAdditional names (SANs). Empty for a single-domain product.
period_yearsintegerԱյո
price_minorintegerԱյոWhat the customer is charged, frozen at order. A copy rather than a join, so an operator repricing the catalogue cannot move an existing bill.
currencystringԱյո
validation_instructionsstringԱյոWhat the customer must still do, in the authority's own words. ⭐ Carried as text rather than parsed: every authority words it differently, and a half-parsed instruction is worse…
certificate_pemstringԱյոThe issued certificate. ⭐ Public by nature — it is served to every visitor of the site — which is why it is returned here while its **private key never is**: a customer-generate…
chain_pemstringԱյո
messagestringԱյոWhy it failed or was cancelled, in a sentence the customer reads.
ordered_atstringԱյո
issued_atstringԱյո
expires_atstringԱյո
days_until_expiryintegerԱյոWhole days until `expires_at`, negative once it has lapsed. ⛔ `null` and `0` are DIFFERENT answers and a client must not collapse them: `null` means we could not read an expiry…
renewablebooleanԱյոWhether to offer a re-order now — issued, inside the 30-day window, and with no renewal already in flight. ⛔ Computed here rather than left to a client to derive from `expires_a…
free_alternative_existsbooleanԱյոWhether Let's Encrypt issues this kind of certificate for nothing. Carried onto the renewal prompt for the same reason it is on the buy screen: say so **before** asking somebody…
renewal_ofUuidԱյոThe order this one renews, so a client can show the chain.
last_reminded_atstringԱյոWhen the renewal sweep last REACHED this order — which is not the same as when it last emailed about it. ⛔ The sweep stamps this for every row it reaches **including the ones it…

Այս վերջնակետի կողմից վերադարձվող սխալները

401 · 403 · 404 · 422 · 429 · 503