compute

POST /v1/certificates/orders

Start a certificate order. Spends nothing.

Tutti gli endpoint compute

Autenticazione

Invia una chiave API come token di tipo bearer. La chiave deve disporre dell'autorizzazione billing.payment.manage; una chiave sprovvista di tale autorizzazione viene rifiutata con 403 anziché 404.

Questo endpoint non richiede alcun ID organizzazione. La tua chiave identifica già l'organizzazione a cui appartiene e la risposta è limitata ad essa.

Provalo

Sostituisci qualsiasi elemento tra parentesi angolari con i tuoi valori e il segnaposto key con una chiave dalla tua dashboard.

curl -X POST https://api.zinndigital.com/v1/certificates/orders \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "product_code": <string>, "common_name": <string>, "currency": <string> }'

Hai effettuato l'accesso? La console API nella tua dashboard inserisce il tuo ID organizzazione reale e la tua chiave personale, ed esegue la richiesta sull'API live in modo da poter vedere la risposta effettiva. Apri questo endpoint nella console API

Dettagli

⭐ **This does NOT buy anything** — `submit` does. The split exists so the refusals a customer can act on arrive while they are still on the screen rather than as a failed background job, and so a half-filled form can never place an order. ⛔ Answers `422` when the product does not cover what was asked for: a wildcard name on a non-wildcard certificate, more domains than the **price** includes, a term the authority does not sell, or an account not in good standing. Each of those is an order the authority would happily charge for and never issue. Requires `billing.payment.manage`.

Corpo della richiesta

NomeTipoObbligatorioChe cos'è
product_codestring
common_namestringThe primary domain. A leading `*.` is a wildcard and is refused on a product that does not cover one — the authority would accept it at order time and refuse it at issuance, aft…
currencystring
period_yearsintegerNo
domainsstring[]NoAdditional names. ⛔ Capped by the product's `included_domains` — what the **price** covers — not by what the authority would technically allow, because it bills names beyond the…

Risposta

NomeTipoObbligatorioChe cos'è
idUuidUUIDv7 identifier — sortable by creation time (docs/02 §8).
product_codestringThe stable machine key (`positive_ssl`). ⛔ Match on this, never on `product_name` — the name is the certificate authority's marketing string and can be corrected without the pro…
product_namestringWhat the customer reads — the authority's own product name (`PositiveSSL`, `S/MIME Personal`, `Unified Communications Certificate (UCC)`). ⛔ Never a translation key: these are t…
statestring<pending, awaiting_validation, issued, cancelled, failed, expired>⛔⛔ **`awaiting_validation` means PAID AND NOT ISSUED.** The authority charges at order time and then waits for the customer to prove they control the domain. It is deliberately…
common_namestringThe primary domain on the certificate.
domainsstring[]Additional names (SANs). Empty for a single-domain product.
period_yearsinteger
price_minorintegerWhat the customer is charged, frozen at order. A copy rather than a join, so an operator repricing the catalogue cannot move an existing bill.
currencystring
validation_instructionsstringWhat the customer must still do, in the authority's own words. ⭐ Carried as text rather than parsed: every authority words it differently, and a half-parsed instruction is worse…
certificate_pemstringThe issued certificate. ⭐ Public by nature — it is served to every visitor of the site — which is why it is returned here while its **private key never is**: a customer-generate…
chain_pemstring
messagestringWhy it failed or was cancelled, in a sentence the customer reads.
ordered_atstring
issued_atstring
expires_atstring
days_until_expiryintegerWhole days until `expires_at`, negative once it has lapsed. ⛔ `null` and `0` are DIFFERENT answers and a client must not collapse them: `null` means we could not read an expiry…
renewablebooleanWhether to offer a re-order now — issued, inside the 30-day window, and with no renewal already in flight. ⛔ Computed here rather than left to a client to derive from `expires_a…
free_alternative_existsbooleanWhether Let's Encrypt issues this kind of certificate for nothing. Carried onto the renewal prompt for the same reason it is on the buy screen: say so **before** asking somebody…
renewal_ofUuidThe order this one renews, so a client can show the chain.
last_reminded_atstringWhen the renewal sweep last REACHED this order — which is not the same as when it last emailed about it. ⛔ The sweep stamps this for every row it reaches **including the ones it…

Errori che questo endpoint può restituire

401 · 403 · 422 · 429