compute

POST /v1/certificates/orders/{orderId}/submit

Buy the certificate. This spends money.

すべての compute エンドポイント

すべての開発者向けドキュメント

認証

ベアラー トークンとして API キーを送信します。キーには billing.payment.manage 権限が付与されている必要があります。権限のないキーは 404 ではなく 403 で拒否されます。

このエンドポイントは組織IDを受け付けません。お使いのキーによって所属する組織がすでに特定されており、レスポンスはその組織にスコープされます。

試してみる

アングルブラケット内のすべてをご自身の値に置き換え、キーのプレースホルダーをご利用中のダッシュボードのキーに置き換えてください。

curl -X POST https://api.zinndigital.com/v1/certificates/orders/{orderId}/submit \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "csr_pem": <string> }'

ログインしていますか?ダッシュボード内のAPIコンソールでは、実際の組織IDやお客様ご自身のキーが自動入力され、ライブAPIに対してリクエストが実行されるため、実際のレスポンスを確認することができます。 API コンソールでこのエンドポイントを開く

詳細

⛔⛔ This is the call that charges. It is a separate endpoint from the one that creates the order precisely so a client cannot buy while a form is half filled in. ⛔⛔ The CSR is required and is checked three times — here, in the service and in the driver. That is not belt-and-braces: the authority accepts an order without one, charges for it, and issues nothing. Two such orders were created against our own account on 2026-08-29 by a probe reading validation errors, and the giveaway is how unlike a purchase they look — no common name, no issue date (docs/272 §9). ⭐ A customer-generated CSR is the better path and the one to encourage: the private key then never leaves their machine. Answers 503 when the authority could not be reached — in which case the order is recorded and reconciled rather than lost. Requires billing.payment.manage.

パラメータ

名前タイプ必須これがその内容です
orderId (path)UuidはいThe order's id, as listCertificateOrders reports it. Ours (UUIDv7).

リクエスト本文

名前タイプ必須これがその内容です
csr_pemstringはいThe certificate signing request, PEM. ⛔ Required. Without it the authority has nothing to sign and the order is billed and permanently unusable.

返信

名前タイプ必須これがその内容です
idUuidはいUUIDv7 identifier — sortable by creation time (docs/02 §8).
product_codestringはいThe stable machine key (positive_ssl). ⛔ Match on this, never on product_name — the name is the certificate authority's marketing string and can be corrected without the…
product_namestringはいWhat the customer reads — the authority's own product name (PositiveSSL, S/MIME Personal, Unified Communications Certificate (UCC)). ⛔ Never a translation key: these are…
statestring<pending, awaiting_validation, issued, cancelled, failed, expired>はい⛔⛔ awaiting_validation means PAID AND NOT ISSUED. The authority charges at order time and then waits for the customer to prove they control the domain. It is deliberately…
common_namestringはいThe primary domain on the certificate.
domainsstring[]はいAdditional names (SANs). Empty for a single-domain product.
period_yearsintegerはい
price_minorintegerはいWhat the customer is charged, frozen at order. A copy rather than a join, so an operator repricing the catalogue cannot move an existing bill.
currencystringはい
validation_instructionsstringはいWhat the customer must still do, in the authority's own words. ⭐ Carried as text rather than parsed: every authority words it differently, and a half-parsed instruction is worse…
certificate_pemstringはいThe issued certificate. ⭐ Public by nature — it is served to every visitor of the site — which is why it is returned here while its private key never is: a customer-generated…
chain_pemstringはい
messagestringはいWhy it failed or was cancelled, in a sentence the customer reads.
ordered_atstringはい
issued_atstringはい
expires_atstringはい
days_until_expiryintegerはいWhole days until expires_at, negative once it has lapsed. ⛔ null and 0 are DIFFERENT answers and a client must not collapse them: null means we could not read an expiry…
renewablebooleanはいWhether to offer a re-order now — issued, inside the 30-day window, and with no renewal already in flight. ⛔ Computed here rather than left to a client to derive from…
free_alternative_existsbooleanはいWhether Let's Encrypt issues this kind of certificate for nothing. Carried onto the renewal prompt for the same reason it is on the buy screen: say so before asking somebody…
renewal_ofUuidはいThe order this one renews, so a client can show the chain.
last_reminded_atstringはいWhen the renewal sweep last REACHED this order — which is not the same as when it last emailed about it. ⛔ The sweep stamps this for every row it reaches…

このエンドポイントが返すエラー

401 · 403 · 404 · 422 · 429 · 503