compute

POST /v1/certificates/orders/{orderId}/submit

Buy the certificate. This spends money.

सबै compute इन्डपइन्टहरू

सबै विकासकर्ता कागजातहरू

प्रमाणीकरण

एपिआई कुञ्जीलाई बियरर टोकन (bearer token) को रूपमा पठाउनुहोस्। कुञ्जीसँग billing.payment.manage अनुमति हुनुपर्छ; अनुमति नभएको कुञ्जीलाई 404 होइन, 403 मार्फत अस्वीकार गरिन्छ।

यो इन्डपोइन्टले कुनै संस्थाको आइडी लिँदैन। तपाईंको कुञ्जीले यस अन्तर्गत पर्ने संस्थालाई पहिल्यै पहिचान गर्छ, र प्रतिक्रिया त्यसैमा सीमित हुन्छ।

प्रयास गर्नुहोस्

कोणीय कोष्ठकभित्र भएका जुनसुकै कुरालाई आफ्नो मानहरूद्वारा बदल्नुहोस्, र मुख्य स्थानहोल्डरलाई तपाईंको ड्यासबोर्डको कुञ्जीद्वारा बदल्नुहोस्।

curl -X POST https://api.zinndigital.com/v1/certificates/orders/{orderId}/submit \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "csr_pem": <string> }'

लगइन गर्नुभएको छ? तपाईंको ड्यासबोर्डमा रहेको API कन्सोलले तपाईंको वास्तविक संस्थाको आईडी र आफ्नै कुञ्जी भरिदिन्छ, र लाइभ API विरुद्ध अनुरोध चलाउँछ ताकि तपाईंले वास्तविक प्रतिक्रिया हेर्न सक्नुहोस्। यो एन्डपोइन्टलाई API कन्सोलमा खोल्नुहोस्

विवरणहरू

⛔⛔ This is the call that charges. It is a separate endpoint from the one that creates the order precisely so a client cannot buy while a form is half filled in. ⛔⛔ The CSR is required and is checked three times — here, in the service and in the driver. That is not belt-and-braces: the authority accepts an order without one, charges for it, and issues nothing. Two such orders were created against our own account on 2026-08-29 by a probe reading validation errors, and the giveaway is how unlike a purchase they look — no common name, no issue date (docs/272 §9). ⭐ A customer-generated CSR is the better path and the one to encourage: the private key then never leaves their machine. Answers 503 when the authority could not be reached — in which case the order is recorded and reconciled rather than lost. Requires billing.payment.manage.

प्यारामिटरहरू

नामप्रकारआवश्यकयो के हो
orderId (path)Uuidहुन्छThe order's id, as listCertificateOrders reports it. Ours (UUIDv7).

अनुरोध बडी

नामप्रकारआवश्यकयो के हो
csr_pemstringहुन्छThe certificate signing request, PEM. ⛔ Required. Without it the authority has nothing to sign and the order is billed and permanently unusable.

प्रतिक्रिया

नामप्रकारआवश्यकयो के हो
idUuidहुन्छUUIDv7 identifier — sortable by creation time (docs/02 §8).
product_codestringहुन्छThe stable machine key (positive_ssl). ⛔ Match on this, never on product_name — the name is the certificate authority's marketing string and can be corrected without the…
product_namestringहुन्छWhat the customer reads — the authority's own product name (PositiveSSL, S/MIME Personal, Unified Communications Certificate (UCC)). ⛔ Never a translation key: these are…
statestring<pending, awaiting_validation, issued, cancelled, failed, expired>हुन्छ⛔⛔ awaiting_validation means PAID AND NOT ISSUED. The authority charges at order time and then waits for the customer to prove they control the domain. It is deliberately…
common_namestringहुन्छThe primary domain on the certificate.
domainsstring[]हुन्छAdditional names (SANs). Empty for a single-domain product.
period_yearsintegerहुन्छ
price_minorintegerहुन्छWhat the customer is charged, frozen at order. A copy rather than a join, so an operator repricing the catalogue cannot move an existing bill.
currencystringहुन्छ
validation_instructionsstringहुन्छWhat the customer must still do, in the authority's own words. ⭐ Carried as text rather than parsed: every authority words it differently, and a half-parsed instruction is worse…
certificate_pemstringहुन्छThe issued certificate. ⭐ Public by nature — it is served to every visitor of the site — which is why it is returned here while its private key never is: a customer-generated…
chain_pemstringहुन्छ
messagestringहुन्छWhy it failed or was cancelled, in a sentence the customer reads.
ordered_atstringहुन्छ
issued_atstringहुन्छ
expires_atstringहुन्छ
days_until_expiryintegerहुन्छWhole days until expires_at, negative once it has lapsed. ⛔ null and 0 are DIFFERENT answers and a client must not collapse them: null means we could not read an expiry…
renewablebooleanहुन्छWhether to offer a re-order now — issued, inside the 30-day window, and with no renewal already in flight. ⛔ Computed here rather than left to a client to derive from…
free_alternative_existsbooleanहुन्छWhether Let's Encrypt issues this kind of certificate for nothing. Carried onto the renewal prompt for the same reason it is on the buy screen: say so before asking somebody…
renewal_ofUuidहुन्छThe order this one renews, so a client can show the chain.
last_reminded_atstringहुन्छWhen the renewal sweep last REACHED this order — which is not the same as when it last emailed about it. ⛔ The sweep stamps this for every row it reaches…

यो इन्डपोइन्टले फर्काउन सक्ने त्रुटिहरू

401 · 403 · 404 · 422 · 429 · 503