hosting

GET /v1/sites/{siteId}/certificate

The TLS certificate serving this site.

Все эндпоинты hosting

Вся документация для разработчиков

Аутентификация

Передайте API-ключ в качестве маркера носителя (bearer token). Эта конечная точка не указывает конкретное разрешение в спецификации, поэтому предоставьте своему ключу минимум необходимых прав и проверьте ответ, вместо того чтобы делать предположения.

Этот эндпоинт не принимает идентификатор организации. Ваш ключ уже определяет организацию, к которой он принадлежит, и ответ ограничивается ее рамками.

Попробовать

Замените всё в угловых скобках на собственные значения, а плейсхолдер ключа — на ключ из вашей панели управления.

curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/certificate \
  -H "Authorization: Bearer zdk_live_…"

Вошли в систему? Консоль API в вашей панели управления автоматически подставляет реальный идентификатор вашей организации и ваш собственный ключ, а также выполняет запрос к работающему API, чтобы вы могли увидеть актуальный ответ. Откройте эту конечную точку в API-консоли

Подробнее

Whether this site is served over HTTPS on its own name, and if not, why not. Sites on our own fleet are served a per-vhost certificate the platform obtains itself by ACME (owner ruling 2026-09-07, docs/537), because not every site sits behind a CDN and a site with DNS pointed straight at our fleet needs a publicly-trusted certificate of its own. ⛔ state is never simply "no". issued / pending / failed with a reason are three different facts, and the failure directions are asymmetric: behind Cloudflare Full (strict) an uncovered host answers HTTP 526 — a hard outage — while behind plain Full it is a silent downgrade. A payload that could only say "no" would leave a customer looking at a broken site with no explanation. ⛔ covered and serving are DIFFERENT and both are returned. covered means a CA signed it; serving means the box actually presents it. A certificate that exists and is not installed serves nobody, and a screen built from covered alone would report a healthy site to a customer whose visitors see a name-mismatch warning. scope is shared when the site is covered by one platform certificate for a registrable domain we own — the ordinary case for a preview hostname, where a single wildcard covers every site on that domain rather than one certificate each.

Параметры

ИмяТипОбязательноЧто это
siteId (path)UuidДаSite ID (UUIDv7).

Ответ

ИмяТипОбязательноЧто это
site_idstringДа
statestring<none, pending, issued, failed, retired>Даnone means nothing has been attempted, which is a DIFFERENT fact from failed. Collapsing them would leave a screen unable to tell a new site from a broken one.
scopestring<site, shared>Даshared when one platform certificate for a registrable domain we own covers this site — the ordinary case for a preview hostname.
shared_suffixstringНетThe registrable domain a shared certificate covers. Empty when scope is site.
hostnamesstring[]ДаRead back off the ISSUED artefact, never from what was requested — a CA that trimmed a name must not be reported as covering it.
coveredbooleanДаA certificate authority has signed a certificate for this site.
servingbooleanДа⛔ The box actually presents it. DIFFERENT from covered: a certificate that exists in Vault and is not installed serves nobody.
failure_reasonstringНет
failure_detailstringНет
not_afterstringНет
installed_atstringНет
environmentstringНет⛔ Travels because a staging certificate is trusted by NO browser. A screen showing one as simply "issued" would report green for a site every visitor sees a warning on.
wildcard_coveredbooleanНетWhether subdomains are covered. A wildcard needs DNS-01, which needs a TXT record in the zone, so a domain whose DNS we do not manage cannot have one.

Ошибки, которые может возвращать этот эндпоинт

401 · 403 · 404