hosting
GET /v1/sites/{siteId}/certificate
The TLS certificate serving this site.
Автентифікація
Надішліть ключ API як маркер носія (bearer token). Ця кінцева точка не вказує конкретного дозволу в специфікації, тому надайте своєму ключу мінімально необхідні права та перевірте відповідь, замість того щоб припускати.
Цей кінцевий пункт не потребує ідентифікатора організації. Ваш ключ уже ідентифікує організацію, якій він належить, і відповідь обмежується її межами.
Спробувати
Замініть усе в кутових дужках власними значеннями, а заповнювач ключа — ключем із вашої панелі керування.
curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/certificate \
-H "Authorization: Bearer zdk_live_…"Увійшли в систему? Консоль API у вашій панелі керування автоматично підставляє ваш реальний ідентифікатор організації та ваш власний ключ, а також виконує запит до робочого API, щоб ви могли побачити справжню відповідь. Відкрийте цю кінцеву точку в консолі API
Деталі
Whether this site is served over HTTPS on its own name, and if not, why not. Sites on our own fleet are served a per-vhost certificate the platform obtains itself by ACME (owner ruling 2026-09-07, docs/537), because not every site sits behind a CDN and a site with DNS pointed straight at our fleet needs a publicly-trusted certificate of its own. ⛔ state is never simply "no". issued / pending / failed with a reason are three different facts, and the failure directions are asymmetric: behind Cloudflare Full (strict) an uncovered host answers HTTP 526 — a hard outage — while behind plain Full it is a silent downgrade. A payload that could only say "no" would leave a customer looking at a broken site with no explanation. ⛔ covered and serving are DIFFERENT and both are returned. covered means a CA signed it; serving means the box actually presents it. A certificate that exists and is not installed serves nobody, and a screen built from covered alone would report a healthy site to a customer whose visitors see a name-mismatch warning. scope is shared when the site is covered by one platform certificate for a registrable domain we own — the ordinary case for a preview hostname, where a single wildcard covers every site on that domain rather than one certificate each.
Параметри
| Назва | Тип | Обов'язкове | Що це таке |
|---|---|---|---|
siteId (path) | Uuid | Так | Site ID (UUIDv7). |
Відповідь
| Назва | Тип | Обов'язкове | Що це таке |
|---|---|---|---|
site_id | string | Так | — |
state | string<none, pending, issued, failed, retired> | Так | ⛔ none means nothing has been attempted, which is a DIFFERENT fact from failed. Collapsing them would leave a screen unable to tell a new site from a broken one. |
scope | string<site, shared> | Так | shared when one platform certificate for a registrable domain we own covers this site — the ordinary case for a preview hostname. |
shared_suffix | string | Ні | The registrable domain a shared certificate covers. Empty when scope is site. |
hostnames | string[] | Так | Read back off the ISSUED artefact, never from what was requested — a CA that trimmed a name must not be reported as covering it. |
covered | boolean | Так | A certificate authority has signed a certificate for this site. |
serving | boolean | Так | ⛔ The box actually presents it. DIFFERENT from covered: a certificate that exists in Vault and is not installed serves nobody. |
failure_reason | string | Ні | — |
failure_detail | string | Ні | — |
not_after | string | Ні | — |
installed_at | string | Ні | — |
environment | string | Ні | ⛔ Travels because a staging certificate is trusted by NO browser. A screen showing one as simply "issued" would report green for a site every visitor sees a warning on. |
wildcard_covered | boolean | Ні | Whether subdomains are covered. A wildcard needs DNS-01, which needs a TXT record in the zone, so a domain whose DNS we do not manage cannot have one. |
Помилки, які може повертати ця кінцева точка
401 · 403 · 404