hosting

GET /v1/sites/{siteId}/certificate

The TLS certificate serving this site.

Tất cả các điểm cuối hosting

Tất cả tài liệu dành cho nhà phát triển

Xác thực

Gửi khóa API dưới dạng mã thông báo bearer. Điểm cuối này không nêu rõ quyền cụ thể trong thông số kỹ thuật, vì vậy hãy cấp cho khóa của bạn quyền tối thiểu cần thiết và kiểm tra phản hồi thay vì phỏng đoán.

Endpoint này không nhận ID tổ chức. Khóa của bạn đã xác định tổ chức mà nó thuộc về và phản hồi được giới hạn trong phạm vi đó.

Dùng thử

Thay thế bất kỳ nội dung nào trong ngoعل (angle brackets) bằng giá trị của riêng bạn và trình giữ chỗ key bằng một key từ trang tổng quan của bạn.

curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/certificate \
  -H "Authorization: Bearer zdk_live_…"

Đã đăng nhập? Bảng điều khiển API trong trang quản lý của bạn sẽ tự điền ID tổ chức thực tế và khóa của riêng bạn, sau đó chạy yêu cầu đối với API trực tiếp để bạn có thể xem phản hồi thực tế. Mở điểm cuối này trong bảng điều khiển API

Chi tiết

Whether this site is served over HTTPS on its own name, and if not, why not. Sites on our own fleet are served a per-vhost certificate the platform obtains itself by ACME (owner ruling 2026-09-07, docs/537), because not every site sits behind a CDN and a site with DNS pointed straight at our fleet needs a publicly-trusted certificate of its own. ⛔ state is never simply "no". issued / pending / failed with a reason are three different facts, and the failure directions are asymmetric: behind Cloudflare Full (strict) an uncovered host answers HTTP 526 — a hard outage — while behind plain Full it is a silent downgrade. A payload that could only say "no" would leave a customer looking at a broken site with no explanation. ⛔ covered and serving are DIFFERENT and both are returned. covered means a CA signed it; serving means the box actually presents it. A certificate that exists and is not installed serves nobody, and a screen built from covered alone would report a healthy site to a customer whose visitors see a name-mismatch warning. scope is shared when the site is covered by one platform certificate for a registrable domain we own — the ordinary case for a preview hostname, where a single wildcard covers every site on that domain rather than one certificate each.

Tham số

TênLoạiBắt buộcNội dung này là gì
siteId (path)UuidSite ID (UUIDv7).

Phản hồi

TênLoạiBắt buộcNội dung này là gì
site_idstring
statestring<none, pending, issued, failed, retired>none means nothing has been attempted, which is a DIFFERENT fact from failed. Collapsing them would leave a screen unable to tell a new site from a broken one.
scopestring<site, shared>shared when one platform certificate for a registrable domain we own covers this site — the ordinary case for a preview hostname.
shared_suffixstringKhôngThe registrable domain a shared certificate covers. Empty when scope is site.
hostnamesstring[]Read back off the ISSUED artefact, never from what was requested — a CA that trimmed a name must not be reported as covering it.
coveredbooleanA certificate authority has signed a certificate for this site.
servingboolean⛔ The box actually presents it. DIFFERENT from covered: a certificate that exists in Vault and is not installed serves nobody.
failure_reasonstringKhông
failure_detailstringKhông
not_afterstringKhông
installed_atstringKhông
environmentstringKhông⛔ Travels because a staging certificate is trusted by NO browser. A screen showing one as simply "issued" would report green for a site every visitor sees a warning on.
wildcard_coveredbooleanKhôngWhether subdomains are covered. A wildcard needs DNS-01, which needs a TXT record in the zone, so a domain whose DNS we do not manage cannot have one.

Các lỗi điểm cuối này có thể trả về

401 · 403 · 404