compute
POST /v1/certificates/orders/{orderId}/submit
Buy the certificate. This spends money.
Ìfàṣẹ́pọ̀
Fi bọ́ọ̀lù (bearer token) ranṣẹ gẹ́gẹ́ bí kọ́kọ́rọ́ API. Kọ́kọ́rọ́ náà gbọ́dọ̀ ní ìyọ̀ǹda billing.payment.manage; a ó kọ̀ ọ́ silẹ pẹlu 403, kii ṣe 404, ti kọ́kọ́rọ́ náà kò bá ní i.
Ojú abánisọ̀rọ̀ yìí kò gba id ajọ kankan. Kọ́kọ́rọ́ rẹ ti mọ ajọ ti o jẹ ti e, a o si fèsì nipa rẹ̀.
Gbiyanju rẹ
Rọ́pọ̀ èyíkéyìí nínú àwọn àmì ìtọ́ka < > pẹ̀lú iye tirẹ̀, àti àmì ìdánimọ̀ bọ́tìnnì náà pẹ̀lú bọ́tìnnì kan láti inú dásibọ̀ọ̀dù rẹ.
curl -X POST https://api.zinndigital.com/v1/certificates/orders/{orderId}/submit \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "csr_pem": <string> }'Ṣé o ti wọlé? Iwọ̀n api ní nú ìgbékalẹ̀ rẹ kún id àjọ gidi rẹ ati bọtini tirẹ, o si nṣiṣẹ ibeere na lòdì si api gidi ki o le rii esi gidi na. Ṣí ojú abáná yìí sílẹ̀ nínú kọnsólù API
Àwọn kúlẹ̀kúlẹ̀
⛔⛔ This is the call that charges. It is a separate endpoint from the one that creates the order precisely so a client cannot buy while a form is half filled in. ⛔⛔ The CSR is required and is checked three times — here, in the service and in the driver. That is not belt-and-braces: the authority accepts an order without one, charges for it, and issues nothing. Two such orders were created against our own account on 2026-08-29 by a probe reading validation errors, and the giveaway is how unlike a purchase they look — no common name, no issue date (docs/272 §9). ⭐ A customer-generated CSR is the better path and the one to encourage: the private key then never leaves their machine. Answers 503 when the authority could not be reached — in which case the order is recorded and reconciled rather than lost. Requires billing.payment.manage.
Àwọn ìpìlẹ̀
| Orúkọ | Iru | Tí a nílò | Kini o jẹ |
|---|---|---|---|
orderId (path) | Uuid | Bẹẹni | The order's id, as listCertificateOrders reports it. Ours (UUIDv7). |
Akoonu ibeere naa
| Orúkọ | Iru | Tí a nílò | Kini o jẹ |
|---|---|---|---|
csr_pem | string | Bẹẹni | The certificate signing request, PEM. ⛔ Required. Without it the authority has nothing to sign and the order is billed and permanently unusable. |
Idahun
| Orúkọ | Iru | Tí a nílò | Kini o jẹ |
|---|---|---|---|
id | Uuid | Bẹẹni | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
product_code | string | Bẹẹni | The stable machine key (positive_ssl). ⛔ Match on this, never on product_name — the name is the certificate authority's marketing string and can be corrected without the… |
product_name | string | Bẹẹni | What the customer reads — the authority's own product name (PositiveSSL, S/MIME Personal, Unified Communications Certificate (UCC)). ⛔ Never a translation key: these are… |
state | string<pending, awaiting_validation, issued, cancelled, failed, expired> | Bẹẹni | ⛔⛔ awaiting_validation means PAID AND NOT ISSUED. The authority charges at order time and then waits for the customer to prove they control the domain. It is deliberately… |
common_name | string | Bẹẹni | The primary domain on the certificate. |
domains | string[] | Bẹẹni | Additional names (SANs). Empty for a single-domain product. |
period_years | integer | Bẹẹni | — |
price_minor | integer | Bẹẹni | What the customer is charged, frozen at order. A copy rather than a join, so an operator repricing the catalogue cannot move an existing bill. |
currency | string | Bẹẹni | — |
validation_instructions | string | Bẹẹni | What the customer must still do, in the authority's own words. ⭐ Carried as text rather than parsed: every authority words it differently, and a half-parsed instruction is worse… |
certificate_pem | string | Bẹẹni | The issued certificate. ⭐ Public by nature — it is served to every visitor of the site — which is why it is returned here while its private key never is: a customer-generated… |
chain_pem | string | Bẹẹni | — |
message | string | Bẹẹni | Why it failed or was cancelled, in a sentence the customer reads. |
ordered_at | string | Bẹẹni | — |
issued_at | string | Bẹẹni | — |
expires_at | string | Bẹẹni | — |
days_until_expiry | integer | Bẹẹni | Whole days until expires_at, negative once it has lapsed. ⛔ null and 0 are DIFFERENT answers and a client must not collapse them: null means we could not read an expiry… |
renewable | boolean | Bẹẹni | Whether to offer a re-order now — issued, inside the 30-day window, and with no renewal already in flight. ⛔ Computed here rather than left to a client to derive from… |
free_alternative_exists | boolean | Bẹẹni | Whether Let's Encrypt issues this kind of certificate for nothing. Carried onto the renewal prompt for the same reason it is on the buy screen: say so before asking somebody… |
renewal_of | Uuid | Bẹẹni | The order this one renews, so a client can show the chain. |
last_reminded_at | string | Bẹẹni | When the renewal sweep last REACHED this order — which is not the same as when it last emailed about it. ⛔ The sweep stamps this for every row it reaches… |
Awọn aṣiṣe ti ibudo ipari yii le da pada
401 · 403 · 404 · 422 · 429 · 503