hosting
GET /v1/sites/{siteId}/certificate
The TLS certificate serving this site.
Ìfàṣẹ́pọ̀
Fi bọ́kì kọ́kọ́ (bearer token) ránṣẹ́ gẹ́gẹ́ bí àmì ìdánimọ̀ API. Ibùdó yìí kò sọ àṣẹ pàtó kan nínú àlàyé rẹ̀, nítorí náà fún kọ́kọ́ rẹ̀ ní ohun tó kéré jù lọ tí ó nílò kí o sì ṣàyẹ̀wò ìdáhùn náà dípò kí o kàn rò ó.
Ojú abánisọ̀rọ̀ yìí kò gba id ajọ kankan. Kọ́kọ́rọ́ rẹ ti mọ ajọ ti o jẹ ti e, a o si fèsì nipa rẹ̀.
Gbiyanju rẹ
Rọ́pọ̀ èyíkéyìí nínú àwọn àmì ìtọ́ka < > pẹ̀lú iye tirẹ̀, àti àmì ìdánimọ̀ bọ́tìnnì náà pẹ̀lú bọ́tìnnì kan láti inú dásibọ̀ọ̀dù rẹ.
curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/certificate \
-H "Authorization: Bearer zdk_live_…"Ṣé o ti wọlé? Iwọ̀n api ní nú ìgbékalẹ̀ rẹ kún id àjọ gidi rẹ ati bọtini tirẹ, o si nṣiṣẹ ibeere na lòdì si api gidi ki o le rii esi gidi na. Ṣí ojú abáná yìí sílẹ̀ nínú kọnsólù API
Àwọn kúlẹ̀kúlẹ̀
Whether this site is served over HTTPS on its own name, and if not, why not. Sites on our own fleet are served a per-vhost certificate the platform obtains itself by ACME (owner ruling 2026-09-07, docs/537), because not every site sits behind a CDN and a site with DNS pointed straight at our fleet needs a publicly-trusted certificate of its own. ⛔ state is never simply "no". issued / pending / failed with a reason are three different facts, and the failure directions are asymmetric: behind Cloudflare Full (strict) an uncovered host answers HTTP 526 — a hard outage — while behind plain Full it is a silent downgrade. A payload that could only say "no" would leave a customer looking at a broken site with no explanation. ⛔ covered and serving are DIFFERENT and both are returned. covered means a CA signed it; serving means the box actually presents it. A certificate that exists and is not installed serves nobody, and a screen built from covered alone would report a healthy site to a customer whose visitors see a name-mismatch warning. scope is shared when the site is covered by one platform certificate for a registrable domain we own — the ordinary case for a preview hostname, where a single wildcard covers every site on that domain rather than one certificate each.
Àwọn ìpìlẹ̀
| Orúkọ | Iru | Tí a nílò | Kini o jẹ |
|---|---|---|---|
siteId (path) | Uuid | Bẹẹni | Site ID (UUIDv7). |
Idahun
| Orúkọ | Iru | Tí a nílò | Kini o jẹ |
|---|---|---|---|
site_id | string | Bẹẹni | — |
state | string<none, pending, issued, failed, retired> | Bẹẹni | ⛔ none means nothing has been attempted, which is a DIFFERENT fact from failed. Collapsing them would leave a screen unable to tell a new site from a broken one. |
scope | string<site, shared> | Bẹẹni | shared when one platform certificate for a registrable domain we own covers this site — the ordinary case for a preview hostname. |
shared_suffix | string | Bẹẹkọ | The registrable domain a shared certificate covers. Empty when scope is site. |
hostnames | string[] | Bẹẹni | Read back off the ISSUED artefact, never from what was requested — a CA that trimmed a name must not be reported as covering it. |
covered | boolean | Bẹẹni | A certificate authority has signed a certificate for this site. |
serving | boolean | Bẹẹni | ⛔ The box actually presents it. DIFFERENT from covered: a certificate that exists in Vault and is not installed serves nobody. |
failure_reason | string | Bẹẹkọ | — |
failure_detail | string | Bẹẹkọ | — |
not_after | string | Bẹẹkọ | — |
installed_at | string | Bẹẹkọ | — |
environment | string | Bẹẹkọ | ⛔ Travels because a staging certificate is trusted by NO browser. A screen showing one as simply "issued" would report green for a site every visitor sees a warning on. |
wildcard_covered | boolean | Bẹẹkọ | Whether subdomains are covered. A wildcard needs DNS-01, which needs a TXT record in the zone, so a domain whose DNS we do not manage cannot have one. |
Awọn aṣiṣe ti ibudo ipari yii le da pada
401 · 403 · 404