Issue a certificate
/users/{user_id}/certificatesIssues a certificate to the user for the specified product.
If the user already holds a valid certificate for the product, the existing certificate is returned instead of a new one being issued.
To reissue a certificate, set supersedes_certificate_id to the certificate being replaced. Reissuing requires the certificates.reissue permission in addition to certificates.create, and the certificate identified in supersedes_certificate_id is revoked with the reason reissued. That certificate must belong to the same user and product; otherwise, the request is rejected with a validation error on supersedes_certificate_id. A certificate that is already revoked cannot be superseded.
Autonomous mode: the API credential secret, sent as a bearer token. Credential secrets are identified by a fixed prefix.
In: header
Path Parameters
Header Parameters
Client-generated key that makes the request safe to retry. Must be 1 to 128 characters from [A-Za-z0-9._:-]. Required by this operation: a missing key returns idempotency_key_required, and a malformed key returns idempotency_key_invalid. Repeating the request with the same key and the same body returns the stored result with Idempotent-Replayed: true.
Optional client-generated identifier of the request, up to 64 characters from [A-Za-z0-9._-]. Echoed back in the response and recorded in the request log; it never replaces the server-generated X-Request-Id.
length <= 64Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/users/string/certificates" \ -H "Idempotency-Key: string" \ -H "Content-Type: application/json" \ -d '{ "product_id": "string" }'{ "data": { "code": "string", "deleted": true, "fields": {}, "id": "string", "issued_at": "2019-08-24T14:15:22Z", "number": { "instance": 0, "product": 0 }, "object": "certificate", "pdf_url": "string", "product_id": "string", "reissue": true, "revision": "string", "revoked": { "at": "2019-08-24T14:15:22Z", "by": { "id": "string", "kind": "admin" }, "reason": "string" }, "status": "valid", "superseded_by_certificate_id": "string", "supersedes_certificate_id": "string", "user_id": "string", "validation_url": "string" }}List a user's certificates GET
Returns the certificates issued to the user, including revoked certificates. Deleted certificates are not included. The collection can be filtered by product, status, and issue date, and is paginated with a cursor. When the credentials are restricted to specific products, only certificates for those products are returned. The `fields` object, which contains the document, address, and custom field values recorded at issuance, is included only when the credential has the `users.read_personal` permission.
Retrieve a certificate GET
Revoked certificates remain retrievable, with `status` set to `revoked`. Template previews are not certificates and cannot be retrieved through this operation. The response includes an `ETag` representing the current revision. Send this value in the `If-Match` header when revoking the certificate to avoid acting on an outdated version.