Revoke a certificate
/users/{user_id}/certificates/{certificate_id}Revokes a certificate. Revocation is the only supported change: set status to revoked and provide a reason. Any other field is rejected.
A revoked certificate remains on record and retrievable, and public validation reports it as revoked. Revocation does not affect the user's access, progress, or points. To remove a certificate, use the delete operation instead.
Send the certificate's current ETag in the If-Match header to avoid acting on an outdated version.
Autonomous mode: the API credential secret, sent as a bearer token. Credential secrets are identified by a fixed prefix.
In: header
Path Parameters
Header Parameters
Client-generated key that makes the request safe to retry. Must be 1 to 128 characters from [A-Za-z0-9._:-]. Optional on this operation; when sent, a malformed key returns idempotency_key_invalid, and repeating the request with the same key and the same body returns the stored result with Idempotent-Replayed: true.
Expected revision of the resource, in the same format as the ETag header (W/"<type>:<id>:<revision>"). If the resource has changed since that revision, the request fails with 412 and the revision_mismatch error code. When omitted, the update is applied to the current revision.
Optional client-generated identifier of the request, up to 64 characters from [A-Za-z0-9._-]. Echoed back in the response and recorded in the request log; it never replaces the server-generated X-Request-Id.
length <= 64Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X PATCH "https://example.com/users/string/certificates/string" \ -H "Content-Type: application/json" \ -d '{ "reason": "string", "status": "revoked" }'{ "data": { "code": "string", "deleted": true, "fields": {}, "id": "string", "issued_at": "2019-08-24T14:15:22Z", "number": { "instance": 0, "product": 0 }, "object": "certificate", "pdf_url": "string", "product_id": "string", "reissue": true, "revision": "string", "revoked": { "at": "2019-08-24T14:15:22Z", "by": { "id": "string", "kind": "admin" }, "reason": "string" }, "status": "valid", "superseded_by_certificate_id": "string", "supersedes_certificate_id": "string", "user_id": "string", "validation_url": "string" }}Retrieve a certificate GET
Revoked certificates remain retrievable, with `status` set to `revoked`. Template previews are not certificates and cannot be retrieved through this operation. The response includes an `ETag` representing the current revision. Send this value in the `If-Match` header when revoking the certificate to avoid acting on an outdated version.
Delete a certificate DELETE
Moves the certificate to the trash. A `reason` is required and is recorded with the deletion. Deleted certificates no longer appear in the user's certificate list and can no longer be verified through public validation. If the user is still eligible, they can obtain a new certificate on demand. To invalidate a certificate while keeping it on record, revoke it through the update operation instead.