Available Private CA MCP tools
The DigiCert® Private CA MCP server provides read-only tools for retrieving information about your Private CA environment. Your AI client selects the appropriate tool based on your question.
The information each tool can retrieve depends on the accounts, roles, and permissions assigned to your DigiCert ONE Service User.
The following example prompts illustrate the kinds of questions each tool can answer. Users do not need to specify the tool name in their prompts; the AI client selects the appropriate tool.
Certificate tools
Tool | What it retrieves | Example prompt |
|---|---|---|
| A certificate identified by its certificate ID. | Get the certificate with ID <certificate-ID>. |
| Certificates matching a serial number, subject key ID, or subject public key. | Find the certificate with serial number <serial-number>. |
| Discovered certificates, optionally filtered by certificate type or discovery information. | List the discovered certificates that expire this year. |
| Certificate inventory data in CSV format. | Export the certificate inventory as CSV. |
Certificate authority tools
Tool | What it retrieves | Example prompt |
|---|---|---|
| The private CAs (roots and ICAs)available to the Service User. | List the private CAs in my account. |
| Details for a CA identified by its CA ID. | Show details for CA <CA-ID>. |
| The active status of a CA. | Is CA <CA-ID> active? |
| The CA hierarchy and certificate-chain relationships. | Show the hierarchy for CA <CA_ID>. |
| The certificate signing request for a CA. | Show the CSR for CA <CA_ID>. |
| Notes associated with a CA. | Show the notes for CA <CA_ID>. |
CA configuration tools
Tool | What it retrieves | Example prompt |
|---|---|---|
| The certificate-policy issuance configuration for a CA. | Which certificate policies can CA <CA-ID> issue? |
| The AIA issuer configuration for a CA. | Does CA <CA-ID> include AIA issuer information? |
| The certificate-chain configuration for a CA. | Show the configured certificate chains for CA <CA-ID>. |
| The CRL issuance configuration for a CA. | How frequently does CA <CA-ID> publish CRLs? |
| The OCSP configuration for a CA. | Show the OCSP configuration for CA <CA-ID>. |
| Certificate-expiration information available through Private CA. | Which certificates expire soon? |
Certificate template tools
Tool | What it retrieves | Example prompt |
|---|---|---|
| Certificate templates, optionally filtered by name. | List the certificate templates in my account. |
| Details for a certificate template identified by its template ID. | Show details for template <template-ID>. |
| The accounts assigned to a certificate template. | Which accounts can use template <template-ID>? |
| The certificate-template validation schema. | Show the certificate-template validation schema. |
OCSP responder tools
Tool | What it retrieves | Example prompt |
|---|---|---|
| The OCSP responders available to the Service User. | List the OCSP responders. |
| Details for an OCSP responder identified by its responder ID. | Show details for OCSP responder <responder-ID>. |
AIA and CRL tools
Tool | What it retrieves | Example prompt |
|---|---|---|
| AIA issuer files. | List the AIA issuer files. |
| CRL records. | List the CRLs. |
| Details for a CRL identified by its CRL ID. | Show details for CRL <CRL-ID>. |
Audit tools
Tool | What it retrieves | Example prompt |
|---|---|---|
| Private CA audit-log entries. | Show recent certificate revocation events. |