Generate an API key
An application programming interface (API) key gives a user or Service User API-only access to CertCentral. Use an API key to authenticate automated integrations, third-party tools, and custom API workflows without requiring interactive sign-in credentials.
Before you begin
You must be a CertCentral administrator to access the API Keys page and create API keys for other CertCentral users and Service Users.
Decide whether to link the key to an existing CertCentral user or create a new Service User. A Service User has API-only access and inherits your administrator permissions by default.
Generate an API key
In the CertCentral main menu, go to Automation > API Keys.
On the API Keys page, select Add API Key.
In the Add API Key window, enter a Description to identify the API key (for example, the name of the application or user assigned to the key), and then select Add.
In the User menu, select one of the following:
Your name: The API key inherits your permissions.
CertCentral user: The API key inherits the user's permissions.
Service User: The API key inherits the Service User's permissions.
Create new service user: Create a Service User with API-only access
To create a new Service User:
In the Service and User name fields, replace the default names or leave them unchanged.
In the Email address field, enter the email address for the Service User.
In the Division restrictions menu, select the divisions to which you want to restrict the Service User, if needed.
Note: This option appears if divisions are enabled for your account.
In the API key restrictions (optional), select one of the following options to restrict the API key’s permissions to a specified set of actions.
Orders: Limits the key to these actions: Orders, requests, and certificates.
Orders, Domains, Organizations: Limits the key to these actions: Orders, requests, certificates, organizations, and domains.
View Only: Limits the key to GET requests. POST, PUT, or DELETE requests are disabled.
User Management: Limits the key to these actions: Users.
Domains: Limits key to these actions: Domains.
Select Add API Key.
In the New API Key window, select the generated API key to copy it, or if you created multiple API keys, select Download CSV to get a CSV file containing all the API keys.
Atenção
Important: CertCentral displays the API keys one time. After you acknowledge the message, you can’t retrieve them again. Store these API keys in a secure location before continuing.
Select I understand I will not see this again.
Your new API keys are added to the list of keys on the API Keys page. Return to this page to view, revoke, deactivate, or transfer ownership of your API keys.
Transfer API key ownership
You must be an Administrator in CertCentral to transfer API keys. All API key transfers are recorded in your CertCentral audit log (go to Account > Audit Logs).
When you transfer ownership of an API key to another CertCentral user or Service User, existing copies of the API key remain valid until the API key is revoked or deactivated.
Atenção
Important: When you transfer ownership of an API key, the API key inherits the permissions of the user or Service User it’s linked to. API key restrictions can further limit what the API key is allowed to do.
In the CertCentral menu, go to Automation > API Keys.
On the API Keys page, select the API key Description link.
In the Update API Key window, in the User menu, select the CertCentral user or Service User you want to transfer API key ownership to.
Select Update API Key.
Ownership of the API key has been transferred to the selected user or Service User.