Set up MCP server for Private CA
The DigiCert® Private CA Model Context Protocol (MCP) server gives you a conversational way to explore information in your Private CA account using an AI client. Ask questions in natural language to retrieve information about certificate authorities (CAs), certificates, templates, CRLs, OCSP responders, AIA issuer files, and audit activity.
Your AI client uses the read-only tools available through the MCP server to retrieve Private CA information permitted by your DigiCert® ONE Service User.
注意
All tools available through the MCP server are read-only. They cannot create, modify, renew, revoke, or delete your Private CA resources.
How access works
To connect an AI client to the MCP server, use the Service User Token ID generated for a DigiCert ONE Service User. The products, accounts, roles, and permissions assigned to that Service User determine which Private CA information the MCP server can retrieve.
小心
Treat the Service User Token ID as a credential. Do not include it in prompts, share it with other users, or add it to files stored in source control.
What you can ask
For example, you can ask an AI client to:
List the certificate authorities in your account and identify which ones are active.
Find certificates approaching expiration.
Review CA hierarchy and configuration, including certificate policies, chains, CRLs, and OCSP.
Explore certificate templates and the accounts assigned to them.
Review AIA issuer files, CRLs, OCSP responders, and audit activity.
The AI client chooses the appropriate Private CA MCP tools, retrieves the information, and presents the results conversationally. The available tools cover certificates, certificate authorities, templates, validation resources, and audit logs.
Supported AI clients
You can connect the DigiCert Private CA MCP server to:
Cursor
GitHub Copilot in Visual Studio
GitHub Copilot in Visual Studio Code
To begin, prepare a DigiCert ONE Service User and follow the connection instructions for your AI client.