Before you begin
Prepare a PEM certificate chain and its matching, unencrypted PEM private key. The certificate must cover the hostnames you intend to serve. You need certificate-create permission and available imported-certificate quota in the selected project.1
Open the certificate inventory
Select the project and open TLS Manager → Certificates. Start a certificate upload.
2
Provide certificate material
Enter a unique name, the PEM certificate chain, and private key. Enable root CA validation when you want to require a chain trusted by the system trust store.
3
Inspect the uploaded certificate
Confirm the covered domains, issuer, fingerprint, validity period, and status. A successfully uploaded certificate is not automatically attached to a distribution.
4
Assign it to your distribution
Open the distribution’s TLS configuration, select imported certificate mode, and choose the certificate from the same project. Save and verify HTTPS on every intended hostname.
API request
Send a JSON object withname, certificate, private_key, and validate_root_ca to POST /tls-manager/certificates. PEM line breaks must be encoded as JSON newlines. The response is the created certificate metadata with HTTP 201.
Store upload material in a server-side secret manager. Do not put a real private key into the interactive documentation playground, browser source, logs, or support messages.