Skip to main content

Before you begin

Prepare a PEM certificate chain and its matching, unencrypted PEM private key. The certificate must cover the hostnames you intend to serve. You need certificate-create permission and available imported-certificate quota in the selected project.
1

Open the certificate inventory

Select the project and open TLS Manager → Certificates. Start a certificate upload.
2

Provide certificate material

Enter a unique name, the PEM certificate chain, and private key. Enable root CA validation when you want to require a chain trusted by the system trust store.
3

Inspect the uploaded certificate

Confirm the covered domains, issuer, fingerprint, validity period, and status. A successfully uploaded certificate is not automatically attached to a distribution.
4

Assign it to your distribution

Open the distribution’s TLS configuration, select imported certificate mode, and choose the certificate from the same project. Save and verify HTTPS on every intended hostname.
Names must be unique in the project, contain no control characters, and fit within 64 bytes. The API limits certificate material to 256 KiB and the private key to 64 KiB.

API request

Send a JSON object with name, certificate, private_key, and validate_root_ca to POST /tls-manager/certificates. PEM line breaks must be encoded as JSON newlines. The response is the created certificate metadata with HTTP 201. Store upload material in a server-side secret manager. Do not put a real private key into the interactive documentation playground, browser source, logs, or support messages.

Replace an expiring certificate

Upload the replacement as a new certificate, select it on each consuming distribution, and verify the HTTPS result. Open the old certificate’s detail page to confirm that its usage list is empty before deleting it. Replacing an inventory entry’s name does not replace its certificate material.