> ## Documentation Index
> Fetch the complete documentation index at: https://developers.aptranet.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Import a certificate

> Upload a PEM certificate chain and matching private key, then bind the certificate to a Cloud CDN distribution.

## Before you begin

Prepare a PEM certificate chain and its matching, unencrypted PEM private key. The certificate must cover the hostnames you intend to serve. You need certificate-create permission and available imported-certificate quota in the selected project.

<Steps>
  <Step title="Open the certificate inventory">Select the project and open **TLS Manager → Certificates**. Start a certificate upload.</Step>
  <Step title="Provide certificate material">Enter a unique name, the PEM certificate chain, and private key. Enable root CA validation when you want to require a chain trusted by the system trust store.</Step>
  <Step title="Inspect the uploaded certificate">Confirm the covered domains, issuer, fingerprint, validity period, and status. A successfully uploaded certificate is not automatically attached to a distribution.</Step>
  <Step title="Assign it to your distribution">Open the distribution's **TLS** configuration, select imported certificate mode, and choose the certificate from the same project. Save and verify HTTPS on every intended hostname.</Step>
</Steps>

Names must be unique in the project, contain no control characters, and fit within 64 bytes. The API limits certificate material to 256 KiB and the private key to 64 KiB.

## API request

Send a JSON object with `name`, `certificate`, `private_key`, and `validate_root_ca` to `POST /tls-manager/certificates`. PEM line breaks must be encoded as JSON newlines. The response is the created certificate metadata with HTTP `201`.

Store upload material in a server-side secret manager. Do not put a real private key into the interactive documentation playground, browser source, logs, or support messages.

## Replace an expiring certificate

Upload the replacement as a new certificate, select it on each consuming distribution, and verify the HTTPS result. Open the old certificate's detail page to confirm that its usage list is empty before deleting it. Replacing an inventory entry's name does not replace its certificate material.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.