openapi: 3.1.0 info: title: Envoy Proxy Admin Certificates API description: The Envoy Proxy Administration Interface provides a local HTTP-based management API for querying and modifying various aspects of the Envoy server at runtime. It serves as a critical operational tool for monitoring, debugging, and managing Envoy proxy instances. The admin interface typically runs on port 9901 by default. All mutation operations must be sent as HTTP POST requests; GET requests will not perform changes. Note that this endpoint is not authenticated, so access should be restricted in production environments. version: 1.38.0 contact: name: Envoy Proxy url: https://www.envoyproxy.io/ license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 servers: - url: http://localhost:9901 description: Default Envoy Admin Interface tags: - name: Certificates description: TLS certificate information endpoints. paths: /certs: get: operationId: getCerts summary: Envoy Proxy List TLS Certificates description: Lists all loaded TLS certificates including file name, serial number, subject alternate names, and days until expiration in JSON format. responses: '200': description: Successful response with certificate information. content: application/json: schema: type: object properties: certificates: type: array items: type: object properties: ca_cert: type: array items: type: object cert_chain: type: array items: type: object tags: - Certificates