openapi: 3.1.0 info: title: Fastly Account ACL TLS Certificates API description: The Fastly Account API provides endpoints for managing customer accounts, users, and identity and access management (IAM) resources. Developers can programmatically manage user invitations, roles, permissions, and service groups to control access to Fastly resources. The API supports retrieving and updating customer information, managing user profiles, and configuring organizational settings for enterprise accounts. version: '1.0' contact: name: Fastly Support url: https://support.fastly.com termsOfService: https://www.fastly.com/terms servers: - url: https://api.fastly.com description: Fastly API Production Server security: - apiKeyAuth: [] tags: - name: TLS Certificates description: Operations for managing custom TLS certificates that are used to terminate TLS traffic for one or more fully qualified domain names. paths: /tls/certificates: get: operationId: listTlsCertificates summary: List TLS certificates description: Retrieves a list of all custom TLS certificates associated with the account. tags: - TLS Certificates parameters: - name: page[number] in: query description: The page number to retrieve. schema: type: integer - name: page[size] in: query description: The number of items per page. schema: type: integer - name: filter[tls_domains.id] in: query description: Filter certificates by TLS domain ID. schema: type: string - name: sort in: query description: The field to sort results by. schema: type: string enum: - created_at - -created_at responses: '200': description: Successfully retrieved the list of TLS certificates. content: application/vnd.api+json: schema: type: object properties: data: type: array items: $ref: '#/components/schemas/TlsCertificate' '401': description: Unauthorized. The API token is missing or invalid. post: operationId: createTlsCertificate summary: Create a TLS certificate description: Uploads a new custom TLS certificate. Uploading a new certificate automatically enables TLS for all domains listed as Subject Alternative Names (SAN entries) on the certificate. Certificate deployment takes approximately 20 minutes on average but may take up to an hour. tags: - TLS Certificates requestBody: required: true content: application/vnd.api+json: schema: type: object properties: data: type: object properties: type: type: string enum: - tls_certificate attributes: type: object properties: cert_blob: type: string description: The PEM-encoded certificate. name: type: string description: A customizable name for the certificate. relationships: type: object properties: tls_domains: type: object description: The TLS domains associated with the certificate. responses: '201': description: Successfully created the TLS certificate. content: application/vnd.api+json: schema: type: object properties: data: $ref: '#/components/schemas/TlsCertificate' '400': description: Bad request. Missing or invalid certificate data. '401': description: Unauthorized. The API token is missing or invalid. /tls/certificates/{tls_certificate_id}: get: operationId: getTlsCertificate summary: Get a TLS certificate description: Retrieves the details of a specific custom TLS certificate. tags: - TLS Certificates parameters: - name: tls_certificate_id in: path required: true description: The alphanumeric string identifying the TLS certificate. schema: type: string responses: '200': description: Successfully retrieved the TLS certificate. content: application/vnd.api+json: schema: type: object properties: data: $ref: '#/components/schemas/TlsCertificate' '401': description: Unauthorized. The API token is missing or invalid. '404': description: TLS certificate not found. patch: operationId: updateTlsCertificate summary: Update a TLS certificate description: Replaces a TLS certificate with a new one. The new certificate must cover the same domains as the original. tags: - TLS Certificates parameters: - name: tls_certificate_id in: path required: true description: The alphanumeric string identifying the TLS certificate. schema: type: string requestBody: required: true content: application/vnd.api+json: schema: type: object properties: data: type: object properties: type: type: string enum: - tls_certificate attributes: type: object properties: cert_blob: type: string description: The PEM-encoded replacement certificate. name: type: string description: A customizable name for the certificate. responses: '200': description: Successfully updated the TLS certificate. content: application/vnd.api+json: schema: type: object properties: data: $ref: '#/components/schemas/TlsCertificate' '400': description: Bad request. Missing or invalid certificate data. '401': description: Unauthorized. The API token is missing or invalid. '404': description: TLS certificate not found. delete: operationId: deleteTlsCertificate summary: Delete a TLS certificate description: Deletes a custom TLS certificate. The certificate must not have any active TLS activations. tags: - TLS Certificates parameters: - name: tls_certificate_id in: path required: true description: The alphanumeric string identifying the TLS certificate. schema: type: string responses: '204': description: Successfully deleted the TLS certificate. '401': description: Unauthorized. The API token is missing or invalid. '404': description: TLS certificate not found. components: schemas: TlsCertificate: type: object description: A custom TLS certificate used to terminate TLS traffic for one or more fully qualified domain names. properties: id: type: string description: The alphanumeric string identifying the TLS certificate. type: type: string description: The resource type. enum: - tls_certificate attributes: type: object properties: name: type: string description: A customizable name for the certificate. cert_blob: type: string description: The PEM-encoded certificate. issued_to: type: string description: The common name of the entity the certificate was issued to. issuer: type: string description: The certificate authority that issued the certificate. serial_number: type: string description: The serial number of the certificate. signature_algorithm: type: string description: The algorithm used to sign the certificate. not_before: type: string format: date-time description: The date the certificate is valid from. not_after: type: string format: date-time description: The date the certificate expires. created_at: type: string format: date-time description: The date and time the certificate was created. updated_at: type: string format: date-time description: The date and time the certificate was last updated. securitySchemes: apiKeyAuth: type: apiKey in: header name: Fastly-Key description: API token used to authenticate requests to the Fastly API. externalDocs: description: Fastly Account API Documentation url: https://www.fastly.com/documentation/reference/api/account/