All Products
Search
Document Center

Certificate Management Service:API overview

Last Updated:Aug 28, 2026

API standards and multilingual preset SDKs

The OpenAPI of this product (cas/2020-04-07) uses the RPC signature style. We have encapsulated SDKs for common programming languages for developers. Developers can download the SDK to directly call this product's OpenAPI without worrying about technical details. If the existing SDK does not meet your needs, you can use the signature mechanism for self-signing integration. Since the details of self-signing are very complex, it may take around 5 business days. Therefore, we recommend joining our DingTalk service group (147535001692) and conducting signature integration under expert guidance.

Before using the API, you need to prepare your identity account and access key (AccessKey) to effectively access the API through client tools (such as SDK and CLI). For details, see Obtain an AccessKey.

Custom signature scenarios

If your business scenario has special requirements and you need to integrate the API through self-signing, we recommend consulting our technical support team first (DingTalk service group: 147535001692) to obtain professional guidance and ensure efficient integration.

Account and security preparation

Alibaba Cloud accounts have full administrative permissions over all resources. Once an AccessKey is compromised, all associated resources will be at risk of unauthorized access. To ensure security, it is recommended to create a RAM user with only API access permissions and configure its AccessKey, while configuring RAM policies based on the principle of least privilege (PoLP). Use the Alibaba Cloud account only in specific scenarios where Alibaba Cloud account permissions are explicitly required.

Subscription instance

API

Title

Description

ListInstances List instances Retrieves a list of instances.
UpdateInstance UpdateInstance Updates the configuration of a Certificate Management Service instance.
GetInstanceDetail Get instance details Queries the details of an instance.
DeleteInstance Delete an instance Deletes an instance.
RefundInstance Refund an instance Refunds an instance within 7 days.
GetInstanceSummary GetInstanceSummary Queries the summary statistics of Certificate Management Service instances, such as certificate counts by status.
ApplyCertificate Apply for a certificate Applies for a certificate.
GetTaskAttribute GetTaskAttribute Queries the processing result and status of a submitted certificate application.
CancelPendingCertificate Revoke a certificate application Revokes a certificate application.
ListCertificates ListCertificates Queries the certificates managed by Certificate Management Service.
RevokeCertificate Revoke a certificate Revokes a certificate.
GetCertificateDetail Retrieve certificate details excluding private key Queries the details of a certificate without returning the certificate content or private key content.
GetUserCertificateDetail Get certificate details Retrieves the details of a certificate, including basic information and public/private key content. You can use this operation to download the certificate content and private key.
DeleteUserCertificate Delete a certificate Deletes an expired, revoked, or uploaded certificate.
UploadUserCertificate Upload a certificate Uploads a certificate, including a standard Chinese national cryptographic (China SM) certificate or a non-China SM certificate.

Certificate contact

API

Title

Description

CreateContact Create a certificate application contact Creates a certificate application contact.
GetContact Get contact information Retrieves a contact.
ListContact Retrieve contact list Retrieves the list of contacts.
UpdateContact Edit a certificate application contact Updates a contact.
DeleteContact Delete a certificate application contact Deletes a contact.

Company organization

API

Title

Description

CreateCompany Create a certificate company organization Creates a company.
UpdateCompany Edit certificate company organization Updates company information.
ListCompanies Retrieve certificate company organizations Retrieves a list of companies.
GetCompany Get certificate company or organization details Retrieves the details of a company.
DeleteCompany Delete a certificate company organization Deletes a company.

Resource group

API

Title

Description

MoveResourceGroup MoveResourceGroup Changes the resource group to which a certificate or certificate order belongs.

Deployment task

API

Title

Description

CreateDeploymentJob CreateDeploymentJob Creates a certificate deployment task to deploy an SSL certificate to one or more Alibaba Cloud services immediately or at a scheduled time.
UpdateDeploymentJobStatus UpdateDeploymentJobStatus Updates the status of a certificate deployment task, such as changing from editing to pending execution.
ListDeploymentJob Query deployment task list Retrieves a list of deployment tasks after you create a deployment task.
UpdateDeploymentJob UpdateDeploymentJob Updates the configuration of a certificate deployment task, such as the certificates or target resources.
DescribeDeploymentJob DescribeDeploymentJob Retrieves information about a certificate deployment task, including the task status, target resources, and certificates.
ListWorkerResource ListWorkerResource Queries the worker tasks of a deployment task. Each worker task deploys a certificate to a specific cloud resource in a cloud service.
DescribeDeploymentJobStatus DescribeDeploymentJobStatus Queries the execution status summary of a certificate deployment task, including the number of succeeded and failed workers.
ListDeploymentJobResource ListDeploymentJobResource Queries the cloud resources associated with a deployment task. An empty list indicates that the resources are invalid and must be re-associated.
ListDeploymentJobCert ListDeploymentJobCert Queries the certificates associated with a deployment task, such as the certificate instance ID, type, and name.
UpdateWorkerResourceStatus Update worker task status in a deployment task Updates the status of a worker task in a deployment task.
DeleteWorkerResource DeleteWorkerResource Deletes a worker task from a certificate deployment task.
DeleteDeploymentJob DeleteDeploymentJob Deletes a certificate deployment task.
DescribeCloudResourceStatus DescribeCloudResourceStatus Queries the number of cloud resources on which certificates were deployed by using a multi-cloud deployment task.
ListCloudResources ListCloudResources Queries the cloud resources on which certificates are deployed, such as Server Load Balancer (SLB) instances and CDN domains.
ListCloudAccess ListCloudAccess Queries the AccessKey pairs that are configured for multi-cloud certificate deployment.

Certificate repository

API

Title

Description

GetCertWarehouseQuota GetCertWarehouseQuota Queries the remaining quota for certificate application repository operations.
ListCertWarehouse Query certificate repository list Queries the list of certificate repositories.
ListCert ListCert This API queries certificates in the certificate store.
Sign Sign This operation creates a digital signature with a PCA certificate from a certificate repository.
Verify Verify Verifies a data signature by using a private certificate in a certificate application repository.
Encrypt Encrypt Encrypts data by using a certificate in a certificate application repository.
Decrypt Decrypt Decrypts data that was encrypted by using a certificate in a certificate application repository.
UploadPCACert Upload a PCA certificate to a certificate repository Uploads a PCA certificate to a certificate repository.
DeletePCACert DeletePCACert Deletes a private certificate from a certificate application repository.
CreateWHClientCertificate CreateWHClientCertificate Issues a single client certificate from the general user certificate repository.
RevokeWHClientCertificate RevokeWHClientCertificate Revokes a client certificate from the certificate repository.

CSR management

API

Title

Description

ListCsr ListCsr Queries the certificate signing requests (CSRs) in your account.
CreateCsr CreateCsr Creates a certificate signing request (CSR) that contains information about an SSL certificate to apply for, such as the domain names and the certificate holder. You must provide a CSR when you submit a certificate application to a certificate authority (CA).
UploadCsr UploadCsr Uploads an existing certificate signing request (CSR) to Certificate Management Service. After the upload, you can use the CSR to apply for certificates.
GetCsrDetail GetCsrDetail Queries the content of a certificate signing request (CSR).
UpdateCsr Upload or update a CSR private key Uploads the private key corresponding to a CSR if you did not provide the CSR private key when uploading the local CSR.
DeleteCsr DeleteCsr Deletes a certificate signing request (CSR).

Order (V1.0)

API

Title

Description

DescribePackageState DescribePackageState Queries the quota and usage of domain validated (DV) certificate packages.
ListUserCertificateOrder Query user certificates or orders Queries the list of user certificates or orders.
CreateCertificateForPackageRequest CreateCertificateForPackageRequest Submits a certificate application by using a purchased certificate package quota.
CancelCertificateForPackageRequest CancelCertificateForPackageRequest Revokes an issued certificate or cancels a pending certificate order and restores the quota.
CancelOrderRequest CancelOrderRequest Cancels a certificate application order that is pending domain verification or under review.
RenewCertificateOrderForPackageRequest RenewCertificateOrderForPackageRequest Submits a renewal application for an issued SSL certificate.

Certificate request (V1.0)

API

Title

Description

DescribeCertificateState DescribeCertificateState Queries the status of a certificate application order, such as domain validation progress.
CreateCertificateWithCsrRequest CreateCertificateWithCsrRequest Purchases, applies for, and issues a domain validated (DV) certificate by using a custom certificate signing request (CSR) file.
CreateCertificateRequest CreateCertificateRequest Purchases, applies for, and issues a domain validated (DV) certificate by using extended certificate services.
DeleteCertificateRequest DeleteCertificateRequest Deletes a failed domain validated (DV) certificate application order.

Others

API

Title

Description

AddCloudAccess AddCloudAccess Adds an AccessKey for authorization.
CreateWarehouse Create a certificate application repository Creates a certificate repository.
DeleteCloudAccess DeleteCloudAccess Deletes an access key.
DeleteWarehouse DeleteWarehouse Deletes a certificate warehouse.
DescribeWarehouseCert DescribeWarehouseCert Retrieves the details of a certificate stored in a certificate warehouse.
GetAssetCount Query asset count Queries the number of assets.
GetRiskCount GetRiskCount Queries the number of assets with certificate-related risks, such as expired or soon-to-expire certificates.
ListAssetCount Query cloud service resource statistics Queries the resource statistics list of cloud services.
ListWarehouse ListWarehouse Lists warehouses.
BatchUpdateNoticeStatus Updates the status of message notification Updates the notification status in batches
GetMatchedResources Retrieve matched resources for a certificate Retrieves the resources that match a certificate.
CreateRollbackTask Roll back a deployment Rolls back a deployment.
GetCertificatePackageCount Retrieve certificate resource plan quantity Retrieves the number of certificate resource plans.
ListTagKeys Query tag keys Retrieves a list of tag keys and values.
ListTagResources Get resource tag list Retrieves the tags associated with a resource.
ListTrusteeOrder Get managed order list Retrieves the list of managed orders.
TagResources Attach tags to a specified resource (SSL certificate instance) Adds resource tags.
UntagResources Remove tags from a specified resource (SSL certificate instance) Removes tags.