---
title: Origin CA Certificates
---

[Skip to content](#%5Ftop) 

[API Reference](https://developers.cloudflare.com/api/typescript)

Copy Markdown

Open in **Claude**

Open in **ChatGPT**

Open in **Cursor**

---

**Copy Markdown**

**View as Markdown**

# Origin CA Certificates

##### [List Certificates](https://developers.cloudflare.com/api/typescript/resources/origin%5Fca%5Fcertificates/methods/list)

client.originCACertificates.list(OriginCACertificateListParams { zone\_id, limit, offset, 2 more } query, RequestOptionsoptions?): V4PagePaginationArray<[OriginCACertificate](https://developers.cloudflare.com/api/typescript/resources/origin%5Fca%5Fcertificates#%28resource%29%20origin%5Fca%5Fcertificates%20%3E%20%28model%29%20origin%5Fca%5Fcertificate%20%3E%20%28schema%29) { csr, hostnames, request\_type, 4 more } \>

GET/certificates

##### [Get Certificate](https://developers.cloudflare.com/api/typescript/resources/origin%5Fca%5Fcertificates/methods/get)

client.originCACertificates.get(stringcertificateID, RequestOptionsoptions?): [OriginCACertificate](https://developers.cloudflare.com/api/typescript/resources/origin%5Fca%5Fcertificates#%28resource%29%20origin%5Fca%5Fcertificates%20%3E%20%28model%29%20origin%5Fca%5Fcertificate%20%3E%20%28schema%29) { csr, hostnames, request\_type, 4 more } 

GET/certificates/{certificate\_id}

##### [Create Certificate](https://developers.cloudflare.com/api/typescript/resources/origin%5Fca%5Fcertificates/methods/create)

client.originCACertificates.create(OriginCACertificateCreateParams { csr, hostnames, request\_type, requested\_validity } body, RequestOptionsoptions?): [OriginCACertificate](https://developers.cloudflare.com/api/typescript/resources/origin%5Fca%5Fcertificates#%28resource%29%20origin%5Fca%5Fcertificates%20%3E%20%28model%29%20origin%5Fca%5Fcertificate%20%3E%20%28schema%29) { csr, hostnames, request\_type, 4 more } 

POST/certificates

##### [Revoke Certificate](https://developers.cloudflare.com/api/typescript/resources/origin%5Fca%5Fcertificates/methods/delete)

client.originCACertificates.delete(stringcertificateID, RequestOptionsoptions?): [OriginCACertificateDeleteResponse](https://developers.cloudflare.com/api/typescript/resources/origin%5Fca%5Fcertificates#%28resource%29%20origin%5Fca%5Fcertificates%20%3E%20%28model%29%20origin%5Fca%5Fcertificate%5Fdelete%5Fresponse%20%3E%20%28schema%29) { id, revoked\_at } 

DELETE/certificates/{certificate\_id}

##### ModelsExpand Collapse 

OriginCACertificate { csr, hostnames, request\_type, 4 more } 

csr: string

The Certificate Signing Request (CSR). Must be newline-encoded.

hostnames: Array<string\>

Array of hostnames or wildcard names bound to the certificate. Hostnames must be fully qualified domain names (FQDNs) belonging to zones on your account (e.g., `example.com` or `sub.example.com`). Wildcards are supported only as a `*.` prefix for a single level (e.g., `*.example.com`). Double wildcards (`*.*.example.com`) and interior wildcards (`foo.*.example.com`) are not allowed. The wildcard suffix must be a multi-label domain (`*.example.com` is valid, but `*.com` is not). Unicode/IDN hostnames are accepted and automatically converted to punycode.

request\_type: [CertificateRequestType](https://developers.cloudflare.com/api/typescript/resources/$shared#%28resource%29%20%24shared%20%3E%20%28model%29%20certificate%5Frequest%5Ftype%20%3E%20%28schema%29)

Signature type desired on certificate (“origin-rsa” (rsa), “origin-ecc” (ecdsa), or “keyless-certificate” (for Keyless SSL servers).

requested\_validity: [RequestValidity](https://developers.cloudflare.com/api/typescript/resources/ssl#%28resource%29%20ssl.certificate%5Fpacks%20%3E%20%28model%29%20request%5Fvalidity%20%3E%20%28schema%29)

The number of days for which the certificate should be valid.

id?: string

Identifier.

maxLength32

certificate?: string

The Origin CA certificate. Will be newline-encoded.

expires\_on?: string

When the certificate will expire.

OriginCACertificateDeleteResponse { id, revoked\_at } 

id?: string

Identifier.

maxLength32

revoked\_at?: string

When the certificate was revoked.

formatdate-time