---
title: "Deletes a certificate from a specified key vault."
method: DELETE
path: "/certificates/{certificate-name}"
tags: ["Certificates"]
---

# Deletes a certificate from a specified key vault.

`DELETE /certificates/{certificate-name}`

Deletes all versions of a certificate object along with its associated policy. Delete certificate cannot be used to remove individual versions of a certificate object. This operation requires the certificates/delete permission.

## Path parameters

- `certificate-name` string, required

## Query parameters

- `api-version` string, required

## Response `200`

The deleted certificate.

- DeletedCertificateBundle — A certificate bundle consists of a certificate (X509) plus its attributes.
  - `id` string — The certificate id.
  - `kid` string — The key id.
  - `sid` string — The secret id.
  - `x5t` string, base64url — Thumbprint of the certificate.
  - `policy` CertificatePolicy — Management policy for a certificate.
    - `id` string — The certificate id.
    - `key_props` KeyProperties — Properties of the key pair backing a certificate.
      - `exportable` boolean — Indicates if the private key can be exported.
      - `kty` string — The key type.
      - `key_size` integer — The key size in bytes. For example; 1024 or 2048.
      - `reuse_key` boolean — Indicates if the same key pair will be used on certificate renewal.
    - `secret_props` SecretProperties — Properties of the key backing a certificate.
      - `contentType` string — The media type (MIME type).
    - `x509_props` X509CertificateProperties — Properties of the X509 component of a certificate.
      - `subject` string — The subject name. Should be a valid X509 distinguished Name.
      - `ekus` string[] — The enhanced key usage.
      - `sans` SubjectAlternativeNames — The subject alternate names of a X509 object.
        - `emails` string[] — Email addresses.
        - `dns_names` string[] — Domain names.
        - `upns` string[] — User principal names.
      - `key_usage` string[] — List of key usages.
      - `validity_months` integer — The duration that the ceritifcate is valid in months.
    - `lifetime_actions` LifetimeAction[] — Actions that will be performed by Key Vault over the lifetime of a certificate.
      - `trigger` Trigger — A condition to be satisfied for an action to be executed.
        - `lifetime_percentage` integer — Percentage of lifetime at which to trigger. Value should be between 1 and 99.
        - `days_before_expiry` integer — Days before expiry to attempt renewal. Value should be between 1 and validity_in_months multiplied by 27. If validity_in_months is 36, then value should be between 1 and 972 (36 * 27).
      - `action` Action — The action that will be executed.
        - `action_type` 'EmailContacts' | 'AutoRenew' — The type of the action.
    - `issuer` IssuerParameters — Parameters for the issuer of the X509 component of a certificate.
      - `name` string — Name of the referenced issuer object or reserved names; for example, 'Self' or 'Unknown'.
      - `cty` string — Type of certificate to be requested from the issuer provider.
    - `attributes` CertificateAttributes — The object attributes managed by the KeyVault service.
      - `enabled` boolean — Determines whether the object is enabled.
      - `nbf` integer — Not before date in UTC.
      - `exp` integer — Expiry date in UTC.
      - `created` integer — Creation time in UTC.
      - `updated` integer — Last updated time in UTC.
  - `cer` string, byte — CER contents of x509 certificate.
  - `contentType` string — The content type of the secret.
  - `attributes` CertificateAttributes — The object attributes managed by the KeyVault service.
    - `enabled` boolean — Determines whether the object is enabled.
    - `nbf` integer — Not before date in UTC.
    - `exp` integer — Expiry date in UTC.
    - `created` integer — Creation time in UTC.
    - `updated` integer — Last updated time in UTC.
  - `tags` object — Application specific metadata in the form of key-value pairs

## Other responses

- `default` — Key Vault error response describing why the operation failed.

---

[API](https://skmtc.dev/azure/apis/keyvaultclient.md) · [All operations](https://skmtc.dev/azure/apis/keyvaultclient/llms.txt) · [OpenAPI document](https://skmtc.dev/azure/apis/keyvaultclient/revisions/cf38bcf6c4de?raw)
