---
title: "Get a CA Certificate"
method: GET
path: "/ca_certificates/{CACertificateId}"
tags: ["CA Certificates"]
---

# Get a CA Certificate

`GET /ca_certificates/{CACertificateId}`

Get a CA Certificate using ID.

## Response `200`

Successfully fetched CA Certificate

- CACertificate — A CA certificate object represents a trusted CA. These objects are used by Kong to verify the validity of a client or server certificate.
  - `cert` string, required — PEM-encoded public certificate of the CA.
  - `cert_digest` string, nullable — SHA256 hex digest of the public certificate. This field is read-only and it cannot be set by the caller, the value is automatically computed.
  - `created_at` integer, nullable — Unix epoch when the resource was created.
  - `id` string, nullable — A string representing a UUID (universally unique identifier).
  - `tags` string[], nullable — An optional set of strings associated with the Certificate for grouping and filtering.
  - `updated_at` integer, nullable — Unix epoch when the resource was last updated.

## Other responses

- `401` — Unauthorized
- `404` — Resource does not exist

## Changes

> 11 revisions in range; 1 not diffed.

- **2025-10-09** `740b73588ef4` — 1 breaking
  - the response property `tags` became nullable for the status `200`
- **2025-04-04** `e07a25288f1f` — 2 breaking, 2 info
  - the response property `created_at` became nullable for the status `200`
  - the response property `updated_at` became nullable for the status `200`
  - the response optional property `created_at` became not read-only for the status `200`
  - the response optional property `updated_at` became not read-only for the status `200`
- **2024-11-26** `99e71588eb61` — 2 breaking, 2 info
  - the response property `cert_digest` became nullable for the status `200`
  - the response property `id` became nullable for the status `200`
  - the response optional property `id` became not read-only for the status `200`
  - the response property `cert` became required for the status `200`
- **2024-09-11** `5bd52189d290` — 1 warning
  - deleted the `path` request parameter `CACertificateId`

[Change history](https://skmtc.dev/kong/apis/kong-enterprise-admin-api/changes/ca_certificates/:CACertificateId/get.md)

---

[API](https://skmtc.dev/kong/apis/kong-enterprise-admin-api.md) · [All operations](https://skmtc.dev/kong/apis/kong-enterprise-admin-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/kong/kong-enterprise-admin-api/revisions/28b1f8a59cdc/schema)
