---
title: "Create a new CA Certificate"
method: POST
path: "/v2/control-planes/{controlPlaneId}/core-entities/ca_certificates"
tags: ["CA Certificates"]
---

# Create a new CA Certificate

`POST /v2/control-planes/{controlPlaneId}/core-entities/ca_certificates`

Create a new CA Certificate

## Request body

- CACertificate — A CA certificate object represents a trusted CA. These objects are used by Kong to verify the validity of a client or server certificate.
  - `cert` string, required — PEM-encoded public certificate of the CA.
  - `cert_digest` string, nullable — SHA256 hex digest of the public certificate. This field is read-only and it cannot be set by the caller, the value is automatically computed.
  - `created_at` integer, nullable — Unix epoch when the resource was created.
  - `id` string, nullable — A string representing a UUID (universally unique identifier).
  - `tags` string[], nullable — An optional set of strings associated with the Certificate for grouping and filtering.
  - `updated_at` integer, nullable — Unix epoch when the resource was last updated.

## Response `201`

Successfully created CA Certificate

- CACertificate — A CA certificate object represents a trusted CA. These objects are used by Kong to verify the validity of a client or server certificate.
  - `cert` string, required — PEM-encoded public certificate of the CA.
  - `cert_digest` string, nullable — SHA256 hex digest of the public certificate. This field is read-only and it cannot be set by the caller, the value is automatically computed.
  - `created_at` integer, nullable — Unix epoch when the resource was created.
  - `id` string, nullable — A string representing a UUID (universally unique identifier).
  - `tags` string[], nullable — An optional set of strings associated with the Certificate for grouping and filtering.
  - `updated_at` integer, nullable — Unix epoch when the resource was last updated.

## Other responses

- `401` — Unauthorized

## Changes

- **2025-08-22** `96118a9cd7f4` — 2 info
  - the request optional property `cert_digest` became read-only
  - the response optional property `cert_digest` became read-only for the status `201`
- **2025-07-22** `2c77aeaee5fb` — 1 breaking, 1 info
  - the response property `tags` became nullable for the status `201`
  - the request property `tags` became nullable
- **2025-04-15** `fc6abbc537f3` — 2 breaking, 6 info
  - the response property `created_at` became nullable for the status `201`
  - the response property `updated_at` became nullable for the status `201`
  - the request optional property `created_at` became not read-only
  - the request optional property `updated_at` became not read-only
  - …4 more
- **2024-12-06** `426663331655` — 1 breaking
  - the request property `tags` became not nullable
- **2024-11-11** `08ead66e9ebb` — 4 breaking, 6 info
  - the request property `cert` became required
  - the response property `cert_digest` became nullable for the status `201`
  - the response property `id` became nullable for the status `201`
  - the response property `tags` became nullable for the status `201`
  - …6 more

[Change history](https://skmtc.dev/kong/apis/konnect-api/changes/v2/control-planes/:controlPlaneId/core-entities/ca_certificates/post.md)

---

[API](https://skmtc.dev/kong/apis/konnect-api.md) · [All operations](https://skmtc.dev/kong/apis/konnect-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/kong/konnect-api/revisions/72502a676a92/schema)
