---
title: "Export certificate private key"
method: POST
path: "/api/certificates/{certificateId}/export/private-key"
tags: ["Certificates"]
---

# Export certificate private key

`POST /api/certificates/{certificateId}/export/private-key`

Exports the private key of a certificate, re-encrypted with the given passphrase

## Path parameters

- `certificateId` string, required

## Request body

- CertificatePrivateKeyExportCommandDTO — Command DTO for exporting a certificate's private key. Used as the request body for the private key export endpoint, to protect the exported key at rest.
  - `passphrase` string, required — The passphrase used to encrypt the exported private key.

## Response `200`

Private key exported successfully

## Changes

- **2026-09-23** `92023a2f20ae` — 1 info
  - endpoint added
- **2026-09-21** `fbefadfe3be3` — 1 breaking
  - api path removed without deprecation
- **2026-09-21** `91dba375a461` — 1 info
  - endpoint added
- **2026-09-21** `52d824185a20` — 1 breaking
  - api path removed without deprecation
- **2026-09-08** `6cc2578622b5` — 1 info
  - endpoint added

[Full history](https://skmtc.dev/optimistiksas/apis/oibus-api/changes/api/certificates/:certificateId/export/private-key/post.md)

---

[API](https://skmtc.dev/optimistiksas/apis/oibus-api.md) · [All operations](https://skmtc.dev/optimistiksas/apis/oibus-api/llms.txt) · [OpenAPI document](https://skmtc.dev/optimistiksas/apis/oibus-api/revisions/a34e6afd34e1?raw)
