---
title: "Create"
method: POST
path: "/certificates/{owner_kind}/{owner_id}"
tags: ["certificates"]
---

# Create

`POST /certificates/{owner_kind}/{owner_id}`

Issue a client certificate from a customer-owned CSR.

**Request**: `multipart/form-data` with one file field named `csr`, holding an
ASCII PEM certificate signing request of at most 64 KiB. The customer's private
key is never uploaded.

**Permissions**: org admin. The owner must belong to the caller's organization.
Connector owners must also be active self-serve Connectors.

**Errors**:

| Status | Code | Cause |
|--------|------|-------|
| 404 | `CONNECTOR_NOT_FOUND` | Connector missing, in another org, or ineligible |
| 404 | `PROCESSOR_NOT_FOUND` | Processor missing or in another org |
| 404 | — | Connector certificates disabled for this organization |
| 409 | `CERTIFICATE_LIMIT_REACHED` | Both active slots are in use |
| 422 | `CERTIFICATE_INVALID_CSR` | CSR unreadable, oversized, or invalid |
| 500 | `INTERNAL_ERROR` | Signing, validation, or persistence failed |

Responds with the PEM certificate chain as a file attachment, not JSON.

## Path parameters

- `owner_kind` 'connector' | 'processor', required
- `owner_id` string, required

## Response `201`

Successful Response

- unknown

## Other responses

- `422` — Validation Error

## Changes

> 57 revisions in range; 9 not diffed.

- **2026-09-18** `af140c3c54d8` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/traversal/apis/fastapi/changes/certificates/:owner_kind/:owner_id/post.md)

---

[API](https://skmtc.dev/traversal/apis/fastapi.md) · [All operations](https://skmtc.dev/traversal/apis/fastapi/llms.txt) · [OpenAPI document](https://skmtc.dev/traversal/apis/fastapi/revisions/c3bd9dec6c16?raw)
