# Identity: certificate

> Whether the identity is certified, and its root, chain, validity and pending CSR (SPEC §2)

## Whether the identity is certified, and its root, chain, validity and pending CSR (SPEC §2)

`GET /v1/identities/{slug}/certificate` · operation `getCertificate`

Requires the `batondeck:identities:read` permission (action `cert:read`).

**Parameters**

| Name | In | Type | Required | Notes |
|---|---|---|---|---|
| `slug` | path | string | yes |  |

**Responses**

| Status | Meaning |
|---|---|
| 200 | Whether the identity is certified, and its root, chain, validity and pending CSR (SPEC §2) |
| 401 | No portal session, and no live API key. |
| 403 | The policy refused, or the request was cross-site. |
| 404 | No such resource, or none this session may see. |

<details>
<summary>200 response schema</summary>

```json
{
  "type": "object",
  "properties": {
    "certified": {
      "type": "boolean"
    },
    "root_fingerprint": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "chain": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "kid": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "endpoint": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "not_before": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "not_after": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "renewal_due": {
      "type": "boolean"
    },
    "expired": {
      "type": "boolean"
    },
    "pending_csr": {
      "anyOf": [
        {
          "type": "object",
          "properties": {
            "endpoint": {
              "type": "string"
            },
            "purpose": {
              "type": "string"
            },
            "created_at": {
              "type": "number"
            },
            "key_fingerprint": {
              "type": "string"
            }
          },
          "required": [
            "endpoint",
            "purpose",
            "created_at",
            "key_fingerprint"
          ],
          "additionalProperties": false
        },
        {
          "type": "null"
        }
      ]
    },
    "superseded_kids": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "accept_new_hosts": {
      "type": "string"
    },
    "backup_verified_at": {
      "anyOf": [
        {
          "type": "number"
        },
        {
          "type": "null"
        }
      ]
    }
  },
  "required": [
    "certified",
    "root_fingerprint",
    "chain",
    "kid",
    "endpoint",
    "not_before",
    "not_after",
    "renewal_due",
    "expired",
    "pending_csr",
    "superseded_kids",
    "accept_new_hosts",
    "backup_verified_at"
  ],
  "additionalProperties": false
}
```

</details>

```sh
curl -X GET 'https://api.batondeck.com/v1/identities/:slug/certificate' \
  -H "Authorization: Bearer $BATONDECK_API_KEY"
```
