# Azion CLI csr

The Azion CLI `csr` commands create, describe, and delete certificate signing requests (CSRs) in [Certificate Manager](/en/documentation/platform/workloads/certificate-manager/certificates/). A CSR is the request you submit to a certificate authority (CA) to obtain a certificate, and the CLI prints it when it creates one. Azion stores a CSR as a digital certificate with status `pending`, so the CSR and your certificates share one set of IDs. The CLI has no command that lists or updates a CSR: `azion list digital-certificate` lists it with your certificates, and the [digital-certificate commands](/en/documentation/devtools/cli/resources/digital-certificate/) manage the entry. The options every command accepts, such as `--format`, `--out`, and `-y`, are on [Global options](/en/documentation/devtools/cli/globals/).

---

## Create

`azion create csr` creates a CSR with the subject and the key algorithm you pass, and prints the request:

```bash
azion create csr [flags]
```

| Flag                   | Short | Type   | Default | Description                                                                                                                                            |
| ---------------------- | ----- | ------ | ------- | ------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `--alternative-names`  | —     | string | —       | Comma-separated list of Subject Alternative Names (SANs).                                                                                              |
| `--certificate-type`   | —     | string | —       | Type of the certificate, such as `edge_certificate` or `trusted_ca_certificate`. Without it, the CSR gets type `edge_certificate`.                     |
| `--common-name`        | —     | string | —       | Common Name (CN) of the certificate subject.                                                                                                           |
| `--country`            | —     | string | —       | **Required** unless `--file` is set. Country code of the certificate subject, such as `US` or `BR`. Without it, the command asks for the country code. |
| `--email`              | —     | string | —       | Contact email address of the certificate subject.                                                                                                      |
| `--file`               | —     | string | —       | Path to a JSON file with the attributes of the CSR. Use `-` to read the JSON from standard input.                                                      |
| `--key-algorithm`      | —     | string | —       | Algorithm of the key: `rsa_2048`, `rsa_4096`, or `ecc_384`.                                                                                            |
| `--locality`           | —     | string | —       | City or locality of the certificate subject.                                                                                                           |
| `--name`               | —     | string | —       | Name that identifies the CSR.                                                                                                                          |
| `--organization`       | —     | string | —       | Organization name of the certificate subject.                                                                                                          |
| `--organization-unity` | —     | string | —       | Organizational unit of the certificate subject.                                                                                                        |
| `--state`              | —     | string | —       | State or province of the certificate subject.                                                                                                          |

A `--key-algorithm` value outside the three listed is refused with `"rsa_1024" is not a valid choice.`, and a `--name` that a certificate of your account already uses is refused with `This field must be unique.` Every name in `--common-name` and `--alternative-names` must belong to a domain your account has permission for. The bounds of each field are in [Certificates](/en/documentation/platform/workloads/certificate-manager/certificates/).

This command creates a CSR named `my-csr` for `example.com` and `www.example.com`, with a 2048-bit RSA key:

```bash
azion create csr --name my-csr --common-name example.com --country BR --state 'Rio Grande do Sul' --locality 'Porto Alegre' --organization 'Example Corp' --organization-unity Docs --email admin@example.com --alternative-names 'www.example.com' --key-algorithm rsa_2048
```

The command prints the ID of the CSR, then the request in PEM format, which ends with `-----END CERTIFICATE REQUEST-----`. The output opens with these lines:

```text
Created Certificate Signing Request with ID 123481
-----BEGIN CERTIFICATE REQUEST-----
```

---

## Describe

`azion describe csr` prints the settings and the status of one CSR, and the request itself:

```bash
azion describe csr [flags]
```

| Flag       | Short | Type | Default | Description                |
| ---------- | ----- | ---- | ------- | -------------------------- |
| `--csr-id` | —     | int  | —       | ID of the CSR to describe. |

This command describes the CSR with ID `123481`:

```bash
azion describe csr --csr-id 123481
```

The command prints the fields of the CSR, then the request under `CSR:`, which ends with `-----END CERTIFICATE REQUEST-----`. The output opens with these lines:

```text
ID:              123481
Name:            my-csr
Issuer:          null
Subject Names:   []
Validity:        null
Type:            edge_certificate
Managed:         false
Status:          pending
Status Detail:
Challenge:
Authority:
Key Algorithm:   rsa_2048
Active:          true
Last Editor:     you@example.com
Created At:      "2026-01-01T12:00:00.763397Z"
Last Modified:   "2026-01-01T12:00:00.763397Z"
Renewed At:      null

CSR:
-----BEGIN CERTIFICATE REQUEST-----
```

With `--format json`, the command prints the full object: `active`, `authority`, `certificate`, `challenge`, `created_at`, `csr`, `id`, `issuer`, `key_algorithm`, `last_editor`, `last_modified`, `managed`, `name`, `product_version`, `renewed_at`, `status`, `status_detail`, `subject_name`, `type`, and `validity`. These are the keys of a digital certificate. The `csr` value holds the request with each line break written as `\n`, and `certificate` stays `null`. With `--out csr-describe.json`, the command writes the same object to that file and prints `File successfully written to: csr-describe.json`.

`azion describe csr` also accepts the ID of a certificate that did not come from a CSR, and prints that certificate. An ID that does not exist fails with `Error: Failed to get the Certificate Signing Request: The given ID or API's endpoint doesn't exist or isn't available.`, followed by a hint to check your settings.

---

## Delete

`azion delete csr` deletes a CSR:

```bash
azion delete csr [flags]
```

| Flag       | Short | Type | Default | Description              |
| ---------- | ----- | ---- | ------- | ------------------------ |
| `--csr-id` | —     | int  | —       | ID of the CSR to delete. |

This command deletes the CSR with ID `123481`:

```bash
azion delete csr --csr-id 123481
```

The command confirms the deletion:

```text
Certificate Signing Request 123481 was successfully deleted
```

---

## Use a JSON file

`azion create csr` reads the attributes of the CSR from a JSON file with `--file`. In the file, `--common-name`, `--organization-unity`, and `--key-algorithm` become the keys `common_name`, `organization_unity`, and `key_algorithm`.

This file creates a CSR named `my-csr-ecc` for `api.example.com` with the `ecc_384` key algorithm:

```json
{
  "name": "my-csr-ecc",
  "common_name": "api.example.com",
  "country": "BR",
  "state": "Rio Grande do Sul",
  "locality": "Porto Alegre",
  "organization": "Example Corp",
  "organization_unity": "Docs",
  "email": "admin@example.com",
  "key_algorithm": "ecc_384"
}
```

Pass the file to the create command:

```bash
azion create csr --file csr-create.json
```

The command prints the ID of the CSR, then the request in PEM format. The output opens with these lines:

```text
Created Certificate Signing Request with ID 123482
-----BEGIN CERTIFICATE REQUEST-----
```

---

## Related resources

- [Global options](/en/documentation/devtools/cli/globals.md): The options every command accepts, such as `--format`, `--out`, and `-y`.
- [Certificates](/en/documentation/platform/workloads/certificate-manager/certificates.md): The fields of a CSR, its bounds, and how to add the certificate the CA signs.
- [Azion CLI digital-certificate](/en/documentation/devtools/cli/resources/digital-certificate.md): The commands that list your CSRs with your certificates and manage each entry.
- [Resource commands](/en/documentation/devtools/cli/resources.md): Every resource the CLI manages, and the verbs each one supports.
