# Certificate Manager quickstart

This guide instructs you through binding your first certificate of your own to a [workload](/en/documentation/platform/workloads/) with [Certificate Manager](/en/documentation/platform/workloads/#certificate-manager).

- Upload a server certificate and its private key to Certificate Manager.
- Bind the certificate to your workload.
- Confirm that Certificate Manager reports the certificate as active.

Three objects take part, and each one links to the next:

1. The **certificate** is a server certificate you upload to Certificate Manager with its private key. The API stores it with `type` set to `edge_certificate`. Its status stays `inactive` until a workload uses it.
2. The **workload** names the certificate in its `tls.certificate` field. While that field is `null`, the workload uses the Azion SAN certificate instead.
3. The **domains** of the workload are the hostnames the certificate must cover. The API does not compare the certificate's names with the domains, so a certificate that does not cover them is still accepted.

An uploaded certificate protects no traffic until a workload names it. A workload with no certificate of yours keeps the Azion SAN certificate, which covers only the workload domain and the Azion Custom Domain. This guide changes only the `tls` settings of the workload and keeps its domains, ports, and deployment as they are.

To have Azion request a certificate from Let's Encrypt and renew it for you instead, refer to [Request a Let's Encrypt certificate](/en/documentation/guides/application-security/tls-and-certificates/how-to-generate-a-lets-encrypt-certificate/). The workload's **Digital Certificate** field also offers the Let's Encrypt presets, described in [Certificates](/en/documentation/platform/workloads/certificate-manager/certificates/#lets-encrypt-certificate).

---

Select the interface you use. The prerequisites and every stage on this page follow that choice.

## Prerequisites

- An Azion account. To create one, refer to [Create an account](/en/documentation/fundamentals/creating-account/).
- A workload that lists your domain in its domains. To add a domain, refer to [Add a custom domain to a workload](/en/documentation/guides/platform/migration/configure-a-domain/).
- A certificate in PEM format that covers your domain, with its private key, also in PEM and without a passphrase. RSA 2048 keys and P-256 keys are accepted.

**Console**

- Access to Azion Console. To sign in, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).

**CLI**

- The [Azion CLI](/en/documentation/devtools/cli/), installed and authorized.
- The certificate and the private key saved as files, such as `server.pem` and `server.key`.
- The ID of your workload.

**API**

- A personal token and `curl`. To create a token, refer to [Personal tokens](/en/documentation/fundamentals/personal-tokens/).
- The ID of your workload.

---

## Upload the certificate

A server certificate holds the certificate and its private key. Once saved, the private key cannot be read back from the Console or the API. You can upload the certificate alone or with its intermediate certificates.

**Console**

To upload the certificate in Azion Console:

1. **Open the Certificate Manager page**

   Access [Azion Console](https://console.azion.com/) > **Certificate Manager**.

2. **Start a new certificate**

   Select **Create Digital Certificate**. The **Create Digital Certificate** page opens.

3. **Select the Server Certificate preset**

4. **Name the certificate**

   In **Name**, enter a name for the certificate, such as `my-certificate`.

5. **Paste the certificate**

   In **Certificate**, paste the PEM certificate, including its `-----BEGIN CERTIFICATE-----` and `-----END CERTIFICATE-----` lines. The help text reads "Intermediate certificates are accepted."

6. **Paste the private key**

   In **Private Key**, paste the PEM private key, including its `-----BEGIN` and `-----END` lines.

7. **Select Create**

The certificate appears in the **Certificate Manager** list as a **TLS Certificate**. It stays `inactive` until a workload uses it.

**CLI**

To upload the certificate with the Azion CLI, pass the paths of the two PEM files:

```bash
azion create digital-certificate --name my-certificate \
  --certificate server.pem --private-key server.key
```

The command prints the ID of the new certificate:

```text
Created Digital Certificate with ID <certificate-id>
```

Record the ID to bind the certificate to your workload. List the certificates of your account:

```bash
azion list digital-certificate --details
```

The output shows your certificate with the type `edge_certificate` and the status `inactive`:

```text
ID                NAME            STATUS    ISSUER  VALIDITY                   TYPE              MANAGED  LAST EDITOR   LAST MODIFIED
<certificate-id>  my-certificate  inactive          2026-01-31 12:00:00+00:00  edge_certificate  false    <your-email>  2026-01-01 12:00:00.000000 +0000 UTC
```

The certificate exists in Certificate Manager, and no workload uses it yet.

**API**

To upload the certificate with the API, send a `POST` request to the certificates endpoint. `type` set to `edge_certificate` makes it a server certificate. In the body, `certificate` and `private_key` are JSON strings. Write each one as a single continuous string that keeps its `-----BEGIN` and `-----END` lines, with every line break written as `\n`. Replace `[TOKEN VALUE]` with your personal token:

```bash
curl --request POST \
  --url https://api.azion.com/v4/workspace/tls/certificates \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data '{
  "name": "my-certificate",
  "type": "edge_certificate",
  "certificate": "-----BEGIN CERTIFICATE-----\n<certificate-body>\n-----END CERTIFICATE-----\n",
  "private_key": "-----BEGIN PRIVATE KEY-----\n<private-key-body>\n-----END PRIVATE KEY-----\n"
}'
```

The API answers with `201` and returns the new certificate. Record its `id` to bind the certificate to your workload. The certificate exists in Certificate Manager, and no workload uses it yet.

---

## Bind the certificate to your workload

A workload uses a server certificate only once its `tls.certificate` field names it. Before you bind it, check that the certificate covers the domains of the workload. The API accepts a certificate that does not cover them.

**Console**

To bind the certificate in Azion Console:

1. **Open the Workloads page**

   Access [Azion Console](https://console.azion.com/) > **Workloads**.

2. **Open your workload**

   Select your workload. The **Edit Workload** page opens.

3. **Turn on HTTPS support**

   In **Protocol Settings**, turn on **HTTPS support** if it is off. **Digital Certificate** appears only while it is on.

4. **Select your certificate**

   In **Digital Certificate**, select your certificate in the **My certificates** group.

5. **Select Save**

Azion Console shows the message "Your workload has been updated". The workload names your certificate in `tls.certificate`.

**CLI**

To bind the certificate with the Azion CLI, save the JSON below as `tls.json`. Replace `<workload-id>` and `<certificate-id>`:

```json
{
  "id": <workload-id>,
  "tls": {
    "certificate": <certificate-id>,
    "ciphers": 7,
    "minimum_version": "tls_1_3"
  }
}
```

The file sends the whole `tls` object. It names your certificate and keeps the defaults of a new workload, cipher suite `7` and TLS 1.3 as the minimum version. If your workload uses other values, send those instead. Send the file:

```bash
azion update workload --file tls.json
```

The command prints the ID of the workload:

```text
Updated Workload with ID <workload-id>
```

The workload names your certificate in `tls.certificate`.

**API**

To bind the certificate with the API, send a `PATCH` request to your workload with the `tls` object. It names your certificate and keeps the defaults of a new workload, cipher suite `7` and TLS 1.3 as the minimum version. If your workload uses other values, send those instead. Replace `<workload-id>` and `<certificate-id>`:

```bash
curl --request PATCH \
  --url https://api.azion.com/v4/workspace/workloads/<workload-id> \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data '{
  "tls": {
    "certificate": <certificate-id>,
    "ciphers": 7,
    "minimum_version": "tls_1_3"
  }
}'
```

The API accepts the update, and the workload names your certificate in `tls.certificate`.

---

## Confirm the certificate is active

Certificate Manager reports a certificate as `active` once a workload names it. The status shows that your workload uses the certificate.

**Console**

To confirm the status in Azion Console:

1. **Open the Certificate Manager page**

   Access [Azion Console](https://console.azion.com/) > **Certificate Manager**.

2. **Find your certificate**

   Find your certificate in the list, and confirm that its status is `active`. A `pending` certificate shows a warning icon, and a `failed` certificate shows an error icon with the reason.

Your certificate is active, and your workload uses it.

**CLI**

To confirm the status with the Azion CLI, list the certificates of your account:

```bash
azion list digital-certificate --details
```

The output shows your certificate with the status `active`:

```text
ID                NAME            STATUS  ISSUER  VALIDITY                   TYPE              MANAGED  ...
<certificate-id>  my-certificate  active          2026-01-31 12:00:00+00:00  edge_certificate  false    ...
```

Your certificate is active, and your workload uses it.

**API**

To confirm the status with the API, send a `GET` request to your certificate. Replace `<certificate-id>`:

```bash
curl --request GET \
  --url https://api.azion.com/v4/workspace/tls/certificates/<certificate-id> \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]'
```

The response returns your certificate. These are some of its fields, with `status` set to `active`:

```json
{
 "id": <certificate-id>,
 "managed": false,
 "name": "my-certificate",
 "status": "active",
 "type": "edge_certificate"
}
```

Your certificate is active, and your workload uses it.

Binding a certificate is a change to the workload. The change takes several minutes to reach all of Azion's distributed infrastructure, with no guaranteed duration. Meanwhile, requests can meet the old configuration or the new one. For more information, refer to [Propagation](/en/documentation/platform/workloads/how-it-works/#propagation).

---

## Next steps

- [Request a Let's Encrypt certificate](/en/documentation/guides/application-security/tls-and-certificates/how-to-generate-a-lets-encrypt-certificate.md): Have Azion request a certificate for your domain from Let's Encrypt and renew it for you.
- [Certificates](/en/documentation/platform/workloads/certificate-manager/certificates.md): Every certificate type, field, status, and error, with the CSR and CRL objects.
- [mTLS](/en/documentation/platform/workloads/mtls.md): Check client certificates against a Trusted CA certificate on your workload.
- [Issuance and renewal](/en/documentation/platform/workloads/certificate-manager/issuance-and-renewal.md): How Azion validates, issues, and renews a Let's Encrypt certificate.
