Revoke a certificate
/users/{user_id}/certificates/{certificate_id}Revokes a certificate. Revocation is the only supported change: set status to revoked and provide a reason. Any other field is rejected.
A revoked certificate remains on record and retrievable, and public validation reports it as revoked. Revocation does not affect the user's access, progress, or points. To remove a certificate, use the delete operation instead.
Send the certificate's current ETag in the If-Match header to avoid acting on an outdated version.
Autonomous mode: the API credential secret, sent as a bearer token. Credential secrets are identified by a fixed prefix.
In: header
Path Parameters
Header Parameters
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X PATCH "https://example.com/users/string/certificates/string" \ -H "Content-Type: application/json" \ -d '{ "reason": "string", "status": "revoked" }'{ "data": { "code": "string", "deleted": true, "fields": {}, "id": "string", "issued_at": "2019-08-24T14:15:22Z", "number": { "instance": 0, "product": 0 }, "object": "certificate", "pdf_url": "string", "product_id": "string", "reissue": true, "revision": "string", "revoked": { "at": "2019-08-24T14:15:22Z", "by": { "id": "string", "kind": "admin" }, "reason": "string" }, "status": "valid", "superseded_by_certificate_id": "string", "supersedes_certificate_id": "string", "user_id": "string", "validation_url": "string" }}Retrieve a certificate GET
Revoked certificates remain retrievable, with `status` set to `revoked`. Template previews are not certificates and cannot be retrieved through this operation. The response includes an `ETag` representing the current revision. Send this value in the `If-Match` header when revoking the certificate to avoid acting on an outdated version.
Delete a certificate DELETE
Moves the certificate to the trash. A `reason` is required. Deleted certificates no longer appear in the user's certificate list and can no longer be verified through public validation. To invalidate a certificate while keeping it on record, revoke it through the update operation instead.