# Retrieve certificate details for a managed device gets the certificates of the device ## Endpoint `GET /api/v1/mdm/devices/{device_id}/certificates` ## Request URL `https://{serverurl}/api/v1/mdm/devices/{device_id}/certificates` ## Scope `MDMOnDemand.MDMInventory.READ` ## Header `Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52` ## Request Parameters ### Request Headers - **Accept** `string` — **Mandatory** — `application/json` ### Path Parameters - **device_id** `string` — **Mandatory** Unique identifier of the device. Obtain from the [Get Device List](https://www.manageengine.com/mobile-device-management/help/api/cloud/devices-get-device-list.html) response ### Query Parameters - **limit** `integer` — Optional Maximum number of records to return in a single response. Used together with offset for pagination - **skip-token** `string` — Optional Pagination continuation token returned by a previous response. Pass it to fetch the next page of results - **offset** `integer` — Optional Zero-based index of the first record to return. Used together with limit for pagination - **delta-token** `string` — Optional Token used for delta/incremental fetches. Pass the token returned from a previous response to retrieve only items modified since that point - **searchkey** `string` — Optional Value to search for. Must be used in combination with searchfield to specify which field is searched - **searchfield** `string` — Optional Name of the field to search against. Used together with searchkey (e.g., name, email, udid) - **is_allowed_apps** `boolean` — Optional Set to true to return apps from the allow list, false to return apps from the block list - **is_app_purchased_from_portal** `boolean` — Optional Set to true to restrict results to apps purchased through the enterprise app portal (VPP/managed Google Play). Default: false - **search** `string` — Optional Free-text search string applied to the default searchable fields of the resource - **app_scope** `string` — Optional Filter applications by their assignment scope. Allowed values: 1=All, 2=Assigned to groups, 3=Assigned to devices - **platform** `string` — Optional Filter results by device platform. Allowed values: 1=iOS, 2=Android, 3=Windows, 4=macOS, 6=tvOS - **expiry** `string` — Optional Filter results by expiry timestamp (epoch milliseconds) - **expiresBefore** `string` — Optional Return only certificates that expire before this timestamp (epoch milliseconds) - **issuer** `string` — Optional Certificate issuer filter (Distinguished Name or issuer common name) - **subject** `string` — Optional Certificate subject filter (Distinguished Name or common name) - **includeContent** `boolean` — Optional When true, includes the raw certificate/file content in the response. Default: false ## Sample Request ```curl curl --request GET \ --url https://appdomain/api/v1/mdm/devices/{device_id}/certificates \ --header 'Accept: application/json' \ --header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' ``` ## Response Parameters ### HTTP Code 200 Response body: `application/json` - `JSON object` - **certificates** `JSON object` — Container with managed and unmanaged certificate arrays ## Possible Response Codes - **200** — HTTP code ## Sample Response: HTTP 200 Managed and unmanaged certificates on the device ```json { "certificates": { "unmanagedcertificates": [ { "certificateissuername": "CN=ExternalCA, O=Company, OU=IT, ST=CA, C=US", "serialnumber": "5482640642439599254", "certificatename": "ExternalCA", "certificateexpiry": "4696305454000", "signaturealgorithmname": "SHA256withRSA", "isidentity": false, "signaturealgorithmoid": "1.2.840.113549.1.1.11", "certificatesubjectname": "CN=ExternalCA, O=Company, OU=IT, ST=CA, C=US" } ], "managedcertificates": [ { "certificateissuername": "CN=ZylkerCA, O=Zylker Inc, OU=Zylker IT, ST=CA, C=US", "serialnumber": "5482640642439599254", "certificatename": "ZylkerCA", "certificateexpiry": "4696305454000", "signaturealgorithmname": "SHA256withRSA", "isidentity": false, "signaturealgorithmoid": "1.2.840.113549.1.1.11", "certificatesubjectname": "CN=ZylkerCA, O=Zylker Inc, OU=Zylker IT, ST=CA, C=US" } ] } } ``` ## API Rate Limit **Duration:** 1 minute | **Threshold:** 250 | **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.