Retrieve certificate details for a managed device

Open in ChatGPT Open in ChatGPT to ask questions about this page
Open in Claude Open in Claude to ask questions about this page
Copy as MarkdownCopy this page as markdown to use with AI assistants
View as Markdown Open this page as markdown in a new tab

gets the certificates of the device

Request URL

https://{server-hostname}:8383/api/v1/mdm/devices/{device_id}/certificates

Scope

MDMInventory.READCopied!

Header

Authorization: d92d4xxxxxxxxxxxxx15f52

Request Parameters

- Request Headers

AcceptstringMandatory
application/jsonapplication/jsonCopied!

- Path Parameters

device_idstringMandatory

Unique identifier of the device. Obtain from the Get Device List response

- Query Parameters

limitintegerOptional

Maximum number of records to return in a single response. Used together with offset for pagination

skip-tokenstringOptional

Pagination continuation token returned by a previous response. Pass it to fetch the next page of results

offsetintegerOptional

Zero-based index of the first record to return. Used together with limit for pagination

delta-tokenstringOptional

Token used for delta/incremental fetches. Pass the token returned from a previous response to retrieve only items modified since that point

searchkeystringOptional

Value to search for. Must be used in combination with searchfield to specify which field is searched

searchfieldstringOptional

Name of the field to search against. Used together with searchkey (e.g., name, email, udid)

is_allowed_appsbooleanOptional

Set to true to return apps from the allow list, false to return apps from the block list

is_app_purchased_from_portalbooleanOptional

Set to true to restrict results to apps purchased through the enterprise app portal (VPP/managed Google Play). Default: false

searchstringOptional

Free-text search string applied to the default searchable fields of the resource

app_scopestringOptional

Filter applications by their assignment scope. Allowed values: 1=All, 2=Assigned to groups, 3=Assigned to devices

platformstringOptional

Filter results by device platform. Allowed values: 1=iOS, 2=Android, 3=Windows, 4=macOS, 6=tvOS

expirystringOptional

Filter results by expiry timestamp (epoch milliseconds)

expiresBeforestringOptional

Return only certificates that expire before this timestamp (epoch milliseconds)

issuerstringOptional

Certificate issuer filter (Distinguished Name or issuer common name)

subjectstringOptional

Certificate subject filter (Distinguished Name or common name)

includeContentbooleanOptional

When true, includes the raw certificate/file content in the response. Default: false

Sample Request

Curl
Java
Python
Deluge
PowerShell
Copied!
curl --request GET \
  --url 'https://appdomain/api/v1/mdm/devices/{device_id}/certificates?limit=SOME_INTEGER_VALUE&skip-token=SOME_STRING_VALUE&offset=SOME_INTEGER_VALUE&delta-token=SOME_STRING_VALUE&searchkey=SOME_STRING_VALUE&searchfield=SOME_STRING_VALUE&is_allowed_apps=SOME_BOOLEAN_VALUE&is_app_purchased_from_portal=SOME_BOOLEAN_VALUE&search=SOME_STRING_VALUE&app_scope=SOME_STRING_VALUE&platform=SOME_STRING_VALUE&expiry=SOME_STRING_VALUE&expiresBefore=SOME_STRING_VALUE&issuer=SOME_STRING_VALUE&subject=SOME_STRING_VALUE&includeContent=SOME_BOOLEAN_VALUE' \
  --header 'Accept: application/json' \
  --header 'Authorization:  d92d4xxxxxxxxxxxxx15f52'

Response Parameters

- HTTP code 200

Response Body - application/json
JSON Object
Hide Sub-Attributes
certificatesJSON Object

Container with managed and unmanaged certificate arrays

Show Sub-Attributes
unmanagedcertificatesJSON Array

Array of certificates not managed through MDM

Show Sub-Attributes
JSON Object
Show Sub-Attributes
signaturealgorithmoidstring

OID of the signature algorithm (e.g., 1.2.840.113549.1.1.11)

certificatenamestring

Common name of the certificate

certificatesubjectnamestring

Full subject distinguished name of the certificate

serialnumberstring

Serial number of the certificate

certificateexpirystring

Certificate expiry timestamp in milliseconds

isidentityboolean

Whether this is an identity certificate

certificateissuernamestring

Full issuer distinguished name

signaturealgorithmnamestring

Human-readable signature algorithm name (e.g., SHA256withRSA)

managedcertificatesJSON Array

Array of certificates installed through MDM

Show Sub-Attributes
JSON Object
Show Sub-Attributes
signaturealgorithmoidstring

OID of the signature algorithm (e.g., 1.2.840.113549.1.1.11)

certificatenamestring

Common name of the certificate

certificatesubjectnamestring

Full subject distinguished name of the certificate

serialnumberstring

Serial number of the certificate

certificateexpirystring

Certificate expiry timestamp in milliseconds

isidentityboolean

Whether this is an identity certificate

certificateissuernamestring

Full issuer distinguished name

signaturealgorithmnamestring

Human-readable signature algorithm name (e.g., SHA256withRSA)

Possible Response Codes

200HTTP code

Sample Response: HTTP 200

Managed and unmanaged certificates on the device

Copied!
  {
    "certificates": {
      "unmanagedcertificates": [
        {
          "certificateissuername": "CN=ExternalCA, O=Company, OU=IT, ST=CA, C=US",
          "serialnumber": "5482640642439599254",
          "certificatename": "ExternalCA",
          "certificateexpiry": "4696305454000",
          "signaturealgorithmname": "SHA256withRSA",
          "isidentity": false,
          "signaturealgorithmoid": "1.2.840.113549.1.1.11",
          "certificatesubjectname": "CN=ExternalCA, O=Company, OU=IT, ST=CA, C=US"
        }
      ],
      "managedcertificates": [
        {
          "certificateissuername": "CN=ZylkerCA, O=Zylker Inc, OU=Zylker IT, ST=CA, C=US",
          "serialnumber": "5482640642439599254",
          "certificatename": "ZylkerCA",
          "certificateexpiry": "4696305454000",
          "signaturealgorithmname": "SHA256withRSA",
          "isidentity": false,
          "signaturealgorithmoid": "1.2.840.113549.1.1.11",
          "certificatesubjectname": "CN=ZylkerCA, O=Zylker Inc, OU=Zylker IT, ST=CA, C=US"
        }
      ]
    }
  }
                
Show full

Duration: 1 minute | Threshold: 250 | Lock period: 5 minutes

Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.