gets the certificates of the device
get /api/v1/mdm/devices/{device_id}/certificates
https://{server-hostname}:8383/api/v1/mdm/devices/{device_id}/certificates
MDMInventory.READCopied!
Authorization: d92d4xxxxxxxxxxxxx15f52
Unique identifier of the device. Obtain from the Get Device List response
Maximum number of records to return in a single response. Used together with offset for pagination
Pagination continuation token returned by a previous response. Pass it to fetch the next page of results
Zero-based index of the first record to return. Used together with limit for pagination
Token used for delta/incremental fetches. Pass the token returned from a previous response to retrieve only items modified since that point
Value to search for. Must be used in combination with searchfield to specify which field is searched
Name of the field to search against. Used together with searchkey (e.g., name, email, udid)
Set to true to return apps from the allow list, false to return apps from the block list
Set to true to restrict results to apps purchased through the enterprise app portal (VPP/managed Google Play). Default: false
Free-text search string applied to the default searchable fields of the resource
Filter applications by their assignment scope. Allowed values: 1=All, 2=Assigned to groups, 3=Assigned to devices
Filter results by device platform. Allowed values: 1=iOS, 2=Android, 3=Windows, 4=macOS, 6=tvOS
Filter results by expiry timestamp (epoch milliseconds)
Return only certificates that expire before this timestamp (epoch milliseconds)
Certificate issuer filter (Distinguished Name or issuer common name)
Certificate subject filter (Distinguished Name or common name)
When true, includes the raw certificate/file content in the response. Default: false
curl --request GET \
--url 'https://appdomain/api/v1/mdm/devices/{device_id}/certificates?limit=SOME_INTEGER_VALUE&skip-token=SOME_STRING_VALUE&offset=SOME_INTEGER_VALUE&delta-token=SOME_STRING_VALUE&searchkey=SOME_STRING_VALUE&searchfield=SOME_STRING_VALUE&is_allowed_apps=SOME_BOOLEAN_VALUE&is_app_purchased_from_portal=SOME_BOOLEAN_VALUE&search=SOME_STRING_VALUE&app_scope=SOME_STRING_VALUE&platform=SOME_STRING_VALUE&expiry=SOME_STRING_VALUE&expiresBefore=SOME_STRING_VALUE&issuer=SOME_STRING_VALUE&subject=SOME_STRING_VALUE&includeContent=SOME_BOOLEAN_VALUE' \
--header 'Accept: application/json' \
--header 'Authorization: d92d4xxxxxxxxxxxxx15f52'Container with managed and unmanaged certificate arrays
Array of certificates not managed through MDM
OID of the signature algorithm (e.g., 1.2.840.113549.1.1.11)
Common name of the certificate
Full subject distinguished name of the certificate
Serial number of the certificate
Certificate expiry timestamp in milliseconds
Whether this is an identity certificate
Full issuer distinguished name
Human-readable signature algorithm name (e.g., SHA256withRSA)
Array of certificates installed through MDM
OID of the signature algorithm (e.g., 1.2.840.113549.1.1.11)
Common name of the certificate
Full subject distinguished name of the certificate
Serial number of the certificate
Certificate expiry timestamp in milliseconds
Whether this is an identity certificate
Full issuer distinguished name
Human-readable signature algorithm name (e.g., SHA256withRSA)
Managed and unmanaged certificates on the device
{
"certificates": {
"unmanagedcertificates": [
{
"certificateissuername": "CN=ExternalCA, O=Company, OU=IT, ST=CA, C=US",
"serialnumber": "5482640642439599254",
"certificatename": "ExternalCA",
"certificateexpiry": "4696305454000",
"signaturealgorithmname": "SHA256withRSA",
"isidentity": false,
"signaturealgorithmoid": "1.2.840.113549.1.1.11",
"certificatesubjectname": "CN=ExternalCA, O=Company, OU=IT, ST=CA, C=US"
}
],
"managedcertificates": [
{
"certificateissuername": "CN=ZylkerCA, O=Zylker Inc, OU=Zylker IT, ST=CA, C=US",
"serialnumber": "5482640642439599254",
"certificatename": "ZylkerCA",
"certificateexpiry": "4696305454000",
"signaturealgorithmname": "SHA256withRSA",
"isidentity": false,
"signaturealgorithmoid": "1.2.840.113549.1.1.11",
"certificatesubjectname": "CN=ZylkerCA, O=Zylker Inc, OU=Zylker IT, ST=CA, C=US"
}
]
}
}
![]()
Duration: 1 minute | Threshold: 250 | Lock period: 5 minutes
Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.