# Retrieve certificate details for a managed device gets the certificates of the device ## Endpoint `GET /api/v1/mdm/devices/{device_id}/certificates` ## Request URL ```text https://{server-hostname}:8383/api/v1/mdm/devices/{device_id}/certificates ``` ## Scope ```text MDMInventory.READ ``` ## Header ```text Authorization: d92d4xxxxxxxxxxxxx15f52 ``` ## Request Parameters ### Request Headers - **Accept** `string` — **Mandatory**: `application/json` ### Path Parameters - **device_id** `string` — **Mandatory**: Unique identifier of the device. Obtain from the [Get Device List](https://www.manageengine.com/products/desktop-central/help/api/onpremise/devices-get-device-list.html) response ### Query Parameters - **limit** `integer` — Optional: Maximum number of records to return in a single response. Used together with offset for pagination - **skip-token** `string` — Optional: Pagination continuation token returned by a previous response. Pass it to fetch the next page of results - **offset** `integer` — Optional: Zero-based index of the first record to return. Used together with limit for pagination - **delta-token** `string` — Optional: Token used for delta/incremental fetches. Pass the token returned from a previous response to retrieve only items modified since that point - **searchkey** `string` — Optional: Value to search for. Must be used in combination with searchfield to specify which field is searched - **searchfield** `string` — Optional: Name of the field to search against. Used together with searchkey (e.g., name, email, udid) - **is_allowed_apps** `boolean` — Optional: Set to true to return apps from the allow list, false to return apps from the block list - **is_app_purchased_from_portal** `boolean` — Optional: Set to true to restrict results to apps purchased through the enterprise app portal (VPP/managed Google Play). Default: false - **search** `string` — Optional: Free-text search string applied to the default searchable fields of the resource - **app_scope** `string` — Optional: Filter applications by their assignment scope. Allowed values: 1=All, 2=Assigned to groups, 3=Assigned to devices - **platform** `string` — Optional: Filter results by device platform. Allowed values: 1=iOS, 2=Android, 3=Windows, 4=macOS, 6=tvOS - **expiry** `string` — Optional: Filter results by expiry timestamp (epoch milliseconds) - **expiresBefore** `string` — Optional: Return only certificates that expire before this timestamp (epoch milliseconds) - **issuer** `string` — Optional: Certificate issuer filter (Distinguished Name or issuer common name) - **subject** `string` — Optional: Certificate subject filter (Distinguished Name or common name) - **includeContent** `boolean` — Optional: When true, includes the raw certificate/file content in the response. Default: false ## Sample Request ```curl curl --request GET \ --url 'https://appdomain/api/v1/mdm/devices/{device_id}/certificates?limit=SOME_INTEGER_VALUE&skip-token=SOME_STRING_VALUE&offset=SOME_INTEGER_VALUE&delta-token=SOME_STRING_VALUE&searchkey=SOME_STRING_VALUE&searchfield=SOME_STRING_VALUE&is_allowed_apps=SOME_BOOLEAN_VALUE&is_app_purchased_from_portal=SOME_BOOLEAN_VALUE&search=SOME_STRING_VALUE&app_scope=SOME_STRING_VALUE&platform=SOME_STRING_VALUE&expiry=SOME_STRING_VALUE&expiresBefore=SOME_STRING_VALUE&issuer=SOME_STRING_VALUE&subject=SOME_STRING_VALUE&includeContent=SOME_BOOLEAN_VALUE' \ --header 'Accept: application/json' \ --header 'Authorization: d92d4xxxxxxxxxxxxx15f52' ``` ## Response Parameters ### HTTP Code 200 #### Response Body — application/json - `JSON Object` - **certificates** `JSON Object`: Container with managed and unmanaged certificate arrays ## Possible Response Codes - **200** — HTTP code ## Sample Response: HTTP 200 Managed and unmanaged certificates on the device ```json { "certificates": { "unmanagedcertificates": [ { "certificateissuername": "CN=ExternalCA, O=Company, OU=IT, ST=CA, C=US", "serialnumber": "5482640642439599254", "certificatename": "ExternalCA", "certificateexpiry": "4696305454000", "signaturealgorithmname": "SHA256withRSA", "isidentity": false, "signaturealgorithmoid": "1.2.840.113549.1.1.11", "certificatesubjectname": "CN=ExternalCA, O=Company, OU=IT, ST=CA, C=US" } ], "managedcertificates": [ { "certificateissuername": "CN=ZylkerCA, O=Zylker Inc, OU=Zylker IT, ST=CA, C=US", "serialnumber": "5482640642439599254", "certificatename": "ZylkerCA", "certificateexpiry": "4696305454000", "signaturealgorithmname": "SHA256withRSA", "isidentity": false, "signaturealgorithmoid": "1.2.840.113549.1.1.11", "certificatesubjectname": "CN=ZylkerCA, O=Zylker Inc, OU=Zylker IT, ST=CA, C=US" } ] } } ``` ## Rate Limit ![](https://www.zohowebstatic.com/sites/zweb/images/people/ico-help.png) **Duration:** 1 minute | **Threshold:** 250 | **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.