Skip to main content
POST
key + certificate are validated (parseable, not expired) before the atomic swap; in-flight requests finish with the identity they started with. The cert-expiry monitor tracks the new certificate immediately.

Request body

RotateAs2IdentityBody
string
required
X.509 certificate PEM.
string
required
PKCS#8 private key PEM.

Response

No response body — identity rotated.

Status codes