> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scanova.io/llms.txt
> Use this file to discover all available pages before exploring further.

# SSL-Zertifikat hochladen

> POST /custom-domain/{pk}/ssl-certificate/

Lädt ein ausgestelltes SSL-Zertifikat für eine Domain hoch und aktiviert es, auf dem **Management-API**-Host (`api.scanova.io`), authentifiziert mit Ihrem rohen Management-API-Schlüssel.

```
POST https://api.scanova.io/custom-domain/{pk}/ssl-certificate/
Authorization: 401f7ac837da42b97f613d789819ff93537bee6a
```

<Warning>
  Nur für Enterprise. Erfordert die Quota `CUSTOM_DOMAIN_CUSTOM_SSL`, die manuell vergeben wird — kein Self-Service-Plan enthält sie. Erfordert eine vorherige CSR — siehe [SSL-Zertifikatsanfrage erstellen](/de/api-reference/management-api/custom-domain/certificate-request-create).
</Warning>

<ParamField path="pk" type="integer" required>
  Die `id` der Domain.
</ParamField>

<ParamField body="certificate" type="string" required>
  Das ausgestellte Zertifikat, PEM-kodiert.
</ParamField>

<ParamField body="certificate_chain" type="string">
  Die Zwischenzertifikatskette der Zertifizierungsstelle, PEM-kodiert, falls Ihre CA eine separat bereitstellt.
</ParamField>

<RequestExample>
  ```bash cURL theme={null}
  curl -X POST "https://api.scanova.io/custom-domain/42/ssl-certificate/" \
    -H "Authorization: 401f7ac837da42b97f613d789819ff93537bee6a" \
    -H "Content-Type: application/json" \
    -d '{
      "certificate": "-----BEGIN CERTIFICATE-----\nMIID...\n-----END CERTIFICATE-----",
      "certificate_chain": "-----BEGIN CERTIFICATE-----\nMIID...\n-----END CERTIFICATE-----"
    }'
  ```
</RequestExample>

<ResponseExample>
  ```json 200 theme={null}
  {
    "detail": "Certificate activated.",
    "status": "ISSUED",
    "expires_at": "2026-12-08T00:00:00Z"
  }
  ```
</ResponseExample>

Scanova validiert das Zertifikat gegen die Domain und den Schlüssel der CSR, importiert es in AWS ACM und verknüpft es, um Live-Traffic zu bedienen — dies ist vollständig automatisiert, ohne manuellen Prüfschritt. Es sind drei Ergebnisse möglich:

* **`200`** — validiert, importiert und aktiviert. Der Traffic auf dieser Domain wird jetzt mit dem neuen Zertifikat bedient.
* **`202`** — in ACM importiert, aber noch nicht ausgestellt; noch nicht mit dem Traffic verknüpft. Schauen Sie in Kürze erneut nach.
* **`207` Multi-Status** — ausgestellt, aber die Verknüpfung mit dem Live-Traffic ist fehlgeschlagen; das Scanova-Support-Team wird automatisch benachrichtigt und wird sich melden.

`400`, wenn für diese Domain noch keine CSR existiert, das Zertifikat nicht zur Domain oder zum Schlüssel der CSR passt, oder AWS ACM den Import ablehnt (die Fehlermeldung ist in der Antwort enthalten).

## Verwandte Themen

* [SSL-Zertifikatsstatus abrufen](/de/api-reference/management-api/custom-domain/ssl-certificate-retrieve) — den Status nach dem Hochladen prüfen.
* [SSL-Zertifikatsanfrage erstellen](/de/api-reference/management-api/custom-domain/certificate-request-create) — die vor dem Hochladen erforderliche CSR.
* [Übersicht über die Management API](/de/api-reference/management-api/overview) — das Authentifizierungsschema und die Quota-Regeln für diesen Endpunkt.


## OpenAPI

````yaml api-reference/openapi/management-api.json POST /custom-domain/{pk}/ssl-certificate/
openapi: 3.1.0
info:
  title: Scanova Management API (v2)
  description: >-
    The complete Scanova Management API — every endpoint available at
    api.scanova.io (QR codes, folders, tags, leads, forms, analytics, plans,
    shared users & roles), plus the token-creation and usage-stats endpoints
    used to authenticate against it. Every path and request/response shape below
    was verified live against a real API key and the actual running backend
    (Phase 7, 2026-08-16) — not guessed from reading urls.py alone.
  version: 2.0.0
servers:
  - url: https://api.scanova.io
    description: Management API — QR/folder/tag/lead/form/analytics/plans endpoints
security:
  - apiKeyAuth: []
paths:
  /custom-domain/{pk}/ssl-certificate/:
    post:
      summary: Upload an SSL certificate
      description: >-
        Requires a prior CSR (see Create an SSL certificate request). Validates
        the certificate against the domain and the CSR's key, imports it into
        AWS ACM, and links it for serving traffic. A `202` means ACM accepted
        the import but hasn't finished issuing; a `207` means activation partly
        failed and support was notified automatically.
      operationId: uploadSslCertificate
      parameters:
        - name: pk
          in: path
          required: true
          schema:
            type: integer
      requestBody:
        content:
          application/json:
            example:
              certificate: '-----BEGIN CERTIFICATE-----\nMIID...\n-----END CERTIFICATE-----'
              certificate_chain: '-----BEGIN CERTIFICATE-----\nMIID...\n-----END CERTIFICATE-----'
      responses:
        '200':
          description: Certificate validated, imported, and activated for serving traffic.
          content:
            application/json:
              example:
                detail: Certificate activated.
                status: ISSUED
                expires_at: '2026-12-08T00:00:00Z'
        '202':
          description: >-
            Certificate imported into ACM but not yet issued; not linked to
            serve traffic yet.
          content:
            application/json:
              example:
                detail: Certificate imported but not yet issued. Check back shortly.
        '207':
          description: >-
            Certificate issued but linking it to serve traffic failed; support
            has been notified automatically.
          content:
            application/json:
              example:
                detail: >-
                  Certificate issued, but activation needs manual follow-up. Our
                  team has been notified.
        '400':
          description: >-
            No CSR exists for this domain yet, the certificate doesn't match the
            domain/CSR key, or AWS ACM rejected the import (error message
            included).
components:
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: Authorization
      description: >-
        Send your Management API key as the raw value of the Authorization
        header — no "Bearer " or "Token " prefix, and no other characters.
        Example: `Authorization: 401f7ac837da42b97f613d789819ff93537bee6a`. A
        header containing more than one space-separated part is rejected
        outright. Requests also require the request's Host header to be the
        management API host (e.g. api.scanova.io) — the same key sent to the
        regular API host will not authenticate.

````