---
title: Upload mTLS certificate
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/go)

[MTLS Certificates](https://developers.cloudflare.com/api/go/resources/mtls_certificates)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Upload mTLS certificate

client.MTLSCertificates.New(ctx, params) (\*[MTLSCertificateNewResponse](<https://developers.cloudflare.com/api/go/resources/mtls_certificates#(resource)%20mtls_certificates%20%3E%20(model)%20MTLSCertificateNewResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/mtls\_certificates

Upload a certificate that you want to use with mTLS-enabled Cloudflare services, such as Bring Your Own CA (BYO-CA) for mTLS. To create certificates issued by the Cloudflare managed CA, use the [Create Client Certificate endpoint](https://developers.cloudflare.com/api/resources/client_certificates/methods/create/).

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### Accepted Permissions (at least one required)

`Account: SSL and Certificates Write`

##### ParametersExpand Collapse

<details>

<summary>

params MTLSCertificateNewParams

</summary>

AccountID param.Field\[string]

Path param: Identifier.

maxLength32

<a href="#(resource)%20mtls_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20account_id">Link to this property</a>

CA param.Field\[bool]

Body param: Indicates whether the certificate is a CA or leaf certificate.

<a href="#(resource)%20mtls_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20ca">Link to this property</a>

Certificates param.Field\[string]

Body param: The uploaded root CA certificate.

<a href="#(resource)%20mtls_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20certificates">Link to this property</a>

Name param.Field\[string]Optional

Body param: Optional unique name for the certificate. Only used for human readability.

<a href="#(resource)%20mtls_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20name">Link to this property</a>

PrivateKey param.Field\[string]Optional

Body param: The private key for the certificate. This field is only needed for specific use cases such as using a custom certificate with Zero Trust’s block page.

<a href="#(resource)%20mtls_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20private_key">Link to this property</a>

</details>

[Link to this property](<#(resource)%20mtls_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default>)

##### ReturnsExpand Collapse

<details>

<summary>

type MTLSCertificateNewResponse struct{…}

</summary>

ID stringOptional

Certificate identifier tag.

maxLength36

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20MTLSCertificateNewResponse%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

CA boolOptional

Indicates whether the certificate is a CA or leaf certificate.

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20MTLSCertificateNewResponse%20%3E%20(schema)%20%3E%20(property)%20ca">Link to this property</a>

Certificates stringOptional

The uploaded root CA certificate.

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20MTLSCertificateNewResponse%20%3E%20(schema)%20%3E%20(property)%20certificates">Link to this property</a>

ExpiresOn TimeOptional

When the certificate expires.

formatdate-time

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20MTLSCertificateNewResponse%20%3E%20(schema)%20%3E%20(property)%20expires_on">Link to this property</a>

Issuer stringOptional

The certificate authority that issued the certificate.

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20MTLSCertificateNewResponse%20%3E%20(schema)%20%3E%20(property)%20issuer">Link to this property</a>

Name stringOptional

Optional unique name for the certificate. Only used for human readability.

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20MTLSCertificateNewResponse%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

SerialNumber stringOptional

The certificate serial number.

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20MTLSCertificateNewResponse%20%3E%20(schema)%20%3E%20(property)%20serial_number">Link to this property</a>

Signature stringOptional

The type of hash used for the certificate.

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20MTLSCertificateNewResponse%20%3E%20(schema)%20%3E%20(property)%20signature">Link to this property</a>

<details>

<summary>

Type MTLSCertificateNewResponseTypeOptional

The type of the certificate, indicating how it was created and who manages it.

</summary>

One of the following:

const MTLSCertificateNewResponseTypeCustom MTLSCertificateNewResponseType = "custom"

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20MTLSCertificateNewResponse%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

const MTLSCertificateNewResponseTypeGatewayManaged MTLSCertificateNewResponseType = "gateway\_managed"

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20MTLSCertificateNewResponse%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

const MTLSCertificateNewResponseTypeAccessManaged MTLSCertificateNewResponseType = "access\_managed"

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20MTLSCertificateNewResponse%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20MTLSCertificateNewResponse%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

UpdatedAt TimeOptional

This is the time the certificate was updated.

formatdate-time

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20MTLSCertificateNewResponse%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

UploadedOn TimeOptional

This is the time the certificate was uploaded.

formatdate-time

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20MTLSCertificateNewResponse%20%3E%20(schema)%20%3E%20(property)%20uploaded_on">Link to this property</a>

</details>

[Link to this property](<#(resource)%20mtls_certificates%20%3E%20(model)%20MTLSCertificateNewResponse%20%3E%20(schema)>)

### Upload mTLS certificate

Go

HTTPTypeScriptPythonGoTerraform

```
package main

import (
  "context"
  "fmt"

  "github.com/cloudflare/cloudflare-go"
  "github.com/cloudflare/cloudflare-go/mtls_certificates"
  "github.com/cloudflare/cloudflare-go/option"
)

func main() {
  client := cloudflare.NewClient(
    option.WithAPIToken("Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY"),
  )
  mtlsCertificate, err := client.MTLSCertificates.New(context.TODO(), mtls_certificates.MTLSCertificateNewParams{
    AccountID: cloudflare.F("023e105f4ecef8ad9ca31a8372d0c353"),
    CA: cloudflare.F(true),
    Certificates: cloudflare.F("-----BEGIN CERTIFICATE-----\nMIIDmDCCAoCgAwIBAgIUKTOAZNjcXVZRj4oQt0SHsl1c1vMwDQYJKoZIhvcNAQEL\nBQAwUTELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDVNhbiBGcmFuY2lzY28xEzARBgNV\nBAcMCkNhbGlmb3JuaWExFTATBgNVBAoMDEV4YW1wbGUgSW5jLjAgFw0yMjExMjIx\nNjU5NDdaGA8yMTIyMTAyOTE2NTk0N1owUTELMAkGA1UEBhMCVVMxFjAUBgNVBAgM\nDVNhbiBGcmFuY2lzY28xEzARBgNVBAcMCkNhbGlmb3JuaWExFTATBgNVBAoMDEV4\nYW1wbGUgSW5jLjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMRcORwg\nJFTdcG/2GKI+cFYiOBNDKjCZUXEOvXWY42BkH9wxiMT869CO+enA1w5pIrXow6kC\nM1sQspHHaVmJUlotEMJxyoLFfA/8Kt1EKFyobOjuZs2SwyVyJ2sStvQuUQEosULZ\nCNGZEqoH5g6zhMPxaxm7ZLrrsDZ9maNGVqo7EWLWHrZ57Q/5MtTrbxQL+eXjUmJ9\nK3kS+3uEwMdqR6Z3BluU1ivanpPc1CN2GNhdO0/hSY4YkGEnuLsqJyDd3cIiB1Mx\nuCBJ4ZaqOd2viV1WcP3oU3dxVPm4MWyfYIldMWB14FahScxLhWdRnM9YZ/i9IFcL\nypXsuz7DjrJPtPUCAwEAAaNmMGQwHQYDVR0OBBYEFP5JzLUawNF+c3AXsYTEWHh7\nz2czMB8GA1UdIwQYMBaAFP5JzLUawNF+c3AXsYTEWHh7z2czMA4GA1UdDwEB/wQE\nAwIBBjASBgNVHRMBAf8ECDAGAQH/AgEBMA0GCSqGSIb3DQEBCwUAA4IBAQBc+Be7\nNDhpE09y7hLPZGRPl1cSKBw4RI0XIv6rlbSTFs5EebpTGjhx/whNxwEZhB9HZ711\n1Oa1YlT8xkI9DshB78mjAHCKBAJ76moK8tkG0aqdYpJ4ZcJTVBB7l98Rvgc7zfTi\ni7WemTy72deBbSeiEtXavm4EF0mWjHhQ5Nxpnp00Bqn5g1x8CyTDypgmugnep+xG\n+iFzNmTdsz7WI9T/7kDMXqB7M/FPWBORyS98OJqNDswCLF8bIZYwUBEe+bRHFomo\nShMzaC3tvim7WCb16noDkSTMlfKO4pnvKhpcVdSgwcruATV7y+W+Lvmz2OT/Gui4\nJhqeoTewsxndhDDE\n-----END CERTIFICATE-----"),
  })
  if err != nil {
    panic(err.Error())
  }
  fmt.Printf("%+v\n", mtlsCertificate.ID)
}
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "id": "2458ce5a-0c35-4c7f-82c7-8e9487d3ff60",
    "ca": true,
    "certificates": "-----BEGIN CERTIFICATE-----\nMIIDmDCCAoCgAwIBAgIUKTOAZNjcXVZRj4oQt0SHsl1c1vMwDQYJKoZIhvcNAQEL\nBQAwUTELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDVNhbiBGcmFuY2lzY28xEzARBgNV\nBAcMCkNhbGlmb3JuaWExFTATBgNVBAoMDEV4YW1wbGUgSW5jLjAgFw0yMjExMjIx\nNjU5NDdaGA8yMTIyMTAyOTE2NTk0N1owUTELMAkGA1UEBhMCVVMxFjAUBgNVBAgM\nDVNhbiBGcmFuY2lzY28xEzARBgNVBAcMCkNhbGlmb3JuaWExFTATBgNVBAoMDEV4\nYW1wbGUgSW5jLjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMRcORwg\nJFTdcG/2GKI+cFYiOBNDKjCZUXEOvXWY42BkH9wxiMT869CO+enA1w5pIrXow6kC\nM1sQspHHaVmJUlotEMJxyoLFfA/8Kt1EKFyobOjuZs2SwyVyJ2sStvQuUQEosULZ\nCNGZEqoH5g6zhMPxaxm7ZLrrsDZ9maNGVqo7EWLWHrZ57Q/5MtTrbxQL+eXjUmJ9\nK3kS+3uEwMdqR6Z3BluU1ivanpPc1CN2GNhdO0/hSY4YkGEnuLsqJyDd3cIiB1Mx\nuCBJ4ZaqOd2viV1WcP3oU3dxVPm4MWyfYIldMWB14FahScxLhWdRnM9YZ/i9IFcL\nypXsuz7DjrJPtPUCAwEAAaNmMGQwHQYDVR0OBBYEFP5JzLUawNF+c3AXsYTEWHh7\nz2czMB8GA1UdIwQYMBaAFP5JzLUawNF+c3AXsYTEWHh7z2czMA4GA1UdDwEB/wQE\nAwIBBjASBgNVHRMBAf8ECDAGAQH/AgEBMA0GCSqGSIb3DQEBCwUAA4IBAQBc+Be7\nNDhpE09y7hLPZGRPl1cSKBw4RI0XIv6rlbSTFs5EebpTGjhx/whNxwEZhB9HZ711\n1Oa1YlT8xkI9DshB78mjAHCKBAJ76moK8tkG0aqdYpJ4ZcJTVBB7l98Rvgc7zfTi\ni7WemTy72deBbSeiEtXavm4EF0mWjHhQ5Nxpnp00Bqn5g1x8CyTDypgmugnep+xG\n+iFzNmTdsz7WI9T/7kDMXqB7M/FPWBORyS98OJqNDswCLF8bIZYwUBEe+bRHFomo\nShMzaC3tvim7WCb16noDkSTMlfKO4pnvKhpcVdSgwcruATV7y+W+Lvmz2OT/Gui4\nJhqeoTewsxndhDDE\n-----END CERTIFICATE-----",
    "expires_on": "2122-10-29T16:59:47Z",
    "issuer": "O=Example Inc.,L=California,ST=San Francisco,C=US",
    "name": "example_ca_cert",
    "serial_number": "235217144297995885180570755458463043449861756659",
    "signature": "SHA256WithRSA",
    "type": "custom",
    "updated_at": "2022-11-22T17:32:30.467938Z",
    "uploaded_on": "2022-11-22T17:32:30.467938Z"
  }
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "id": "2458ce5a-0c35-4c7f-82c7-8e9487d3ff60",
    "ca": true,
    "certificates": "-----BEGIN CERTIFICATE-----\nMIIDmDCCAoCgAwIBAgIUKTOAZNjcXVZRj4oQt0SHsl1c1vMwDQYJKoZIhvcNAQEL\nBQAwUTELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDVNhbiBGcmFuY2lzY28xEzARBgNV\nBAcMCkNhbGlmb3JuaWExFTATBgNVBAoMDEV4YW1wbGUgSW5jLjAgFw0yMjExMjIx\nNjU5NDdaGA8yMTIyMTAyOTE2NTk0N1owUTELMAkGA1UEBhMCVVMxFjAUBgNVBAgM\nDVNhbiBGcmFuY2lzY28xEzARBgNVBAcMCkNhbGlmb3JuaWExFTATBgNVBAoMDEV4\nYW1wbGUgSW5jLjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMRcORwg\nJFTdcG/2GKI+cFYiOBNDKjCZUXEOvXWY42BkH9wxiMT869CO+enA1w5pIrXow6kC\nM1sQspHHaVmJUlotEMJxyoLFfA/8Kt1EKFyobOjuZs2SwyVyJ2sStvQuUQEosULZ\nCNGZEqoH5g6zhMPxaxm7ZLrrsDZ9maNGVqo7EWLWHrZ57Q/5MtTrbxQL+eXjUmJ9\nK3kS+3uEwMdqR6Z3BluU1ivanpPc1CN2GNhdO0/hSY4YkGEnuLsqJyDd3cIiB1Mx\nuCBJ4ZaqOd2viV1WcP3oU3dxVPm4MWyfYIldMWB14FahScxLhWdRnM9YZ/i9IFcL\nypXsuz7DjrJPtPUCAwEAAaNmMGQwHQYDVR0OBBYEFP5JzLUawNF+c3AXsYTEWHh7\nz2czMB8GA1UdIwQYMBaAFP5JzLUawNF+c3AXsYTEWHh7z2czMA4GA1UdDwEB/wQE\nAwIBBjASBgNVHRMBAf8ECDAGAQH/AgEBMA0GCSqGSIb3DQEBCwUAA4IBAQBc+Be7\nNDhpE09y7hLPZGRPl1cSKBw4RI0XIv6rlbSTFs5EebpTGjhx/whNxwEZhB9HZ711\n1Oa1YlT8xkI9DshB78mjAHCKBAJ76moK8tkG0aqdYpJ4ZcJTVBB7l98Rvgc7zfTi\ni7WemTy72deBbSeiEtXavm4EF0mWjHhQ5Nxpnp00Bqn5g1x8CyTDypgmugnep+xG\n+iFzNmTdsz7WI9T/7kDMXqB7M/FPWBORyS98OJqNDswCLF8bIZYwUBEe+bRHFomo\nShMzaC3tvim7WCb16noDkSTMlfKO4pnvKhpcVdSgwcruATV7y+W+Lvmz2OT/Gui4\nJhqeoTewsxndhDDE\n-----END CERTIFICATE-----",
    "expires_on": "2122-10-29T16:59:47Z",
    "issuer": "O=Example Inc.,L=California,ST=San Francisco,C=US",
    "name": "example_ca_cert",
    "serial_number": "235217144297995885180570755458463043449861756659",
    "signature": "SHA256WithRSA",
    "type": "custom",
    "updated_at": "2022-11-22T17:32:30.467938Z",
    "uploaded_on": "2022-11-22T17:32:30.467938Z"
  }
}
```