---
title: Upload mTLS certificate
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/python)

[MTLS Certificates](https://developers.cloudflare.com/api/python/resources/mtls_certificates)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Upload mTLS certificate

mtls\_certificates.create(MTLSCertificateCreateParams\*\*kwargs) -> [MTLSCertificateCreateResponse](<https://developers.cloudflare.com/api/python/resources/mtls_certificates#(resource)%20mtls_certificates%20%3E%20(model)%20mtls_certificate_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/mtls\_certificates

Upload a certificate that you want to use with mTLS-enabled Cloudflare services, such as Bring Your Own CA (BYO-CA) for mTLS. To create certificates issued by the Cloudflare managed CA, use the [Create Client Certificate endpoint](https://developers.cloudflare.com/api/resources/client_certificates/methods/create/).

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### Accepted Permissions (at least one required)

`Account: SSL and Certificates Write`

##### ParametersExpand Collapse

account\_id: str

Identifier.

maxLength32

[Link to this property](<#(resource)%20mtls_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20account_id%20%3E%20(schema)>)

ca: [bool](<https://developers.cloudflare.com/api/python/resources/mtls_certificates/methods/create#(resource)%20mtls_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20ca%20%3E%20(schema)>)

Indicates whether the certificate is a CA or leaf certificate.

[Link to this property](<#(resource)%20mtls_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20ca%20%3E%20(schema)>)

certificates: str

The uploaded root CA certificate.

[Link to this property](<#(resource)%20mtls_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20certificates%20%3E%20(schema)>)

name: Optional\[str]

Optional unique name for the certificate. Only used for human readability.

[Link to this property](<#(resource)%20mtls_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20name%20%3E%20(schema)>)

private\_key: Optional\[str]

The private key for the certificate. This field is only needed for specific use cases such as using a custom certificate with Zero Trust’s block page.

[Link to this property](<#(resource)%20mtls_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20private_key%20%3E%20(schema)>)

##### ReturnsExpand Collapse

<details>

<summary>

class MTLSCertificateCreateResponse: …

</summary>

id: Optional\[str]

Certificate identifier tag.

maxLength36

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20mtls_certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

ca: Optional\[bool]

Indicates whether the certificate is a CA or leaf certificate.

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20mtls_certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20ca">Link to this property</a>

certificates: Optional\[str]

The uploaded root CA certificate.

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20mtls_certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20certificates">Link to this property</a>

expires\_on: Optional\[datetime]

When the certificate expires.

formatdate-time

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20mtls_certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20expires_on">Link to this property</a>

issuer: Optional\[str]

The certificate authority that issued the certificate.

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20mtls_certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20issuer">Link to this property</a>

name: Optional\[str]

Optional unique name for the certificate. Only used for human readability.

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20mtls_certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

serial\_number: Optional\[str]

The certificate serial number.

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20mtls_certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20serial_number">Link to this property</a>

signature: Optional\[str]

The type of hash used for the certificate.

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20mtls_certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20signature">Link to this property</a>

<details>

<summary>

type: Optional\[Literal\["custom", "gateway\_managed", "access\_managed"]]

The type of the certificate, indicating how it was created and who manages it.

</summary>

One of the following:

"custom"

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20mtls_certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

"gateway\_managed"

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20mtls_certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

"access\_managed"

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20mtls_certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20mtls_certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

updated\_at: Optional\[datetime]

This is the time the certificate was updated.

formatdate-time

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20mtls_certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

uploaded\_on: Optional\[datetime]

This is the time the certificate was uploaded.

formatdate-time

<a href="#(resource)%20mtls_certificates%20%3E%20(model)%20mtls_certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20uploaded_on">Link to this property</a>

</details>

[Link to this property](<#(resource)%20mtls_certificates%20%3E%20(model)%20mtls_certificate_create_response%20%3E%20(schema)>)

### Upload mTLS certificate

Python

HTTPTypeScriptPythonGoTerraform

```
import os
from cloudflare import Cloudflare

client = Cloudflare(
    api_token=os.environ.get("CLOUDFLARE_API_TOKEN"),  # This is the default and can be omitted
)
mtls_certificate = client.mtls_certificates.create(
    account_id="023e105f4ecef8ad9ca31a8372d0c353",
    ca=True,
    certificates="-----BEGIN CERTIFICATE-----\nMIIDmDCCAoCgAwIBAgIUKTOAZNjcXVZRj4oQt0SHsl1c1vMwDQYJKoZIhvcNAQEL\nBQAwUTELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDVNhbiBGcmFuY2lzY28xEzARBgNV\nBAcMCkNhbGlmb3JuaWExFTATBgNVBAoMDEV4YW1wbGUgSW5jLjAgFw0yMjExMjIx\nNjU5NDdaGA8yMTIyMTAyOTE2NTk0N1owUTELMAkGA1UEBhMCVVMxFjAUBgNVBAgM\nDVNhbiBGcmFuY2lzY28xEzARBgNVBAcMCkNhbGlmb3JuaWExFTATBgNVBAoMDEV4\nYW1wbGUgSW5jLjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMRcORwg\nJFTdcG/2GKI+cFYiOBNDKjCZUXEOvXWY42BkH9wxiMT869CO+enA1w5pIrXow6kC\nM1sQspHHaVmJUlotEMJxyoLFfA/8Kt1EKFyobOjuZs2SwyVyJ2sStvQuUQEosULZ\nCNGZEqoH5g6zhMPxaxm7ZLrrsDZ9maNGVqo7EWLWHrZ57Q/5MtTrbxQL+eXjUmJ9\nK3kS+3uEwMdqR6Z3BluU1ivanpPc1CN2GNhdO0/hSY4YkGEnuLsqJyDd3cIiB1Mx\nuCBJ4ZaqOd2viV1WcP3oU3dxVPm4MWyfYIldMWB14FahScxLhWdRnM9YZ/i9IFcL\nypXsuz7DjrJPtPUCAwEAAaNmMGQwHQYDVR0OBBYEFP5JzLUawNF+c3AXsYTEWHh7\nz2czMB8GA1UdIwQYMBaAFP5JzLUawNF+c3AXsYTEWHh7z2czMA4GA1UdDwEB/wQE\nAwIBBjASBgNVHRMBAf8ECDAGAQH/AgEBMA0GCSqGSIb3DQEBCwUAA4IBAQBc+Be7\nNDhpE09y7hLPZGRPl1cSKBw4RI0XIv6rlbSTFs5EebpTGjhx/whNxwEZhB9HZ711\n1Oa1YlT8xkI9DshB78mjAHCKBAJ76moK8tkG0aqdYpJ4ZcJTVBB7l98Rvgc7zfTi\ni7WemTy72deBbSeiEtXavm4EF0mWjHhQ5Nxpnp00Bqn5g1x8CyTDypgmugnep+xG\n+iFzNmTdsz7WI9T/7kDMXqB7M/FPWBORyS98OJqNDswCLF8bIZYwUBEe+bRHFomo\nShMzaC3tvim7WCb16noDkSTMlfKO4pnvKhpcVdSgwcruATV7y+W+Lvmz2OT/Gui4\nJhqeoTewsxndhDDE\n-----END CERTIFICATE-----",
)
print(mtls_certificate.id)
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "id": "2458ce5a-0c35-4c7f-82c7-8e9487d3ff60",
    "ca": true,
    "certificates": "-----BEGIN CERTIFICATE-----\nMIIDmDCCAoCgAwIBAgIUKTOAZNjcXVZRj4oQt0SHsl1c1vMwDQYJKoZIhvcNAQEL\nBQAwUTELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDVNhbiBGcmFuY2lzY28xEzARBgNV\nBAcMCkNhbGlmb3JuaWExFTATBgNVBAoMDEV4YW1wbGUgSW5jLjAgFw0yMjExMjIx\nNjU5NDdaGA8yMTIyMTAyOTE2NTk0N1owUTELMAkGA1UEBhMCVVMxFjAUBgNVBAgM\nDVNhbiBGcmFuY2lzY28xEzARBgNVBAcMCkNhbGlmb3JuaWExFTATBgNVBAoMDEV4\nYW1wbGUgSW5jLjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMRcORwg\nJFTdcG/2GKI+cFYiOBNDKjCZUXEOvXWY42BkH9wxiMT869CO+enA1w5pIrXow6kC\nM1sQspHHaVmJUlotEMJxyoLFfA/8Kt1EKFyobOjuZs2SwyVyJ2sStvQuUQEosULZ\nCNGZEqoH5g6zhMPxaxm7ZLrrsDZ9maNGVqo7EWLWHrZ57Q/5MtTrbxQL+eXjUmJ9\nK3kS+3uEwMdqR6Z3BluU1ivanpPc1CN2GNhdO0/hSY4YkGEnuLsqJyDd3cIiB1Mx\nuCBJ4ZaqOd2viV1WcP3oU3dxVPm4MWyfYIldMWB14FahScxLhWdRnM9YZ/i9IFcL\nypXsuz7DjrJPtPUCAwEAAaNmMGQwHQYDVR0OBBYEFP5JzLUawNF+c3AXsYTEWHh7\nz2czMB8GA1UdIwQYMBaAFP5JzLUawNF+c3AXsYTEWHh7z2czMA4GA1UdDwEB/wQE\nAwIBBjASBgNVHRMBAf8ECDAGAQH/AgEBMA0GCSqGSIb3DQEBCwUAA4IBAQBc+Be7\nNDhpE09y7hLPZGRPl1cSKBw4RI0XIv6rlbSTFs5EebpTGjhx/whNxwEZhB9HZ711\n1Oa1YlT8xkI9DshB78mjAHCKBAJ76moK8tkG0aqdYpJ4ZcJTVBB7l98Rvgc7zfTi\ni7WemTy72deBbSeiEtXavm4EF0mWjHhQ5Nxpnp00Bqn5g1x8CyTDypgmugnep+xG\n+iFzNmTdsz7WI9T/7kDMXqB7M/FPWBORyS98OJqNDswCLF8bIZYwUBEe+bRHFomo\nShMzaC3tvim7WCb16noDkSTMlfKO4pnvKhpcVdSgwcruATV7y+W+Lvmz2OT/Gui4\nJhqeoTewsxndhDDE\n-----END CERTIFICATE-----",
    "expires_on": "2122-10-29T16:59:47Z",
    "issuer": "O=Example Inc.,L=California,ST=San Francisco,C=US",
    "name": "example_ca_cert",
    "serial_number": "235217144297995885180570755458463043449861756659",
    "signature": "SHA256WithRSA",
    "type": "custom",
    "updated_at": "2022-11-22T17:32:30.467938Z",
    "uploaded_on": "2022-11-22T17:32:30.467938Z"
  }
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "id": "2458ce5a-0c35-4c7f-82c7-8e9487d3ff60",
    "ca": true,
    "certificates": "-----BEGIN CERTIFICATE-----\nMIIDmDCCAoCgAwIBAgIUKTOAZNjcXVZRj4oQt0SHsl1c1vMwDQYJKoZIhvcNAQEL\nBQAwUTELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDVNhbiBGcmFuY2lzY28xEzARBgNV\nBAcMCkNhbGlmb3JuaWExFTATBgNVBAoMDEV4YW1wbGUgSW5jLjAgFw0yMjExMjIx\nNjU5NDdaGA8yMTIyMTAyOTE2NTk0N1owUTELMAkGA1UEBhMCVVMxFjAUBgNVBAgM\nDVNhbiBGcmFuY2lzY28xEzARBgNVBAcMCkNhbGlmb3JuaWExFTATBgNVBAoMDEV4\nYW1wbGUgSW5jLjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMRcORwg\nJFTdcG/2GKI+cFYiOBNDKjCZUXEOvXWY42BkH9wxiMT869CO+enA1w5pIrXow6kC\nM1sQspHHaVmJUlotEMJxyoLFfA/8Kt1EKFyobOjuZs2SwyVyJ2sStvQuUQEosULZ\nCNGZEqoH5g6zhMPxaxm7ZLrrsDZ9maNGVqo7EWLWHrZ57Q/5MtTrbxQL+eXjUmJ9\nK3kS+3uEwMdqR6Z3BluU1ivanpPc1CN2GNhdO0/hSY4YkGEnuLsqJyDd3cIiB1Mx\nuCBJ4ZaqOd2viV1WcP3oU3dxVPm4MWyfYIldMWB14FahScxLhWdRnM9YZ/i9IFcL\nypXsuz7DjrJPtPUCAwEAAaNmMGQwHQYDVR0OBBYEFP5JzLUawNF+c3AXsYTEWHh7\nz2czMB8GA1UdIwQYMBaAFP5JzLUawNF+c3AXsYTEWHh7z2czMA4GA1UdDwEB/wQE\nAwIBBjASBgNVHRMBAf8ECDAGAQH/AgEBMA0GCSqGSIb3DQEBCwUAA4IBAQBc+Be7\nNDhpE09y7hLPZGRPl1cSKBw4RI0XIv6rlbSTFs5EebpTGjhx/whNxwEZhB9HZ711\n1Oa1YlT8xkI9DshB78mjAHCKBAJ76moK8tkG0aqdYpJ4ZcJTVBB7l98Rvgc7zfTi\ni7WemTy72deBbSeiEtXavm4EF0mWjHhQ5Nxpnp00Bqn5g1x8CyTDypgmugnep+xG\n+iFzNmTdsz7WI9T/7kDMXqB7M/FPWBORyS98OJqNDswCLF8bIZYwUBEe+bRHFomo\nShMzaC3tvim7WCb16noDkSTMlfKO4pnvKhpcVdSgwcruATV7y+W+Lvmz2OT/Gui4\nJhqeoTewsxndhDDE\n-----END CERTIFICATE-----",
    "expires_on": "2122-10-29T16:59:47Z",
    "issuer": "O=Example Inc.,L=California,ST=San Francisco,C=US",
    "name": "example_ca_cert",
    "serial_number": "235217144297995885180570755458463043449861756659",
    "signature": "SHA256WithRSA",
    "type": "custom",
    "updated_at": "2022-11-22T17:32:30.467938Z",
    "uploaded_on": "2022-11-22T17:32:30.467938Z"
  }
}
```