---
title: Client Certificates
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/terraform)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Client Certificates

#### resource cloudflare\_client\_certificate

##### required Expand Collapse

zone\_id: String

Identifier.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20zone_id>)

csr: String

The Certificate Signing Request (CSR). Must be newline-encoded.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20csr>)

validity\_days: Int64

The number of days the Client Certificate will be valid after the issued\_on date.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20validity_days>)

##### optional Expand Collapse

reactivate?: Bool

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20reactivate>)

##### computed Expand Collapse

id: String

Client Certificate Tag

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

certificate: String

The Client Certificate PEM.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20certificate>)

common\_name: String

Common Name of the Client Certificate.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20common_name>)

country: String

Country, provided by the CSR.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20country>)

expires\_on: String

Date that the Client Certificate expires.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20expires_on>)

fingerprint\_sha256: String

Unique identifier of the Client Certificate.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20fingerprint_sha256>)

issued\_on: String

Date that the Client Certificate was issued by the Certificate Authority.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20issued_on>)

location: String

Location, provided by the CSR.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20location>)

organization: String

Organization, provided by the CSR.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20organization>)

organizational\_unit: String

Organizational Unit, provided by the CSR.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20organizational_unit>)

serial\_number: String

The serial number on the created Client Certificate.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20serial_number>)

signature: String

The type of hash used for the Client Certificate..

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20signature>)

ski: String

Subject Key Identifier.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20ski>)

state: String

State, provided by the CSR.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20state>)

status: String

Client Certificates may be active or revoked, and the pending\_reactivation or pending\_revocation represent in-progress asynchronous transitions.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20status>)

<details>

<summary>

certificate\_authority: Attributes

Certificate Authority used to issue the Client Certificate.

</summary>

id: String

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20certificate_authority%20%3E%20(attribute)%20id">Link to this property</a>

name: String

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20certificate_authority%20%3E%20(attribute)%20name">Link to this property</a>

</details>

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20certificate_authority>)

### cloudflare\_client\_certificate

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_client_certificate" "example_client_certificate" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
  csr = <<EOT
  -----BEGIN CERTIFICATE REQUEST-----
  MIICY....
  -----END CERTIFICATE REQUEST-----
  EOT
  validity_days = 3650
}
```

#### data cloudflare\_client\_certificate

##### required Expand Collapse

zone\_id: String

Identifier.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20zone_id>)

##### optional Expand Collapse

client\_certificate\_id?: String

Client Certificate Tag

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20client_certificate_id>)

<details>

<summary>

filter?: Attributes

</summary>

limit?: Int64

Limit to the number of records returned.

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20limit">Link to this property</a>

offset?: Int64

Offset the results.

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20offset">Link to this property</a>

status?: String

Client Certitifcate Status to filter results by.

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20status">Link to this property</a>

</details>

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter>)

##### computed Expand Collapse

id: String

Client Certificate Tag

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

certificate: String

The Client Certificate PEM.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificate>)

common\_name: String

Common Name of the Client Certificate.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20common_name>)

country: String

Country, provided by the CSR.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20country>)

csr: String

The Certificate Signing Request (CSR). Must be newline-encoded.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20csr>)

expires\_on: String

Date that the Client Certificate expires.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20expires_on>)

fingerprint\_sha256: String

Unique identifier of the Client Certificate.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20fingerprint_sha256>)

issued\_on: String

Date that the Client Certificate was issued by the Certificate Authority.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20issued_on>)

location: String

Location, provided by the CSR.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20location>)

organization: String

Organization, provided by the CSR.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20organization>)

organizational\_unit: String

Organizational Unit, provided by the CSR.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20organizational_unit>)

serial\_number: String

The serial number on the created Client Certificate.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20serial_number>)

signature: String

The type of hash used for the Client Certificate..

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20signature>)

ski: String

Subject Key Identifier.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20ski>)

state: String

State, provided by the CSR.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20state>)

status: String

Client Certificates may be active or revoked, and the pending\_reactivation or pending\_revocation represent in-progress asynchronous transitions.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20status>)

validity\_days: Int64

The number of days the Client Certificate will be valid after the issued\_on date.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20validity_days>)

<details>

<summary>

certificate\_authority: Attributes

Certificate Authority used to issue the Client Certificate.

</summary>

id: String

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificate_authority%20%3E%20(attribute)%20id">Link to this property</a>

name: String

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificate_authority%20%3E%20(attribute)%20name">Link to this property</a>

</details>

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificate_authority>)

### cloudflare\_client\_certificate

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_client_certificate" "example_client_certificate" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
  client_certificate_id = "0d89c70d-ad9f-4843-b99f-6cc0252067e9"
}
```

#### data cloudflare\_client\_certificates

##### required Expand Collapse

zone\_id: String

Identifier.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20zone_id>)

##### optional Expand Collapse

limit?: Int64

Limit to the number of records returned.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20limit>)

offset?: Int64

Offset the results.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20offset>)

status?: String

Client Certitifcate Status to filter results by.

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20status>)

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

Client Certificate Tag

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

certificate: String

The Client Certificate PEM.

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20certificate">Link to this property</a>

<details>

<summary>

certificate\_authority: Attributes

Certificate Authority used to issue the Client Certificate.

</summary>

id: String

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20certificate_authority%20%3E%20(attribute)%20id">Link to this property</a>

name: String

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20certificate_authority%20%3E%20(attribute)%20name">Link to this property</a>

</details>

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20certificate_authority">Link to this property</a>

common\_name: String

Common Name of the Client Certificate.

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20common_name">Link to this property</a>

country: String

Country, provided by the CSR.

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20country">Link to this property</a>

csr: String

The Certificate Signing Request (CSR). Must be newline-encoded.

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20csr">Link to this property</a>

expires\_on: String

Date that the Client Certificate expires.

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20expires_on">Link to this property</a>

fingerprint\_sha256: String

Unique identifier of the Client Certificate.

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20fingerprint_sha256">Link to this property</a>

issued\_on: String

Date that the Client Certificate was issued by the Certificate Authority.

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20issued_on">Link to this property</a>

location: String

Location, provided by the CSR.

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20location">Link to this property</a>

organization: String

Organization, provided by the CSR.

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20organization">Link to this property</a>

organizational\_unit: String

Organizational Unit, provided by the CSR.

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20organizational_unit">Link to this property</a>

serial\_number: String

The serial number on the created Client Certificate.

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20serial_number">Link to this property</a>

signature: String

The type of hash used for the Client Certificate..

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20signature">Link to this property</a>

ski: String

Subject Key Identifier.

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20ski">Link to this property</a>

state: String

State, provided by the CSR.

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20state">Link to this property</a>

status: String

Client Certificates may be active or revoked, and the pending\_reactivation or pending\_revocation represent in-progress asynchronous transitions.

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20status">Link to this property</a>

validity\_days: Int64

The number of days the Client Certificate will be valid after the issued\_on date.

<a href="#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20validity_days">Link to this property</a>

</details>

[Link to this property](<#(resource)%20client_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_client\_certificates

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_client_certificates" "example_client_certificates" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
  limit = 10
  offset = 10
  status = "all"
}
```