---
title: Create Keyless SSL Configuration
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/typescript)

[Keyless Certificates](https://developers.cloudflare.com/api/typescript/resources/keyless_certificates)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Create Keyless SSL Configuration

client.keylessCertificates.create(KeylessCertificateCreateParams {zone\_id, certificate, host, 4 more } params, RequestOptionsoptions?): [KeylessCertificate](<https://developers.cloudflare.com/api/typescript/resources/keyless_certificates#(resource)%20keyless_certificates%20%3E%20(model)%20keyless_certificate%20%3E%20(schema)>) {id, created\_on, enabled, 7 more }

POST/zones/{zone\_id}/keyless\_certificates

Creates a Keyless SSL configuration that allows SSL/TLS termination without exposing private keys to Cloudflare. Keys remain on your infrastructure.

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### Accepted Permissions (at least one required)

`SSL and Certificates Write`

##### ParametersExpand Collapse

<details>

<summary>

params: KeylessCertificateCreateParams {zone\_id, certificate, host, 4 more }

</summary>

zone\_id: string

Path param: Identifier.

maxLength32

<a href="#(resource)%20keyless_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20zone_id">Link to this property</a>

certificate: string

Body param: The zone’s SSL certificate or SSL certificate and intermediate(s).

<a href="#(resource)%20keyless_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20certificate">Link to this property</a>

host: string

Body param: The keyless SSL name.

formathostname

maxLength253

<a href="#(resource)%20keyless_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20host">Link to this property</a>

port: number

Body param: The keyless SSL port used to communicate between Cloudflare and the client’s Keyless SSL server.

maxLength65535

<a href="#(resource)%20keyless_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20port">Link to this property</a>

<details>

<summary>

bundle\_method?: <a href="https://developers.cloudflare.com/api/typescript/resources/custom_hostnames#(resource)%20custom_hostnames%20%3E%20(model)%20bundle_method%20%3E%20(schema)">BundleMethod</a>

Body param: A ubiquitous bundle has the highest probability of being verified everywhere, even by clients using outdated or unusual trust stores. An optimal bundle uses the shortest chain and newest intermediates. And the force bundle verifies the chain, but does not otherwise modify it.

</summary>

One of the following:

"ubiquitous"

<a href="#(resource)%20keyless_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20bundle_method%20%2B%20(resource)%20custom_hostnames%20%3E%20(model)%20bundle_method%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"optimal"

<a href="#(resource)%20keyless_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20bundle_method%20%2B%20(resource)%20custom_hostnames%20%3E%20(model)%20bundle_method%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"force"

<a href="#(resource)%20keyless_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20bundle_method%20%2B%20(resource)%20custom_hostnames%20%3E%20(model)%20bundle_method%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20keyless_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20bundle_method">Link to this property</a>

name?: string

Body param: The keyless SSL name.

maxLength180

<a href="#(resource)%20keyless_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20name">Link to this property</a>

<details>

<summary>

tunnel?: <a href="https://developers.cloudflare.com/api/typescript/resources/keyless_certificates#(resource)%20keyless_certificates%20%3E%20(model)%20tunnel%20%3E%20(schema)">Tunnel</a> {private\_ip, vnet\_id }

Body param: Configuration for using Keyless SSL through a Cloudflare Tunnel.

</summary>

private\_ip: string

Private IP of the Key Server Host.

<a href="#(resource)%20keyless_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20tunnel%20%2B%20(resource)%20keyless_certificates%20%3E%20(model)%20tunnel%20%3E%20(schema)%20%3E%20(property)%20private_ip">Link to this property</a>

vnet\_id: string

Cloudflare Tunnel Virtual Network ID.

<a href="#(resource)%20keyless_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20tunnel%20%2B%20(resource)%20keyless_certificates%20%3E%20(model)%20tunnel%20%3E%20(schema)%20%3E%20(property)%20vnet_id">Link to this property</a>

</details>

<a href="#(resource)%20keyless_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20tunnel">Link to this property</a>

</details>

[Link to this property](<#(resource)%20keyless_certificates%20%3E%20(method)%20create%20%3E%20(params)%20default>)

##### ReturnsExpand Collapse

<details>

<summary>

KeylessCertificate {id, created\_on, enabled, 7 more }

</summary>

id: string

Keyless certificate identifier tag.

maxLength32

<a href="#(resource)%20keyless_certificates%20%3E%20(model)%20keyless_certificate%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_on: string

When the Keyless SSL was created.

formatdate-time

<a href="#(resource)%20keyless_certificates%20%3E%20(model)%20keyless_certificate%20%3E%20(schema)%20%3E%20(property)%20created_on">Link to this property</a>

enabled: boolean

Whether or not the Keyless SSL is on or off.

<a href="#(resource)%20keyless_certificates%20%3E%20(model)%20keyless_certificate%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

host: string

The keyless SSL name.

formathostname

maxLength253

<a href="#(resource)%20keyless_certificates%20%3E%20(model)%20keyless_certificate%20%3E%20(schema)%20%3E%20(property)%20host">Link to this property</a>

modified\_on: string

When the Keyless SSL was last modified.

formatdate-time

<a href="#(resource)%20keyless_certificates%20%3E%20(model)%20keyless_certificate%20%3E%20(schema)%20%3E%20(property)%20modified_on">Link to this property</a>

name: string

The keyless SSL name.

maxLength180

<a href="#(resource)%20keyless_certificates%20%3E%20(model)%20keyless_certificate%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

permissions: Array&lt;string&gt;

Available permissions for the Keyless SSL for the current user requesting the item.

<a href="#(resource)%20keyless_certificates%20%3E%20(model)%20keyless_certificate%20%3E%20(schema)%20%3E%20(property)%20permissions">Link to this property</a>

port: number

The keyless SSL port used to communicate between Cloudflare and the client’s Keyless SSL server.

maxLength65535

<a href="#(resource)%20keyless_certificates%20%3E%20(model)%20keyless_certificate%20%3E%20(schema)%20%3E%20(property)%20port">Link to this property</a>

<details>

<summary>

status: "active"| "deleted"

Status of the Keyless SSL.

</summary>

One of the following:

"active"

<a href="#(resource)%20keyless_certificates%20%3E%20(model)%20keyless_certificate%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"deleted"

<a href="#(resource)%20keyless_certificates%20%3E%20(model)%20keyless_certificate%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20keyless_certificates%20%3E%20(model)%20keyless_certificate%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

<details>

<summary>

tunnel?: <a href="https://developers.cloudflare.com/api/typescript/resources/keyless_certificates#(resource)%20keyless_certificates%20%3E%20(model)%20tunnel%20%3E%20(schema)">Tunnel</a> {private\_ip, vnet\_id }

Configuration for using Keyless SSL through a Cloudflare Tunnel.

</summary>

private\_ip: string

Private IP of the Key Server Host.

<a href="#(resource)%20keyless_certificates%20%3E%20(model)%20keyless_certificate%20%3E%20(schema)%20%3E%20(property)%20tunnel%20%2B%20(resource)%20keyless_certificates%20%3E%20(model)%20tunnel%20%3E%20(schema)%20%3E%20(property)%20private_ip">Link to this property</a>

vnet\_id: string

Cloudflare Tunnel Virtual Network ID.

<a href="#(resource)%20keyless_certificates%20%3E%20(model)%20keyless_certificate%20%3E%20(schema)%20%3E%20(property)%20tunnel%20%2B%20(resource)%20keyless_certificates%20%3E%20(model)%20tunnel%20%3E%20(schema)%20%3E%20(property)%20vnet_id">Link to this property</a>

</details>

<a href="#(resource)%20keyless_certificates%20%3E%20(model)%20keyless_certificate%20%3E%20(schema)%20%3E%20(property)%20tunnel">Link to this property</a>

</details>

[Link to this property](<#(resource)%20keyless_certificates%20%3E%20(model)%20keyless_certificate%20%3E%20(schema)>)

### Create Keyless SSL Configuration

TypeScript

HTTPTypeScriptPythonGoTerraform

```
import Cloudflare from 'cloudflare';

const client = new Cloudflare({
  apiToken: process.env['CLOUDFLARE_API_TOKEN'], // This is the default and can be omitted
});

const keylessCertificate = await client.keylessCertificates.create({
  zone_id: '023e105f4ecef8ad9ca31a8372d0c353',
  certificate:
    '-----BEGIN CERTIFICATE-----\nMIIDtTCCAp2gAwIBAgIJAM15n7fdxhRtMA0GCSqGSIb3DQEBBQUAMEUxCzAJBgNV\nBAYTAlVTMRMwEQYDVQQIEwpTb21lLVN0YXRlMSEwHwYDVQQKExhJbnRlcm5ldCBX\naWRnaXRzIFB0eSBMdGQwHhcNMTQwMzExMTkyMTU5WhcNMTQwNDEwMTkyMTU5WjBF\nMQswCQYDVQQGEwJVUzETMBEGA1UECBMKU29tZS1TdGF0ZTEhMB8GA1UEChMYSW50\nZXJuZXQgV2lkZ2l0cyBQdHkgTHRkMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB\nCgKCAQEAvq3sKsHpeduJHimOK+fvQdKsI8z8A05MZyyLp2/R/GE8FjNv+hkVY1WQ\nLIyTNNQH7CJecE1nbTfo8Y56S7x/rhxC6/DJ8MIulapFPnorq46KU6yRxiM0MQ3N\nnTJHlHA2ozZta6YBBfVfhHWl1F0IfNbXCLKvGwWWMbCx43OfW6KTkbRnE6gFWKuO\nfSO5h2u5TaWVuSIzBvYs7Vza6m+gtYAvKAJV2nSZ+eSEFPDo29corOy8+huEOUL8\n5FAw4BFPsr1TlrlGPFitduQUHGrSL7skk1ESGza0to3bOtrodKei2s9bk5MXm7lZ\nqI+WZJX4Zu9+mzZhc9pCVi8r/qlXuQIDAQABo4GnMIGkMB0GA1UdDgQWBBRvavf+\nsWM4IwKiH9X9w1vl6nUVRDB1BgNVHSMEbjBsgBRvavf+sWM4IwKiH9X9w1vl6nUV\nRKFJpEcwRTELMAkGA1UEBhMCVVMxEzARBgNVBAgTClNvbWUtU3RhdGUxITAfBgNV\nBAoTGEludGVybmV0IFdpZGdpdHMgUHR5IEx0ZIIJAM15n7fdxhRtMAwGA1UdEwQF\nMAMBAf8wDQYJKoZIhvcNAQEFBQADggEBABY2ZzBaW0dMsAAT7tPJzrVWVzQx6KU4\nUEBLudIlWPlkAwTnINCWR/8eNjCCmGA4heUdHmazdpPa8RzwOmc0NT1NQqzSyktt\nvTqb4iHD7+8f9MqJ9/FssCfTtqr/Qst/hGH4Wmdf1EJ/6FqYAAb5iRlPgshFZxU8\nuXtA8hWn6fK6eISD9HBdcAFToUvKNZ1BIDPvh9f95Ine8ar6yGd56TUNrHR8eHBs\nESxz5ddVR/oWRysNJ+aGAyYqHS8S/ttmC7r4XCAHqXptkHPCGRqkAhsterYhd4I8\n/cBzejUobNCjjHFbtkAL/SjxZOLW+pNkZwfeYdM8iPkD54Uua1v2tdw=\n-----END CERTIFICATE-----',
  host: 'example.com',
  port: 24008,
});

console.log(keylessCertificate.id);
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "id": "4d2844d2ce78891c34d0b6c0535a291e",
    "created_on": "2014-01-01T05:20:00Z",
    "enabled": false,
    "host": "example.com",
    "modified_on": "2014-01-01T05:20:00Z",
    "name": "example.com Keyless SSL",
    "permissions": [
      "#ssl:read",
      "#ssl:edit"
    ],
    "port": 24008,
    "status": "active",
    "tunnel": {
      "private_ip": "10.0.0.1",
      "vnet_id": "7365377a-85a4-4390-9480-531ef7dc7a3c"
    }
  }
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "id": "4d2844d2ce78891c34d0b6c0535a291e",
    "created_on": "2014-01-01T05:20:00Z",
    "enabled": false,
    "host": "example.com",
    "modified_on": "2014-01-01T05:20:00Z",
    "name": "example.com Keyless SSL",
    "permissions": [
      "#ssl:read",
      "#ssl:edit"
    ],
    "port": 24008,
    "status": "active",
    "tunnel": {
      "private_ip": "10.0.0.1",
      "vnet_id": "7365377a-85a4-4390-9480-531ef7dc7a3c"
    }
  }
}
```