Trustico® API Services for Ordering and Management

Trustico® provides three Application Programming Interfaces (API). One places orders, one manages SSL Certificates that have already been ordered, and one exposes the free SSL Certificate tools.

Each is documented separately, and this page explains what each one does so you can go straight to the right one.

Partner Ordering Application Programming Interface (API)

The ordering Application Programming Interface (API) places SSL Certificate orders directly from your own systems. Orders are priced against your partner account and paid from your Trustico® Prepaid Credit.

It requires an approved partner account on the current platform and an issued key. Duplicate order protection is built in, so a retry after a timeout never places a second order.

This is the interface to choose where SSL Certificates need to be obtained directly from your own platform, without anyone completing an order form by hand. Learn About The Partner Ordering API 🔗

Tracking System Application Programming Interface (API)

The tracking system Application Programming Interface (API) manages an SSL Certificate after it has been ordered. It covers validation progress, changing the Domain Control Validation (DCV) method, requesting a reissue, and downloading the issued files.

Access requires approval and an issued key, and every call acts on a single SSL Certificate identified by its Certificate Authority (CA) Reference. It applies to traditional SSL Certificates only, as Certificate as a Service (CaaS) products are managed by your own Automated Certificate Management Environment (ACME) client.

Once an order exists, this is the interface that carries the remaining work of validating, reissuing and downloading an SSL Certificate through to completion. Learn About The Tracking System API 🔗

SSL Certificate Tools Application Programming Interface (API)

The tools Application Programming Interface (API) exposes the free utilities hosted at tools.trustico.com. It generates and decodes a Certificate Signing Request (CSR), analyzes chains, matches keys, converts to PFX, and checks Certification Authority Authorization (CAA) and Domain Control Validation (DCV) records.

It requires no key and no account, which makes it suitable for build pipelines and monitoring jobs. It prepares and checks rather than issues, as issuance always follows a validated order.

Preparation and troubleshooting belong here, both before an order is placed and long after an SSL Certificate has been installed on a server. Learn About The SSL Certificate Tools API 🔗

Legacy Systems and Legacy Interfaces

Trustico® operated an earlier platform with its own Application Programming Interface (API). That interface and the systems behind it are no longer supported and should not be used for new development.

Important : A key issued for a legacy system will not work against any interface described on this page. Anything still built against a legacy interface should be moved across rather than extended.

The correct path forward is to place new orders through the ordering Application Programming Interface (API) and to manage existing SSL Certificates through the tracking system Application Programming Interface (API).

Nothing you already hold is affected by that move. An SSL Certificate is managed by its Certificate Authority (CA) Reference rather than by the account or platform the order was placed on. Learn About The Legacy Platform 🔗

Choosing the Right Interface

Ordering and management are deliberately separate, and the two account interfaces follow that same separation rather than duplicating one another. Learn About Ordering and Management 🔗

Where a workflow needs both, an integration typically orders through the first, waits for the Certificate Authority (CA) Reference to be assigned, then uses that reference with the second for everything afterwards.

Partner Ordering API Tracking System API

Anyone wanting to remove manual management altogether can use Certificate as a Service (CaaS), where your own client handles issuance and replacement without either account interface. Learn About Certificate as a Service 🔗

Most Popular Questions

Frequently asked questions covering the three Trustico® Application Programming Interfaces, what each one does, which requires approval, and why legacy interfaces should no longer be used.

Application Programming Interfaces Trustico® Provides

Trustico® provides three Application Programming Interfaces (API). One places orders, one manages SSL Certificates that have already been ordered, and one exposes the free SSL Certificate tools.

Partner Ordering Application Programming Interface (API) Purpose

The ordering Application Programming Interface (API) places SSL Certificate orders directly from a partner's own systems. Orders are priced against the partner account and paid from Trustico® Prepaid Credit.

Tracking System Application Programming Interface (API) Purpose

The tracking system Application Programming Interface (API) manages an SSL Certificate after it has been ordered. It covers validation progress, changing the Domain Control Validation (DCV) method, requesting a reissue, and downloading the issued files.

SSL Certificate Tools Application Programming Interface (API) Purpose

The tools Application Programming Interface (API) exposes the free utilities hosted at tools.trustico.com. It generates and decodes a Certificate Signing Request (CSR), analyzes chains, matches keys, converts to PFX, and checks validation records.

Interfaces Requiring Approval

The ordering and tracking system interfaces both require approval and an issued key. The SSL Certificate tools interface requires no key and no account of any kind.

Support for Legacy Interfaces

The Application Programming Interface (API) belonging to the earlier Trustico® platform is no longer supported and should not be used for new development. A key issued for a legacy system will not work against any current interface.

Correct Path Away from Legacy Systems

New orders should be placed through the ordering Application Programming Interface (API), and existing SSL Certificates should be managed through the tracking system Application Programming Interface (API). Anything still built against a legacy interface should be moved across rather than extended.

Existing SSL Certificates During the Move

Nothing already held is affected by the move. An SSL Certificate is managed by its Certificate Authority (CA) Reference rather than by the account or platform the order was placed on.

Using Both Account Interfaces Together

An integration typically orders through the ordering interface, then waits for the Certificate Authority (CA) Reference to be assigned. That reference is then used with the tracking system interface for everything afterwards.

Avoiding Manual SSL Certificate Management

Certificate as a Service (CaaS) removes manual management entirely, as your own Automated Certificate Management Environment (ACME) client handles issuance and replacement. Neither account interface is involved in that process.