curl --request POST \
--url https://api.example.com/organizations/certificates/validate \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: multipart/form-data' \
--form password=mypassword123import requests
url = "https://api.example.com/organizations/certificates/validate"
payload = "-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"password\"\r\n\r\nmypassword123\r\n-----011000010111000001101001--"
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "multipart/form-data"
}
response = requests.post(url, data=payload, headers=headers)
print(response.text)const form = new FormData();
form.append('password', 'mypassword123');
const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
options.body = form;
fetch('https://api.example.com/organizations/certificates/validate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/organizations/certificates/validate",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => "-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"password\"\r\n\r\nmypassword123\r\n-----011000010111000001101001--",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: multipart/form-data"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/organizations/certificates/validate"
payload := strings.NewReader("-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"password\"\r\n\r\nmypassword123\r\n-----011000010111000001101001--")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.example.com/organizations/certificates/validate")
.header("Authorization", "Bearer <token>")
.body("-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"password\"\r\n\r\nmypassword123\r\n-----011000010111000001101001--")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/organizations/certificates/validate")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request.body = "-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"password\"\r\n\r\nmypassword123\r\n-----011000010111000001101001--"
response = http.request(request)
puts response.read_body{
"valid": true,
"rfc": "XAXX010101000",
"serialNumber": "30001000000300023708",
"expiresAt": "2025-05-15T00:00:00.000Z",
"issuedAt": "2021-05-15T00:00:00.000Z",
"subjectName": "EMPRESA EJEMPLO SA DE CV",
"error": "Invalid certificate format",
"isExpired": false,
"passwordValid": true,
"passwordError": "Incorrect password",
"pairValid": true,
"pairError": "The certificate (.cer) and private key (.key) do not form a matching CSD pair"
}Validate CSD certificate and optionally verify private key password
Validates a CSD certificate file and extracts metadata (RFC, serial number, expiration). Optionally validates the private key password. Does not store the certificate. Useful for pre-validation during onboarding.
curl --request POST \
--url https://api.example.com/organizations/certificates/validate \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: multipart/form-data' \
--form password=mypassword123import requests
url = "https://api.example.com/organizations/certificates/validate"
payload = "-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"password\"\r\n\r\nmypassword123\r\n-----011000010111000001101001--"
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "multipart/form-data"
}
response = requests.post(url, data=payload, headers=headers)
print(response.text)const form = new FormData();
form.append('password', 'mypassword123');
const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
options.body = form;
fetch('https://api.example.com/organizations/certificates/validate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/organizations/certificates/validate",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => "-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"password\"\r\n\r\nmypassword123\r\n-----011000010111000001101001--",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: multipart/form-data"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/organizations/certificates/validate"
payload := strings.NewReader("-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"password\"\r\n\r\nmypassword123\r\n-----011000010111000001101001--")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.example.com/organizations/certificates/validate")
.header("Authorization", "Bearer <token>")
.body("-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"password\"\r\n\r\nmypassword123\r\n-----011000010111000001101001--")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/organizations/certificates/validate")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request.body = "-----011000010111000001101001\r\nContent-Disposition: form-data; name=\"password\"\r\n\r\nmypassword123\r\n-----011000010111000001101001--"
response = http.request(request)
puts response.read_body{
"valid": true,
"rfc": "XAXX010101000",
"serialNumber": "30001000000300023708",
"expiresAt": "2025-05-15T00:00:00.000Z",
"issuedAt": "2021-05-15T00:00:00.000Z",
"subjectName": "EMPRESA EJEMPLO SA DE CV",
"error": "Invalid certificate format",
"isExpired": false,
"passwordValid": true,
"passwordError": "Incorrect password",
"pairValid": true,
"pairError": "The certificate (.cer) and private key (.key) do not form a matching CSD pair"
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Body
Password for the private key
"mypassword123"
Response
Certificate validation result with extracted metadata.
Whether the certificate is valid
true
RFC extracted from the certificate
"XAXX010101000"
Certificate serial number
"30001000000300023708"
Certificate expiration date
"2025-05-15T00:00:00.000Z"
Certificate issue date
"2021-05-15T00:00:00.000Z"
Subject common name from certificate
"EMPRESA EJEMPLO SA DE CV"
Error message if validation failed
"Invalid certificate format"
Whether the certificate has expired
false
Whether the password is valid for the private key
true
Error message if password validation failed
"Incorrect password"
Whether the certificate and private key form a matching CSD pair
true
Error message if the certificate and private key do not match
"The certificate (.cer) and private key (.key) do not form a matching CSD pair"