Certificates
How the edge issues and renews each domain's HTTPS certificate, where to see it, and how you hear about a certificate that needs attention.
The edge issues a certificate for a domain the first time someone visits it over HTTPS once the domain points at CustomDomain™ (Let's Encrypt, through the domain itself). Renewal starts about 30 days before expiry and needs no access to your DNS, so it works the same whatever access was kept. A failing renewal is retried after 30 minutes at first, then less often after each failure, up to about once a day, while the current certificate keeps serving.
Read a domain's certificate
GET /v1/connections/{id}/certificate returns what the edge last reported:
{
"certificate": {
"host": "shop.acme.com",
"status": "issued",
"issuer": "R11",
"issued_at": "2026-09-01T12:00:00Z",
"renewed_at": "2026-10-01T12:00:00Z",
"expires_at": "2026-12-30T12:00:00Z",
"days_left": 92,
"next_renewal_at": "2026-11-30T12:00:00Z",
"managed": true
},
"renewal": { "automatic": true, "needs_dns_access": false, "retry_every": "30 minutes at first, then less often after each failure, up to about once a day" },
"history": [ { "kind": "certificate.renewed", "created_at": "2026-10-01T12:00:00Z" } ]
}status is issued, renewing (renewal keeps failing while the current
certificate still serves; last_error says why), failed, pending or
not_reported (the edge has not reported one yet). attention is set when a
person should look: failed, renewal_failing (failing for 6 hours),
expiring (14 days or less without a renewal) or expired. An apex that
redirects www also returns www_certificate.
Alerts
- Webhooks:
certificate.issued,certificate.renewed,certificate.failed(once per failure episode) andcertificate.expiring(14, 7 and 3 days before an unrenewed certificate expires, and when it did). Each carries acertificateobject. See the event catalog. A certificate an edge finds in its cache after a restart is recorded without an event, so restarts send nothing. The oldersecure_statuswebhook is sent only where the deployment has Secure on (SECURE_ENABLED), once per status change. - Email: the workspace's owners and admins get one email per threshold.
- Console: the domain page's Certificate tab shows the state, the dates, the last error and the history, and the page itself shows a banner that links there when it needs attention.
When a domain is removed, its certificate stops renewing and is deleted from every edge within a minute.
Provider accounts
Connect a DNS provider or registrar account once, for some or all of its domains, with one time or continuous access.
Monitoring and services
Every live domain is checked each hour against the records it went live with. Drift is confirmed before anything happens; missing records CustomDomain™ wrote can be put back where it holds continuous access.