GET Certificates CSV

The GET /Certificates/CSV operation creates output, in a CSV format, of certificates from Keyfactor Command that match the query criteria provided in the request. The content will display in the response body and can be copied from there for use in a file, as needed. On success, the operation returns HTTP 200 OK with  a comma-delimited list of certificates plus a header line that can be copied to a CSV file.

Tip:  The following permissions (see Security Roles and Claims) are required to use this feature:
/certificates/collections/read/
OR
/certificates/collections/read/#/

Permissions for certificates can be set at the system-wide or resource-specific level. The appropriate level depends on how the certificates are accessed. See Certificate Collection Permissions for more information.

In permission strings, # represents a specific resource identifier. In /certificates/collections/ permission strings it refers to a certificate collection ID (for example, CollectionId) and in /certificate_stores/ permission strings it refers to a certificate store application ID (for example, containerId).

Important:  Selecting a large number of certificates to retrieve in CSV format can result in timeouts when attempting to download. Use certificate queries to limit results to a manageable amount of data.

Table 301: GET Certificates CSV Input Parameters

Name In Description
SortName Query A string containing the property by which the results should be sorted. Fields available for sorting through the API for the most part match those that appear as sortable columns in the Keyfactor Command Management Portal. The default sort field is ImportDate.
SortOrder Query An integer that sets the sort order on the returned results. A value of 0 sorts results in ascending order while a value of 1 sorts results in descending order. The default is ascending.
Query Query

A string containing a query to limit the results (for example, field1 -eq value1 AND field2 -gt value2). The default is to return all records. Fields available for querying through the API for the most part match those that appear in the Keyfactor Command Management Portal search dropdowns for the same feature. For querying guidelines, refer to: Searching Certificates, including a list of supported query fields.

CollectionId Query

An optional integer that specifies the certificate collection (CollectionId) to validate whether the user has sufficient permissions to perform the action. If a CollectionId is not provided, the user must have appropriate permissions granted system-wide or via certificate store applications.

Providing a CollectionId allows the system to check the user's permissions at the certificate collection level. Permissions are evaluated in the following order:

  1. System-wide certificate permissions
  2. Granular certificate permissions

Use either ContainerId or CollectionId, not both. If both are specified, CollectionId takes precedence, and the ContainerId is ignored (defaults to 0).

See Certificate Collection Permissions for more information.

MetadataFields Query

An array of integers identifying any optional certificate metadata fields to include in the output.

Use the GET Metadata Fields operation to determine the metadata field IDs.

IncludeSANs Query

A Boolean that indicates whether SANs for the certificates should be included in the output. The default is False.

Table 302: GET Certificates CSV Response Data

Name Description
n/a

A set of comma-delimited strings of certificate data per the criteria supplied. The following fields are included:

  • CA Record Id (integer)
  • Certificate Authority Name (string)
  • Certificate State (string)
  • Effective Date (datetime UTC)
  • Expiration Date (datetime UTC)
  • Import Date (datetime UTC)
  • Is Renewed (Boolean)
  • Issued CN (string)
  • Issued DN (string)
  • Issuer DN (string)
  • Key Algorithm (string)
  • Key Size (string)
  • Key Type (string)
  • Key Usage (comma-separated list of strings)
  • Lifespan (Days) (integer)
  • Location Count (integer)
  • Metadata Fields (optional, type varies depending on field)
  • Owner Role Name (string)
  • Principal (string)
  • Requester (string)
  • Revocation Comment (string)
  • Revocation Effective Date (datetime UTC)
  • Revocation Reason (string)
  • Revoker (string)
  • SAN Count (integer)
  • SANs (optional, string)
  • Serial Number (string)
  • Signing Algorithm (string)
  • Template Display Name (string)
  • Thumbprint (string)
Note:  Optional fields are included only when selected in the CSV export options. Metadata fields represent custom certificate metadata defined in the system and selected for export.

For example:

Copy
Issued DN,Import Date,Effective Date,Expiration Date,Issued CN,Issuer DN,Certificate Authority Name,Template Display Name,Principal,Owner Role Name,Requester,Key Type,Key Algorithm,Key Size,Key Usage,Certificate State,Thumbprint,Serial Number,Signing Algorithm,CA Record Id,SAN Count,Lifespan (Days),IsRenewed,Revoker,Revocation Effective Date,Revocation Reason,Revocation Comment,Location Count
"C=US,ST=Illinois,L=Oakville,O=Key Example,OU=IT,CN=appsrvr103.keyexample.com","2025-08-27T17:40:09.9570000","2025-06-23T15:23:43.0000000","2027-06-23T15:23:42.0000000","appsrvr103.keyexample.com","C=US,ST=Washington,L=Carnation,O=KeyExample,CN=CorpIssuingCA7","https://appsrvr187.keyexample.com:6447\CorpIssuingCA7","Corporate (CorpWebServer-MultiKey)",,"Power Users",,"ML-DSA-65","2.16.840.1.101.3.4.3.18","0","Digital Signature,Key Encipherment (a0)","Active","E08B0F4FD9DE9963EB04B94F93DB4879C9EF49DC","18AD84B465493578AEF19B731249C05B3BFCE317","SHA-512withRSA","18AD84B465493578AEF19B731249C05B3BFCE317","0","730","False",,,,,"0"
"C=US,ST=Colorado,L=Naperville,O=Key Example,OU=IT,CN=appsrvr33.keyexample.com","2025-08-27T17:50:06.0730000","2025-03-12T22:23:43.0000000","2027-03-12T22:23:42.0000000","appsrvr33.keyexample.com","C=US,ST=Washington,L=Ellensburg,O=KeyExample,CN=CorpHybridIssuingCA7","https://appsrvr187.keyexample.com:6447\CorpHybridIssuingCA7","Corporate (CorpHybridWebServer-MultiKey)",,,,"ECC","1.2.840.10045.2.1","384","Digital Signature,Key Encipherment (a0)","Active","CD4413A38B1D5AD8F4CC9BADC304EF4167E60159","33E76E314E78322ED20E5F0D3EF2A1A740EAF0A1","SHA-512withRSA","33E76E314E78322ED20E5F0D3EF2A1A740EAF0A1","1","730","False",,,,,"0"
"C=US,ST=Nevada,L=Wilsonville,O=Key Example Company,OU=HR,CN=appsrvr103.keyexample.com","2025-12-08T22:40:21.1070000","2025-11-12T17:22:12.0000000","2025-12-29T17:22:11.0000000","appsrvr103.keyexample.com","C=US,ST=Washington,L=Carnation,O=KeyExample,CN=CorpIssuingCA7","https://appsrvr187.keyexample.com:6447\CorpIssuingCA7","Corporate (CorpWebServer-MultiKey-47Days)",,,,"RSA","1.2.840.113549.1.1.1","2048","Digital Signature,Key Encipherment (a0)","Active","100E230C507BD242391B593505BF606B95D68E6C","3CC6A47D3A2C037542D0B15EC5AC44E0877A63C7","SHA-512withRSA","3CC6A47D3A2C037542D0B15EC5AC44E0877A63C7","0","47","False",,,,,"0"
"C=US,ST=Nevada,L=Wilsonville,O=Key Example Company,OU=HR,CN=appsrvr54.keyexample.com","2025-12-08T22:40:21.3770000","2025-11-12T17:44:06.0000000","2025-12-29T17:44:05.0000000","appsrvr54.keyexample.com","C=US,ST=Washington,L=Carnation,O=KeyExample,CN=CorpIssuingCA7","https://appsrvr187.keyexample.com:6447\CorpIssuingCA7","Corporate (CorpWebServer-MultiKey-47Days)",,,,"RSA","1.2.840.113549.1.1.1","2048","Digital Signature,Key Encipherment (a0)","Active","4221067B1896DE8FEC28E6C2BB1B86496E341573","3741C5EA315B15E6494F2A363B7EF03487A2642A","SHA-512withRSA","3741C5EA315B15E6494F2A363B7EF03487A2642A","0","47","False",,,,,"0"
"C=US,ST=Nevada,L=Naperville,O=Key Example,OU=IT,CN=appsrvr103.keyexample.com","2026-01-05T17:27:09.3630000","2025-09-26T17:48:03.0000000","2027-09-26T17:48:02.0000000","appsrvr103.keyexample.com","C=US,ST=California,L=Ukiah,O=KeyExample,CN=CorpIssuingCA6A",,,,,,"ECC","1.2.840.10045.2.1","256","Digital Signature,Key Encipherment (a0)","Unknown","22A5581238E791999A7EDA7719A2AFEB17B728C7","70BE7947AE02736868DCA31F85075E0C202EEA56","SHA512withRSAandMGF1",,"1","730","False",,,,,"0"
"C=US,ST=Illinois,L=Oakville,O=Key Example,OU=E-Commerce,CN=app24.keyexample.com","2026-02-06T20:57:26.7030000","2026-02-06T20:47:26.0000000","2028-02-06T20:47:25.0000000","app24.keyexample.com","C=US,ST=Washington,L=Gig Harbor,O=KeyExample,CN=CorpPQCIssuingCA7","https://appsrvr187.keyexample.com:6447\CorpPQCIssuingCA7","Corporate (CorpWebServer-MultiKey)",,"Administrator",,"RSA","1.2.840.113549.1.1.1","2048","Digital Signature,Key Encipherment (a0)","Active","1654D7C2A245E0552A3E6340E795AB8AF8EF4834","346E8303403F132BDA7C322F99AB02F316EE280E","ML-DSA-87","346E8303403F132BDA7C322F99AB02F316EE280E","0","730","False",,,,,"0"

Any commas embedded within strings (for example, SANs) are escaped.