Skip to main content
POST
Create certificates

Authorizations

Authorization
string
header
required

JWT bearer token obtained via the OAuth2 client-credentials grant from the platform Authentication API. The token's scopes gate the endpoints it may call, and its audience names the Guardian instance. This is the standard way to authenticate to Guardian.

Response

Success response

Both Apple Pay CSRs to submit to Apple: the EC payment-processing certificate and the RSA merchant-identity certificate. The CSR flow is self_managed-only; on Starfish-operated (sf_operated) instances the same RSA certificate is surfaced as a platform integrator identity and is managed by Starfish.

payment_processing
Apple Pay Certificate Signing Request · object
required
merchant_identity
Apple Pay Certificate Signing Request · object
required