Get Client Certificate Details
Audience:
Low-code EngineersSkill Prerequisites:
Actions,APIs
Reads the client certificate that the caller sent with a request to an API endpoint, and saves its thumbprint and issuer in tokens. Use it to check which certificate a caller used, for example to allow only known systems to call an API.
This action is only available in API endpoints.
Typical Use Cases
- Allow only callers with a known certificate, by comparing the thumbprint with a list of trusted values
- Record which certificate called an API, for example with Log Event
Don't use it to
- Send a certificate to another system. Use the client certificate settings of Server Request.
- Check certificates on forms or other pages. It only works in API endpoints.
Related Actions
| Action Name | Description |
|---|---|
| Throw Exception | Rejects the request when the certificate isn't trusted. |
| Log Event | Records which certificate called the API. |
| Server Request | Sends a client certificate when calling another API. |
Input Parameter Reference
This action has no input parameters.
Output Parameters Reference
| Parameter | Description |
|---|---|
| Output TokenName | The name of the output token, for example ClientCert. The action sets [<Output TokenName>:Thumbprint] and [<Output TokenName>:Issuer]. If it's empty, the action does nothing. |
Considerations
- The web server must ask for client certificates. In IIS, the site's SSL settings must accept or require client certificates, and the request must use HTTPS. Otherwise the certificate never reaches Plant an App.
- No certificate means an error. If the request doesn't include a client certificate, the action fails with No certificate found in the current request. Use an
On Errorlist or Execute Actions if some callers don't send one. - The certificate isn't validated. The action only reads its details. Compare the thumbprint with your trusted list yourself, as in the example below.
- Thumbprints are upper case, without spaces.
Examples
tip
To understand how to use the below examples, please see Running Examples.
1. Allow only a trusted certificate
The first action reads the certificate. The second rejects the request unless the thumbprint matches the one stored in the TrustedThumbprint token.
[
{
"Title": "Get Client Certificate Details",
"ActionType": "GetCert",
"Description": "Read the caller's certificate",
"Parameters": {
"OutputTokenName": "ClientCert"
}
},
{
"Title": "Throw Exception",
"ActionType": "ThrowException",
"Description": "Reject untrusted certificates",
"Condition": "[ClientCert:Thumbprint] != [TrustedThumbprint]",
"Parameters": {
"AdminMessage": "Untrusted client certificate [ClientCert:Thumbprint] from [ClientCert:Issuer].",
"FriendlyMessage": "Access denied."
}
}
]
Revised 09/27/2026