Skip to main content
Version: 1.28 (Current)

Get Client Certificate Details

Audience: Low-code Engineers

Skill Prerequisites: Actions, APIs

Reads the client certificate that the caller sent with a request to an API endpoint, and saves its thumbprint and issuer in tokens. Use it to check which certificate a caller used, for example to allow only known systems to call an API.

This action is only available in API endpoints.

Typical Use Cases​

  • Allow only callers with a known certificate, by comparing the thumbprint with a list of trusted values
  • Record which certificate called an API, for example with Log Event

Don't use it to​

  • Send a certificate to another system. Use the client certificate settings of Server Request.
  • Check certificates on forms or other pages. It only works in API endpoints.
Action NameDescription
Throw ExceptionRejects the request when the certificate isn't trusted.
Log EventRecords which certificate called the API.
Server RequestSends a client certificate when calling another API.

Input Parameter Reference​

This action has no input parameters.

Output Parameters Reference​

ParameterDescription
Output TokenNameThe name of the output token, for example ClientCert. The action sets [<Output TokenName>:Thumbprint] and [<Output TokenName>:Issuer]. If it's empty, the action does nothing.

Considerations​

  • The web server must ask for client certificates. In IIS, the site's SSL settings must accept or require client certificates, and the request must use HTTPS. Otherwise the certificate never reaches Plant an App.
  • No certificate means an error. If the request doesn't include a client certificate, the action fails with No certificate found in the current request. Use an On Error list or Execute Actions if some callers don't send one.
  • The certificate isn't validated. The action only reads its details. Compare the thumbprint with your trusted list yourself, as in the example below.
  • Thumbprints are upper case, without spaces.

Examples​

tip

To understand how to use the below examples, please see Running Examples.

1. Allow only a trusted certificate​

The first action reads the certificate. The second rejects the request unless the thumbprint matches the one stored in the TrustedThumbprint token.

[
{
"Title": "Get Client Certificate Details",
"ActionType": "GetCert",
"Description": "Read the caller's certificate",
"Parameters": {
"OutputTokenName": "ClientCert"
}
},
{
"Title": "Throw Exception",
"ActionType": "ThrowException",
"Description": "Reject untrusted certificates",
"Condition": "[ClientCert:Thumbprint] != [TrustedThumbprint]",
"Parameters": {
"AdminMessage": "Untrusted client certificate [ClientCert:Thumbprint] from [ClientCert:Issuer].",
"FriendlyMessage": "Access denied."
}
}
]

Revised 09/27/2026