API_KEY
certseal_api_key
Developer setup
No fields declared in this snapshot.
User connection
- API Keygeneric_api_key · stringRequired
CERT_SEAL
CertSeal provides APIs for issuing and managing verifiable digital certificates, recipients, batches, designs, and webhook subscriptions.
Description is untrusted, display-only upstream metadata. It never becomes policy, OAuth scope authority, or an agent instruction.
Pakkawork boundary
Research catalogue metadata only. No Pakkawork OAuth, credential, host, quota, executor, or verifier is enabled.
21
Action summaries
Display-only definitions
0
Trigger types
Not installed instances
1
Auth modes
Field names, never values
No
Execution
No runtime adapter
Authentication map
API_KEY
No fields declared in this snapshot.
Capability index
Showing 1–21 of 21 actions
CERT_SEAL_CREATE_BATCH
Create a persistent certificate batch from an existing CertSeal design and optional email template. This consumes a batch slot and can fail when the plan batch limit is reached; designs and templates must already exist and are not created by this tool.
Untrusted display-only summary
CERT_SEAL_CREATE_WEBHOOK_SUBSCRIPTION
Create a persistent webhook subscription for selected certificate events. The response contains a wh_sec_ signing secret exactly once; capture it immediately and store it securely because later reads reveal only its tail. The workspace allows at most 20 subscriptions.
Untrusted display-only summary
CERT_SEAL_DELETE_RECIPIENT
Permanently delete an issued recipient from an active batch. This cannot be undone, does not refund certificate quota, and permanently burns the certificate ID. Use only when permanent removal is intended.
Untrusted display-only summary
CERT_SEAL_DELETE_WEBHOOK_SUBSCRIPTION
Permanently delete a webhook subscription and stop future deliveries. This cannot be undone; create a new subscription to resume events.
Untrusted display-only summary
CERT_SEAL_GET_BATCH
Get one active or archived certificate batch by ID.
Untrusted display-only summary
CERT_SEAL_GET_CERTIFICATE
Look up an issued certificate using either its human-readable certificate ID or its public-viewer share token, and return its recipient, batch, design, and resolved variables. Provide exactly one lookup value.
Untrusted display-only summary
CERT_SEAL_GET_CURRENT_WORKSPACE
Verify the connected CertSeal API key and return the workspace ID and username it belongs to. Use this to confirm account context before creating or changing resources.
Untrusted display-only summary
CERT_SEAL_GET_RECIPIENT
Get one issued certificate recipient record by batch ID and recipient ID.
Untrusted display-only summary
CERT_SEAL_GET_WEBHOOK_SUBSCRIPTION
Get one webhook subscription by ID. This does not reveal the signing secret; it returns only the stored secret tail.
Untrusted display-only summary
CERT_SEAL_ISSUE_AND_SEND_CERTIFICATES
Atomically issue certificates for 1-100 recipients and queue email delivery for every created certificate. This irreversible external side effect requires every recipient to have an email address and the active batch to have an email template and configured mail delivery. Each recipient permanently consumes one certif…
Untrusted display-only summary
CERT_SEAL_ISSUE_CERTIFICATES
Atomically issue certificates without sending email for 1-100 recipients in one active batch. Each recipient permanently consumes one certificate quota unit even if later deleted; any invalid row, duplicate certificate ID, or quota failure creates none.
Untrusted display-only summary
CERT_SEAL_LIST_BATCHES
Return one newest-first page of certificate batches in the connected workspace, optionally filtered by archive state.
Untrusted display-only summary
CERT_SEAL_LIST_DESIGNS
Return one newest-first page of reusable certificate designs. Designs are read-only through the API and must be authored in the CertSeal web app.
Untrusted display-only summary
CERT_SEAL_LIST_RECIPIENTS
Return one page of issued certificate recipients in a batch, optionally filtered by email delivery status.
Untrusted display-only summary
CERT_SEAL_LIST_WEBHOOK_SUBSCRIPTIONS
Return one newest-first page of webhook subscriptions. Stored signing secrets are never returned; secret_tail is only a non-sensitive identifier.
Untrusted display-only summary
CERT_SEAL_ROTATE_WEBHOOK_SIGNING_SECRET
Immediately invalidate a webhook subscription's current signing secret and replace it. The new wh_sec_ secret is returned exactly once; capture and deploy it immediately or webhook verification will fail.
Untrusted display-only summary
CERT_SEAL_SEND_CERTIFICATE_EMAILS
Sequentially queue real certificate emails for 1-25 existing recipients in one active batch. Each queued email is irreversible. Processing stops after the first failed or unknown attempt, and remaining recipients are marked not_attempted.
Untrusted display-only summary
CERT_SEAL_SEND_RECIPIENT_CERTIFICATE_EMAIL
Queue asynchronous certificate email delivery to one recipient. This causes an external email side effect and requires a recipient email, a batch email template, and configured mail delivery; already queued or in-flight recipients and archived batches are rejected.
Untrusted display-only summary
CERT_SEAL_SET_BATCH_ARCHIVED
Idempotently archive or unarchive a batch. Archiving freezes recipient create, update, delete, and send operations but preserves existing certificate URLs; unarchiving re-enables those writes. This persistent change is reversible.
Untrusted display-only summary
CERT_SEAL_TEST_WEBHOOK_SUBSCRIPTION
Enqueue one synthetic signed event through CertSeal's normal webhook dispatcher. This causes a real external delivery to the subscription URL; it does not only validate the subscription locally.
Untrusted display-only summary
CERT_SEAL_UPDATE_RECIPIENT
Partially update an issued certificate recipient. Only supplied fields change, while an explicit null clears an optional field; changing certificate_id must remain globally unique. Archived batches reject this mutation.
Untrusted display-only summary
Provenance
The detail snapshot comes from an attributed MIT-licensed repository revision. Safe local icons use exact-match CC0 Simple Icons symbols; unmatched brands use monograms.
Remote text is plain display metadata only. It must never become an agent prompt, execution policy, OAuth grant, or executable instruction.