Skip to content
WP Cloud
WP Cloud
    • For Hosts
    • For Agencies
    • For Registrars
    • For Native Hosting
    • Performance
    • Security
    • Real-Time Automated Failover
    • Vertical Scaling and Bursting
    • WordPress Management
    • PanelAlpha Integration: White-Label WordPress Control Panel for Hosts
    • EasyEngine Panel Integration: Visual WordPress Management for WP Cloud
    • FAQs
    • WP Cloud API
    • Partner Portal
    • Documentation
    • New Partner Guide
    • Pressable
    • Convesio
    • Porkbun
    • PanelAlpha
    • Ivapix
    • UNC Greensboro
    • Impressive Hosting
    • Blog
    • Performance Benchmarks
  • Connect With Us
  • Login ↗
Start Here ↗
  • Solutions

    • For Hosts
    • For Agencies
    • For Registrars
    • For Native Hosting
    • Featured Partners

    Features

    • Performance
    • Security
    • Real-Time Automated Failover
    • Vertical Scaling and Bursting
    • WordPress Management

    Integrations

    • PanelAlpha Integration
    • Easy Engine Panel Integration

    Resources

    • FAQs
    • WP Cloud API
    • Partner Portal
    • Documentation
    • New Partner Guide
  • Case Studies
    • PressableA case study about how WP Cloud supports Pressable to power millions of page views daily.
    • Convesio
    • Porkbun
    • PanelAlpha
    • Ivapix
    • UNC Greensboro
    • Newspack
    • Inverse Paradox
  • Insights
    • Podcast
    • BlogWP Cloud blog page with latest news and updates about the platform.
    • Performance Benchmarks
  • Connect With Us
  • Login ↗
Start Here ↗

Browse

    • WP Cloud platform overview
    • Onboard and launch with WP Cloud
    • WP Cloud Partner Portal
    • Get support from WP Cloud
    • WP Cloud glossary
    • Manage and secure API keys
    • Client SSH
    • WP Cloud API quick start
    • Webhooks
    • Run bulk tasks across sites
      • Manage site domains and aliases
      • Domain verification records
      • TLS certificates
      • Manage custom TLS certificates
      • Cloudflare and WP Cloud
    • Clone a site
    • Configure resources, site type, and billing with site meta
    • Delete a site
    • Persistent data
    • Staging sites
    • Migrate a site to WP Cloud
      • SSH and SFTP access models
      • Client SSH
      • User SSH and SFTP access
      • Database credentials
      • phpMyAdmin
      • ABSPATH
      • Default wp-config.php
      • Site constants
      • Configure redirects and headers with custom-redirects.php
      • Akismet and Jetpack
      • Blocked and unsupported plugins
      • PHP lifecycle and supported versions
      • Symlinks and managed software
      • WordPress versions
      • Install Composer and WP-CLI packages
      • Manage platform software with WP-CLI
      • Useful WP-CLI commands
    • Transactional email
    • WordPress multisite
    • Cron scheduling
    • Decoupled and headless WordPress
    • Repair Yoast indexables
      • Page Cache
      • Edge Cache
      • Object Cache
      • Image transformation
      • Offload image sub-sizes
    • Configure lightweight 404s for static files
      • DDoS protection
      • Defensive Mode
      • Rate limiting
      • Network and web application firewalls
      • Bot protection
      • Password protection
      • HTTP and security headers
      • PHP filesystem access permissions
      • Scan a site for malware
    • Backups overview
    • Create an on-demand backup
    • Restore a backup
    • Jetpack backups
      • Error logs
      • Web server logs
    • Metrics
    • Application performance monitoring
    • Automated failover
    • IP ranges
    • Origin and edge servers
    • Server specifications and settings
    • EasyEngine integration
    • PanelAlpha integration
      • White labelling and co-marketing WP Cloud
      • WP Cloud logos
      • Terms of Service & Compliance
      • Prohibited content
      • Copyright infringement and takedown notifications
    • WP Cloud billing
    • WP Cloud for agencies and site networks
    • WP Cloud partner support options
    • Troubleshoot Page and Edge Cache
    • Troubleshoot HTTP 429 and 599 errors
    • WP Cloud HTTP status codes
    • Troubleshoot site performance
    • Cache slow database queries
    • Troubleshoot duplicate core files, wp-config.php, and wp-admin 403 errors
    • Troubleshoot email delivery
    • Troubleshoot PDF thumbnail generation
    • Troubleshoot TLS certificate provisioning
Documentation/Sites/Domains/Manage custom TLS certificates

Manage custom TLS certificates

LAST UPDATED

3 months ago

    WP Cloud normally provisions and renews managed TLS certificates for verified site domains. A host partner can use the Custom SSL Certificates API when a site must serve a certificate supplied by the partner or its customer.

    Partners can include custom certificate support in their hosting products or offer it as a paid upgrade. If WP Cloud cannot use the custom certificate, the platform automatically falls back to a managed Let’s Encrypt certificate.

    Custom certificates require extra care because the workflow handles a private key and has separate validation, staging, activation, update, deactivation, and deletion states. Test the workflow on a controlled site before offering it to customers.

    Prepare the certificate

    Before sending certificate material to WP Cloud:

    • verify the site’s domains;
    • confirm that the certificate covers every hostname where it will be used;
    • provide the certificate and its chain in PEM format;
    • confirm that the private key matches the certificate; and
    • choose a non-production site for the first integration test.

    Treat the private key as a secret. Do not place it in source control, command history, application logs, support requests, or test fixtures. Limit access to the system that submits it, and remove temporary copies after the request completes.

    Validate the certificate material

    Send the certificate, private key, and optional domain list to the Validate Custom Certificate endpoint. Review every validation error and warning before continuing.

    A successful validation confirms that the submitted material passed the endpoint’s checks. It does not store or activate the certificate.

    Stage the certificate

    Send the validated material to the Stage Custom Certificate endpoint. The response returns ssl_custom_certificate_id, the associated domains, and an inactive state. Retain the certificate ID; later lifecycle operations use it.

    Staging prepares the certificate but does not change the certificate currently served by the site.

    Inspect and activate the certificate

    Use the Get Custom Certificate Details endpoint or List Custom Certificates endpoint to check the certificate ID, domains, active state, issuer, subject, and validity dates.

    Activate the staged certificate with the Activate Custom Certificate endpoint. After activation succeeds, check each configured hostname with an independent TLS client or certificate checker. Confirm that it serves the intended certificate and complete chain before directing production traffic to it.

    Renew, deactivate, or delete a certificate

    Use separate lifecycle operations rather than assuming that one request performs every change:

    • Update Custom Certificate replaces certificate material for renewal or rekeying. Inspect the resulting record and verify the served certificate again.
    • Deactivate Custom Certificate stops the selected certificate from being active. Confirm the site’s TLS behavior before relying on another certificate.
    • Delete Custom Certificate removes an inactive certificate record. An active custom certificate must be deactivated before it can be deleted.

    Keep the certificate ID, covered domains, validity dates, and partner-owned renewal date in the system that manages the certificate. Do not rely on validation or staging alone as proof that the certificate is active or being served.

    Previous TLS certificates
    Next Cloudflare and WP Cloud

    Related Guides

    • Manage site domains and aliases

      Manage primary and secondary WP Cloud site domains, control alias canonicalization, retrieve suggested DNS addresses,…

      4 Min.

      READ

    • Domain verification records

      Publish WP Cloud DNS TXT verification records when a domain is already assigned to a…

      2 Min.

      READ

    • TLS certificates

      Understand how WP Cloud provisions, installs, and renews TLS certificates for site domains.

      2 Min.

      READ

    On this page

      Contact support

      Contact us with Support issues and questions related to WP Cloud, the WP Cloud Atomic API, API-key IP allow list changes, Station, and more.

      Check the FAQs

      Have questions? Please visit our FAQ to learn more.

      An Automattic venture

      Work With Us

      Press

      Privacy Policy

      © 2021-2026 Automattic Inc.

      Notifications