---
title: "Create an AI Gateway Certificate"
method: POST
path: "/v1/ai-gateways/{gatewayId}/certificates"
tags: ["AI Gateway Certificates"]
---

# Create an AI Gateway Certificate

`POST /v1/ai-gateways/{gatewayId}/certificates`

**Pre-release Endpoint**
This endpoint is currently in beta and is subject to change.

Creates a new certificate for the AI Gateway.

## Request body

- CreateAIGatewayCertificateRequest — **Pre-release Feature** This feature is currently in beta and is subject to change. A certificate holds a PEM-encoded certificate and its matching private key, used to terminate or originate TLS connections.
  - `name` string, required — Identifier for an AI Gateway entity. In some cases, this may be the entity name or ID.
  - `cert` string, required — PEM-encoded public certificate chain.
  - `key` string, required — PEM-encoded private key matching `cert`.
  - `cert_alt` string, nullable — PEM-encoded public certificate chain of the alternative certificate. It must use a different key algorithm than `cert`, and requires `key_alt` to be set.
  - `key_alt` string, nullable — PEM-encoded private key matching `cert_alt`. Requires `cert_alt` to be set.
  - `labels` PublicLabels — Public labels store information about an entity that can be used for filtering a list of objects. Public labels are intended to store **PUBLIC** metadata. Keys must be of length 1-63 characters, and cannot start with "kong", "konnect", "mesh", "kic", or "_".
  - `managed_by` ManagedBy — Stores information about what manages this entity, such as the tool or system responsible for its lifecycle (for example, `terraform`). Keys must be 1–63 characters long and start with an alphanumeric character.

## Response `201`

AI Gateway Certificate created successfully.

- AIGatewayCertificate — **Pre-release Feature** This feature is currently in beta and is subject to change. A certificate holds a PEM-encoded certificate and its matching private key, used to terminate or originate TLS connections.
  - `name` string, required — Identifier for an AI Gateway entity. In some cases, this may be the entity name or ID.
  - `cert` string, required — PEM-encoded public certificate chain.
  - `key` string, required — PEM-encoded private key matching `cert`.
  - `cert_alt` string, nullable — PEM-encoded public certificate chain of the alternative certificate. It must use a different key algorithm than `cert`, and requires `key_alt` to be set.
  - `key_alt` string, nullable — PEM-encoded private key matching `cert_alt`. Requires `cert_alt` to be set.
  - `labels` PublicLabels — Public labels store information about an entity that can be used for filtering a list of objects. Public labels are intended to store **PUBLIC** metadata. Keys must be of length 1-63 characters, and cannot start with "kong", "konnect", "mesh", "kic", or "_".
  - `managed_by` ManagedBy — Stores information about what manages this entity, such as the tool or system responsible for its lifecycle (for example, `terraform`). Keys must be 1–63 characters long and start with an alphanumeric character.
  - `id` string, uuid, required — Contains a unique identifier used for this resource.
  - `created_at` string, date-time, required — An ISO-8601 timestamp representation of entity creation date.
  - `updated_at` string, date-time, required — An ISO-8601 timestamp representation of entity update date.

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found
- `409` — Conflict
- `429` — Too Many Requests

---

[API](https://skmtc.net/kong/apis/konnect-api-go-sdk.md) · [All operations](https://skmtc.net/kong/apis/konnect-api-go-sdk/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/kong/konnect-api-go-sdk/revisions/b31b9b097e6d/schema)
