v1

latestOpenAPI 3.0.1CC BY-NC-SA 3.0 US2026-07-145251,1312.6 MB
X.509 Authentication

Create One X.509 Certificate for One Database User

Generates one X.509 certificate for the specified MongoDB user. Atlas manages the certificate and MongoDB user that belong to one project.

To get MongoDB Cloud to generate a managed certificate for a database user, set "x509Type" : "MANAGED" on the desired MongoDB Database User.

If you are managing your own Certificate Authority (CA) in Self-Managed X.509 mode, you must generate certificates for database users using your own CA.

post/api/atlas/v2/groups/{groupId}/databaseUsers/{username}/certs

Path parameters

groupIdstring required
Example:32b6e34b3d91647abb20e7b8

Unique 24-hexadecimal digit string that identifies your project. Use the /groups endpoint to retrieve all projects to which the authenticated user has access.

NOTE: Groups and projects are synonymous terms. Your group id is the same as your project id. For existing groups, your group/project id remains the same. The resource and corresponding endpoints use the term groups.

usernamestring required

Human-readable label that represents the MongoDB database user account for whom to create a certificate.

Query parameters

envelopeboolean

Flag that indicates whether Application wraps the response in an envelope JSON object. Some API clients cannot access the HTTP response headers or status code. To remediate this, set envelope=true in the query. Endpoints that return a list of results use the results object as an envelope. Application adds the status parameter to the response body.

prettyboolean

Flag that indicates whether the response body should be in the prettyprint format.

Response

This endpoint returns a PEM file with the certificate and private key.