v8

latestOpenAPI 3.0.0raw.githubusercontent.com2026-01-23241216351.5 KB
SSHHostCertificates

Create

Create a new SSH Host Certificate

post/ssh_host_certificates

Headers

ngrok-versioninteger required

Request body

ssh_certificate_authority_idstring required

the ssh certificate authority that is used to sign this ssh host certificate

public_keystring required

a public key in OpenSSH Authorized Keys format that this certificate signs

principalsstring[]

the list of principals included in the ssh host certificate. This is the list of hostnames and/or IP addresses that are authorized to serve SSH traffic with this certificate. Dangerously, if no principals are specified, this certificate is considered valid for all hosts.

valid_afterstring

The time when the host certificate becomes valid, in RFC 3339 format. Defaults to the current time if unspecified.

valid_untilstring

The time when this host certificate becomes invalid, in RFC 3339 format. If unspecified, a default value of one year in the future will be used. The OpenSSH certificates RFC calls this valid_before.

descriptionstring

human-readable description of this SSH Host Certificate. optional, max 255 bytes.

metadatastring

arbitrary user-defined machine-readable data of this SSH Host Certificate. optional, max 4096 bytes.

Response

Create a new SSH Host Certificate

idstring

unique identifier for this SSH Host Certificate

uristring

URI of the SSH Host Certificate API resource

created_atstring

timestamp when the SSH Host Certificate API resource was created, RFC 3339 format

descriptionstring

human-readable description of this SSH Host Certificate. optional, max 255 bytes.

metadatastring

arbitrary user-defined machine-readable data of this SSH Host Certificate. optional, max 4096 bytes.

public_keystring

a public key in OpenSSH Authorized Keys format that this certificate signs

key_typestring

the key type of the public_key, one of rsa, ecdsa or ed25519

ssh_certificate_authority_idstring

the ssh certificate authority that is used to sign this ssh host certificate

principalsstring[]

the list of principals included in the ssh host certificate. This is the list of hostnames and/or IP addresses that are authorized to serve SSH traffic with this certificate. Dangerously, if no principals are specified, this certificate is considered valid for all hosts.

valid_afterstring

the time when the ssh host certificate becomes valid, in RFC 3339 format.

valid_untilstring

the time after which the ssh host certificate becomes invalid, in RFC 3339 format. the OpenSSH certificates RFC calls this valid_before.

certificatestring

the signed SSH certificate in OpenSSH Authorized Keys format. this value should be placed in a -cert.pub certificate file on disk that should be referenced in your sshd_config configuration file with a HostCertificate directive