- Support
- Integrations
- Certificates
Certificates
Oracle Cloud integration · 20 node(s).
00Overview
Issue and manage TLS certificates and private certificate authorities in Oracle Cloud straight from a flow — create certificates and CAs, list them and their versions, read the issued PEM bundles and CA-bundle contents, and move a certificate between compartments. Build and maintain CA bundles as trust stores, update descriptions, and retire resources by scheduling their deletion. Read a certificate or bundle's contents in one step so a later step can hand the PEM — and the private key when Oracle Cloud manages it — to a server, load balancer or downstream service.
Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.
01Connecting Certificates
- The node's Authentication field offers two methods. Connect Oracle Cloud (the default) uses a managed connection you set up once in Flomation, while API signing key (advanced) lets you supply raw OCI signing-key credentials yourself.
- For the managed path, open your environment's credentials in Flomation and add an Oracle Cloud connection: give it a name, enter your Tenancy OCID and home Region (both shown in the OCI Console under your tenancy details), then follow the guided steps to authorise it and run Test connection before saving.
- In the node, leave Authentication on Connect Oracle Cloud, pick your connection in the Oracle Cloud connection field, and set the Compartment OCID to the compartment that holds (or will hold) your certificates.
- To use a key you manage yourself instead, set Authentication to API signing key (advanced). In the OCI Console, open the profile menu (top‑right) → your user's settings → API Keys → Add API Key, upload a public key, and copy the Tenancy OCID, User OCID, Region and Key Fingerprint it shows.
- Store the matching private key PEM as a Flomation environment secret (e.g.
certificates_secret) and pick it in the node's Private Key (PEM) field, adding the Private Key Passphrase too if your key is encrypted.
| Field | Type | Details | |
|---|---|---|---|
| Authentication | string | Connect Oracle Cloud, API signing key (advanced) | |
| Oracle Cloud connection | credential | Pick a connected Oracle Cloud account | |
| Region | string | e.g. uk-london-1 | |
| Private Key (PEM) | secret | The API signing private key — full PEM, incl. BEGIN/END lines | |
| Private Key Passphrase | secret | Only if the key is encrypted (optional) | |
| Tenancy OCID | string | ocid1.tenancy.oc1..aaaa… | |
| User OCID | string | ocid1.user.oc1..aaaa… | |
| Key Fingerprint | string | aa:bb:cc:… fingerprint of the uploaded API key |
Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.
02Association
OCI Certificates: List Associations
oracle/certificates/association_list · Action
List the associations between certificate-related resources and the Oracle Cloud resources that use them. Optionally filter to a single certificate resource. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Certificate Resource OCID Filter | string | Only associations for this certificate/CA/CA-bundle OCID (optional) |
Returns: tool_result, associations, count, truncated, success, error
03Ca
OCI Certificates: Get CA Bundle Contents
oracle/certificates/ca_bundle_content_get · Action
Read a CA bundle's contents (the root and intermediate certificate PEM) from the certificates data plane by its OCID.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| CA Bundle OCID | string | Required | ocid1.cabundle.oc1..aaaa… |
Returns: tool_result, bundle, id, name, ca_bundle_pem, success, error
OCI Certificates: Create CA Bundle
oracle/certificates/ca_bundle_create · Action
Create a CA bundle — a named, PEM-encoded set of certificate-authority certificates (a trust store) in a compartment.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Name | string | Required | A unique name for the CA bundle within the compartment |
| CA Bundle (PEM) | text | Required | One or more certificates in PEM format, incl. BEGIN/END CERTIFICATE lines |
| Description | string | Optional |
Returns: tool_result, ca_bundle, id, lifecycle_state, success, error
OCI Certificates: Delete CA Bundle
oracle/certificates/ca_bundle_delete · Action
Delete a Certificates CA bundle by its OCID — the trusted CA-certificate collection is removed.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| CA Bundle OCID | string | Required | ocid1.certificateauthoritybundle.oc1..aaaa… of the CA bundle to delete |
Returns: tool_result, id, success, error
OCI Certificates: Get CA Bundle
oracle/certificates/ca_bundle_get · Action
Fetch a single CA bundle by its OCID — its name, description, compartment and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| CA Bundle OCID | string | Required | ocid1.cabundle.oc1..aaaa… |
Returns: tool_result, ca_bundle, id, lifecycle_state, success, error
OCI Certificates: List CA Bundles
oracle/certificates/ca_bundle_list · Action
List the CA bundles in a compartment. Optionally filter by exact name or lifecycle state, and cap the page size. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Name Filter | string | Only CA bundles with this exact name (optional) | |
| Lifecycle State | string | Filter by lifecycle state (optional) — choices: Creating, Active, Updating, Deleting, Deleted, Failed | |
| Page Size | string | Max items per page fetch (optional) |
Returns: tool_result, ca_bundles, count, truncated, success, error
OCI Certificates: Update CA Bundle
oracle/certificates/ca_bundle_update · Action
Partially update a CA bundle — change only the description or certificates (PEM) you supply; blank fields are left unchanged.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| CA Bundle OCID | string | Required | ocid1.certificateauthoritybundle.oc1..aaaa… — the CA bundle to update |
| Description | string | New description (leave blank to keep unchanged) | |
| CA Bundle (PEM) | text | Certificates in PEM format to include in the bundle (leave blank to keep unchanged) |
Returns: tool_result, ca_bundle, id, success, error
04Certificate
OCI Certificates: Create Certificate Authority
oracle/certificates/certificate_authority_create · Action
Create a private root certificate authority (CA) — OCI generates the signing key internally and protects it with the Vault (KMS) key you provide.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| CA Name | string | Required | A name for the certificate authority (unique in the compartment) |
| Subject Common Name | string | Required | e.g. My Internal Root CA |
| Vault (KMS) Key OCID | string | Required | ocid1.key.oc1..aaaa… used to protect the CA signing key |
| Description | string | Optional |
Returns: tool_result, certificate_authority, id, lifecycle_state, success, error
OCI Certificates: Get Certificate Authority
oracle/certificates/certificate_authority_get · Action
Fetch a single certificate authority (CA) by its OCID — its config, signing algorithm, KMS key and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Certificate Authority OCID | string | Required | ocid1.certificateauthority.oc1..aaaa… |
Returns: tool_result, certificate_authority, id, lifecycle_state, success, error
OCI Certificates: List Certificate Authorities
oracle/certificates/certificate_authority_list · Action
List the certificate authorities (CAs) in a compartment. Optionally filter by exact name or lifecycle state. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Name Filter | string | Only CAs with this exact name (optional) | |
| Lifecycle State | string | Filter by lifecycle state (optional) — choices: Creating, Active, Updating, Deleting, Deleted, Scheduling Deletion, Pending Deletion, Cancelling Deletion, Failed, Pending Activation |
Returns: tool_result, certificate_authorities, count, truncated, success, error
OCI Certificates: Schedule CA Deletion
oracle/certificates/certificate_authority_schedule_deletion · Action
Schedule a certificate authority (CA) for deletion, optionally at a future time.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Certificate Authority OCID | string | Required | ocid1.certificateauthority.oc1..aaaa… of the CA to schedule for deletion |
| Time of Deletion | string | Optional — when to delete, RFC 3339 (e.g. 2026-12-31T00:00:00Z) |
Returns: tool_result, id, success, error
OCI Certificates: Update Certificate Authority
oracle/certificates/certificate_authority_update · Action
Partially update a certificate authority — change only the description you supply; a blank description is left unchanged and the CA's configuration, rules and versions are preserved.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Certificate Authority OCID | string | Required | ocid1.certificateauthority.oc1..aaaa… — the CA to update |
| Description | string | New description (leave blank to keep unchanged) |
Returns: tool_result, certificate_authority, id, success, error
OCI Certificates: Get Certificate Bundle
oracle/certificates/certificate_bundle_get · Action
Read an issued certificate bundle by its OCID — certificate PEM, chain, serial, version and the private key when OCI manages it.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Certificate OCID | string | Required | ocid1.certificate.oc1..aaaa… |
| Version Number | string | Optional — a specific certificate version (defaults to the current version) |
Returns: tool_result, bundle, success, error
OCI Certificates: Change Certificate Compartment
oracle/certificates/certificate_change_compartment · Action
Move a certificate into a different compartment — the certificate keeps its OCID, only its compartment placement changes.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Certificate OCID | string | Required | ocid1.certificate.oc1..aaaa… (the certificate to move) |
| Destination Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (where to move the certificate) |
Returns: tool_result, id, destination_compartment_id, success, error
OCI Certificates: Create Certificate
oracle/certificates/certificate_create · Action
Create a certificate issued by one of your private certificate authorities (CAs) — set the common name, profile and key/signature algorithms.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Certificate Name | string | Required | Unique within the compartment |
| Issuer CA OCID | string | Required | ocid1.certificateauthority.oc1..aaaa… (the private CA that signs it) |
| Common Name | string | Required | e.g. www.example.com — the certificate subject CN |
| Certificate Profile | string | Required | How the certificate will be used — choices: TLS server or client, TLS server, TLS client, TLS code sign |
| Subject Alternative DNS Names | string | Comma-separated DNS names, e.g. example.com, api.example.com (optional) | |
| Key Algorithm | string | Defaults to the service default (optional) — choices: RSA 2048, RSA 4096, ECDSA P-256, ECDSA P-384 | |
| Signature Algorithm | string | Defaults to the service default (optional) — choices: SHA-256 with RSA, SHA-384 with RSA, SHA-512 with RSA, SHA-256 with ECDSA, SHA-384 with ECDSA, SHA-512 with ECDSA | |
| Version Name | string | A name for this first version (optional) | |
| Description | string | Optional | |
| Freeform Tags (JSON) | string | {"env":"prod"} (optional) |
Returns: tool_result, certificate, id, lifecycle_state, success, error
OCI Certificates: Get Certificate
oracle/certificates/certificate_get · Action
Fetch a single certificate by its OCID — its configuration, issuing CA, algorithms, current version and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Certificate OCID | string | Required | ocid1.certificate.oc1..aaaa… |
Returns: tool_result, certificate, id, lifecycle_state, success, error
OCI Certificates: List Certificates
oracle/certificates/certificate_list · Action
List the certificates in a compartment. Optionally filter by exact name or lifecycle state. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Name Filter | string | Only certificates with this exact name (optional) | |
| Lifecycle State | string | Filter by lifecycle state (optional) — choices: Creating, Active, Updating, Deleting, Deleted, Scheduling Deletion, Pending Deletion, Cancelling Deletion, Failed |
Returns: tool_result, certificates, count, truncated, success, error
OCI Certificates: Schedule Certificate Deletion
oracle/certificates/certificate_schedule_deletion · Action
Schedule a certificate for deletion by its OCID — it moves to PENDING_DELETION and is deleted after the retention period.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Certificate OCID | string | Required | ocid1.certificate.oc1..aaaa… of the certificate to schedule for deletion |
| Time of Deletion | string | Optional RFC3339, e.g. 2026-12-31T00:00:00Z — when to delete (defaults to the retention period) |
Returns: tool_result, id, success, error
OCI Certificates: Update Certificate
oracle/certificates/certificate_update · Action
Partially update a certificate — change only the description you supply; a blank description leaves the certificate unchanged.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Certificate OCID | string | Required | ocid1.certificate.oc1..aaaa… — the certificate to update |
| Description | string | New description (leave blank to keep unchanged) |
Returns: tool_result, certificate, id, success, error
OCI Certificates: List Certificate Versions
oracle/certificates/certificate_version_list · Action
List the versions of a certificate — each version's number, serial number, rotation stages and creation time. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Certificate OCID | string | Required | ocid1.certificate.oc1..aaaa… |
Returns: tool_result, versions, count, truncated, success, error
05Notes & Limitations
Behaviours and constraints worth knowing before you build with these nodes.
- Certificates are issued by your own private certificate authorities, so they are trusted only by clients that already carry the matching CA bundle and are not recognised by public browsers or the wider internet.
- Creating a certificate authority requires an existing Vault (KMS) key to protect the CA's signing key, so provision that key before you build the CA.
- Create actions return as soon as Oracle Cloud accepts the request while the certificate or CA finishes provisioning in the background, so poll its state with the matching Get action before a later step relies on it being
ACTIVE. - Deleting a certificate or certificate authority is a scheduled soft-delete — the resource moves to
PENDING_DELETIONand is removed only after its retention period, leaving a window to cancel rather than disappearing at once. - List actions return only the resources in the single compartment you name and page through them up to an internal cap, so resources in other compartments will not appear and very large compartments may be truncated — filter by name or lifecycle state to narrow them.