Download Certificates by Id
Returns a ZIP archive stream containing one {n}_{userDn}_ClientCert.pem entry per certificate
Get Single Certificate
List Certificates
Optionalusername: stringList Active Certificates
The most recently issued certificate for each Client UID / User DN pair
List Expired Certificates
List Replaced Certificates
List Revoked Certificates
Probe whether the TAK Server accepts the credentials this API instance was created with
The X509 filter runs on every request and rethrows on failure, so GET /Marti/api/version
(an anonymous, DB-free endpoint returning a short string) is the cheapest authoritative
check - unlike validate it reflects the server's actual enforcement (e.g. whether
x509checkRevocation is enabled) and requires no admin credentials. An expired client
certificate is rejected during the TLS handshake and surfaces as reason: 'tls'.
Only authentication failures are returned as a verdict - any other error (server unreachable, unexpected status) is rethrown so it is not mistaken for a rejection
Revoke Single Certificate
Revoke Certificates by Id
Validate a PEM encoded client certificate against local expiry and the TAK Server revocation record
Expiry is evaluated locally from the certificate. Revocation is looked up via the
Certificate Admin API using the same SHA-256 fingerprint the TAK Server X509Authenticator
consults - get(hash) first (a single cached row) falling back to the user's certificate
list when the TAK Server answers 500, which is how it reports an unknown hash.
Note: The TAK Server only enforces revocation when auth.x509checkRevocation (or
x509TokenAuth) is enabled in CoreConfig - revoked reports the stored state regardless
Delete Certificates by Id
TAK Server Docs.