Skip to content

Integrates with account required

HashiCorp Vault PKI

Vault PKI is a first-class private CA. The connector lists secret mounts and issuers, discovers roles, issues or signs CSRs, reads issued certs back, revokes by serial, fetches CRLs, and records accessor IDs. Tokens are encrypted and never returned to the UI.

Verification: test_verified. Connection: unknown. Credentials: none. Live E2E: no.

Vault address and token for a disposable PKI mount are not configured.

What sslcertificates.io can do

Vault PKI is a first-class private CA. The connector lists secret mounts and issuers, discovers roles, issues or signs CSRs, reads issued certs back, revokes by serial, fetches CRLs, and records accessor IDs. Tokens are encrypted and never returned to the UI. Capabilities: discover_mounts, discover_roles, issue, sign_csr, revoke, crl, short_lived. Authentication uses token.

Required permissions

A token or AppRole that can list PKI mounts, read issuers, and issue/revoke on selected roles. Never root.

Setup

Open Dashboard → Integrations → HashiCorp Vault PKI. Enter the credentials described on this page. Values are encrypted at rest and never shown again. Run Test connection. Discovery runs only after authentication succeeds. Select a discovered resource. Do not paste opaque IDs unless the provider cannot enumerate them. Perform the certificate or notification action, then confirm the external system matches. Disconnect removes stored credentials and owned test resources created by sslcertificates.io.

Known limitations

sslcertificates.io does not store Vault's unseal keys. Short-lived certs must be redeployed by the platform before TTL expiry.

Official sources

Fact checked 2026-09-20. https://developer.hashicorp.com/vault/api-docs/secret/pki HashiCorp Vault PKI is a trademark of its owner. sslcertificates.io is not a partner or certified reseller unless a written agreement exists.

Capabilities

discover_mounts discover_roles issue sign_csr revoke crl short_lived

Connect

Create an account to connect

HashiCorp Vault PKI is a trademark of its owner. sslcertificates.io is not a partner or certified reseller unless a written agreement exists.