certmate-cli
The CertMate SSL certificate
lifecycle from your terminal — built on certmate-sdk.
pip install certmate-cli
export CERTMATE_URL=http://localhost:8000
export CERTMATE_TOKEN=...
certmate cert create app.example.com --dns cloudflare --wait
certmate cert ls
certmate cert info app.example.com
certmate cert renew app.example.com --force
certmate cert create app.example.com --dns cloudflare --dry-run
certmate audit verify
Pulling certificates onto a host
cert download fetches one file at a time, so a target server can pull
exactly what it deploys instead of the certificate manager pushing to it:
certmate cert download app.example.com --file fullchain -o /etc/ssl/certs/app.pem
certmate cert download app.example.com --file privkey -o /etc/ssl/private/app.key
Files are created 0600, with the mode set at creation rather than after the write, so the key is never briefly world-readable.
This is worth preferring over pushing when the manager would otherwise need
credentials on every target host. Give each host an API key scoped to its own
domain and run the pull on a timer: the host needs no inbound access, and the
manager holds no credentials for it. cert, chain and fullchain are
readable by a viewer-role key; privkey, combined and pfx need operator.
--file privkey --key-format pkcs1 serves the legacy
BEGIN RSA PRIVATE KEY form for stacks that reject certbot's PKCS#8.
--bundle zip or --bundle json fetch the whole certificate instead, and
-o - writes to stdout.
Connection comes from --url/--token or CERTMATE_URL/CERTMATE_TOKEN.
Prefer the CERTMATE_TOKEN environment variable over --token: command-line
arguments are visible to other local processes (ps) and shell history.
Metadata
Release files for certmate-cli 0.1.5
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| certmate_cli-0.1.5.tar.gz | 10.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| certmate_cli-0.1.5-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 19.8 kB
Release files / certmate_cli-0.1.5.tar.gz
| Download URL | certmate_cli-0.1.5.tar.gz |
|---|---|
| Size | 10.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
926c5db9b9f4963f7ea031fff2cb3a7a206b7e767cf2adec819aaf14f4a2bb6e
|
|
BLAKE2b-256 checksum How to use checksums |
4808d106d84df69401fb6dbeede678b72de4a576217250e916570bfc3e2cb4dd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 16, 2026.
Transparency logRelease files / certmate_cli-0.1.5-py3-none-any.whl
| Download URL | certmate_cli-0.1.5-py3-none-any.whl |
|---|---|
| Size | 9.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
031cc36bf439b3d3861889b1bb1c28ceaa5b08a9427faaf95602bd34e2efd448
|
|
BLAKE2b-256 checksum How to use checksums |
414d396a2548954f065bb9519f30165d298118ed3991943b4ec778cd2aba76ac
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 16, 2026.
Transparency log