Digicert for AI agents
DigiCert issues and manages TLS/SSL certificates, PKI, and digital signing services that secure websites, devices, and software, used by IT and security teams protecting company infrastructure. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Digicert.
Check a certificate's security rating
Pull the security rating for a domain's certificate before a renewal decision.
List domains under an account
Read the domains registered to an organization to prep an inventory report.
Approve before deleting a domain
Require sign-off before removing a domain from discovery, since it stops future certificate monitoring on it.
101 Digicert actions, graded by risk.
Every Digicert action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
66Look things up. Allowed by default.
- digicert.get_infoGet Remote Service Information
- digicert.get_userGet User Details
- digicert.list_usersList CertCentral Users
- digicert.get_accountGet Account Details
- digicert.get_auth_keyGet AuthKey Details
- digicert.list_domainsList Domains
- digicert.list_localesList Locales
- digicert.list_sensorsList Sensors
- digicert.list_api_keysList API Keys
- digicert.list_productsList Available Products
- digicert.get_cloud_scanGet Cloud Scan Details
- digicert.get_domain_dcvGet Domain DCV Information
- digicert.get_key_by_keyGet API Key Details
- digicert.get_alert_countGet Alert Count
- digicert.list_containersList Containers
- digicert.get_mpki_versionGet MPKI Version
write
29Create and change things. Allow, or ask the user first.
- digicert.update_keyUpdate API Key
- digicert.update_userUpdate User Profile
- digicert.update_reportUpdate Report
- digicert.create_api_keyCreate API Key
- digicert.create_auth_keyCreate AuthKey
- digicert.create_scan_listList Scan Templates
- digicert.update_containerUpdate Container
- digicert.update_user_roleUpdate User Role
- digicert.update_key_statusUpdate API Key Status
- digicert.create_organizationCreate Organization
- digicert.update_organizationUpdate Organization
- digicert.update_notificationsUpdate Notification Settings
- digicert.update_account_emailsUpdate Account Emails
- digicert.update_domain_activateActivate Domain
- digicert.add_tags_to_certificateAdd Tags to Certificate
- digicert.update_domain_dcv_emailsResend Domain DCV Emails
destructive
6Delete, cancel or archive. Ask first, or deny outright.
- digicert.delete_keyDelete SSH Key
- digicert.delete_domainDelete Domain
- digicert.delete_certificateDelete Certificate from Discovery
- digicert.delete_account_auth_keyDelete Account AuthKey
- digicert.delete_reports_endpointsDelete Discovery Endpoints
- digicert.update_organization_deactivateDeactivate Organization
Digicert in three steps.
- 01Your users connect DigicertThey add their Digicert api key on Arc0 Connect, under your brand. It goes straight into the vault.
- 02You set the rulesReads run, writes like “create API Key” can wait for the user, and “delete SSH Key” can be denied outright.
- 03Any agent can actYour agent calls Digicert through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('digicert', { read: 'allow', write: 'ask', // create_api_key destructive: 'deny', // delete_key }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Digicert connects.
Users add their Digicert api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
The same Digicert connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- API key
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Digicert from any agent.
More security and identity apps.
Digicert and Arc0, answered.
Can I use Digicert with Claude, ChatGPT or Cursor?
Yes. Connect Digicert to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Digicert actions you allow.
How do users connect Digicert?
Users add their Digicert api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
Which Digicert actions can my agent take?
101 in total: 66 read, 29 write and 6 destructive, such as “create API Key”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in Digicert?
Yes. Actions like “delete SSH Key” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call Digicert too?
Yes. The same Digicert connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Digicert into your agent.
Your users connect Digicert once, under your brand. Your agent gets 101 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan