Digicert for AI agents

DigiCert issues and manages TLS/SSL certificates, PKI, and digital signing services that secure websites, devices, and software, used by IT and security teams protecting company infrastructure. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Security and identityAPI keyMCP + RESTdigicert.com
AUDIT LOG · DIGICERTPOLICY: acme-support
09:41:07 · claude · u_8f2read
digicert.list_users
List CertCentral Users✓ allowed · 212ms
09:41:08 · claude · u_8f2read
digicert.get_info
Get Remote Service Information✓ allowed · 164ms
09:41:09 · claude · u_8f2write
digicert.create_api_key
Create API Key✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
digicert.delete_key
Delete SSH Key✕ blocked · policy: deny
EVERY DIGICERT CALL, ON THE RECORD
01 · USE CASES

What agents do in Digicert.

01

Check a certificate's security rating

Pull the security rating for a domain's certificate before a renewal decision.

02

List domains under an account

Read the domains registered to an organization to prep an inventory report.

03

Approve before deleting a domain

Require sign-off before removing a domain from discovery, since it stops future certificate monitoring on it.

02 · ACTIONS

101 Digicert actions, graded by risk.

Every Digicert action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

66

Look things up. Allowed by default.

  • digicert.get_info
    Get Remote Service Information
  • digicert.get_user
    Get User Details
  • digicert.list_users
    List CertCentral Users
  • digicert.get_account
    Get Account Details
  • digicert.get_auth_key
    Get AuthKey Details
  • digicert.list_domains
    List Domains
  • digicert.list_locales
    List Locales
  • digicert.list_sensors
    List Sensors
  • digicert.list_api_keys
    List API Keys
  • digicert.list_products
    List Available Products
  • digicert.get_cloud_scan
    Get Cloud Scan Details
  • digicert.get_domain_dcv
    Get Domain DCV Information
  • digicert.get_key_by_key
    Get API Key Details
  • digicert.get_alert_count
    Get Alert Count
  • digicert.list_containers
    List Containers
  • digicert.get_mpki_version
    Get MPKI Version
+ 50 MORE

write

29

Create and change things. Allow, or ask the user first.

  • digicert.update_key
    Update API Key
  • digicert.update_user
    Update User Profile
  • digicert.update_report
    Update Report
  • digicert.create_api_key
    Create API Key
  • digicert.create_auth_key
    Create AuthKey
  • digicert.create_scan_list
    List Scan Templates
  • digicert.update_container
    Update Container
  • digicert.update_user_role
    Update User Role
  • digicert.update_key_status
    Update API Key Status
  • digicert.create_organization
    Create Organization
  • digicert.update_organization
    Update Organization
  • digicert.update_notifications
    Update Notification Settings
  • digicert.update_account_emails
    Update Account Emails
  • digicert.update_domain_activate
    Activate Domain
  • digicert.add_tags_to_certificate
    Add Tags to Certificate
  • digicert.update_domain_dcv_emails
    Resend Domain DCV Emails
+ 13 MORE

destructive

6

Delete, cancel or archive. Ask first, or deny outright.

  • digicert.delete_key
    Delete SSH Key
  • digicert.delete_domain
    Delete Domain
  • digicert.delete_certificate
    Delete Certificate from Discovery
  • digicert.delete_account_auth_key
    Delete Account AuthKey
  • digicert.delete_reports_endpoints
    Delete Discovery Endpoints
  • digicert.update_organization_deactivate
    Deactivate Organization
03 · HOW IT WORKS

Digicert in three steps.

  1. 01Your users connect DigicertThey add their Digicert api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “create API Key” can wait for the user, and “delete SSH Key” can be denied outright.
  3. 03Any agent can actYour agent calls Digicert through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('digicert', {
  read: 'allow',
  write: 'ask',        // create_api_key
  destructive: 'deny',  // delete_key
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Digicert connects.

Users add their Digicert api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same Digicert connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Digicert from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Digicert and Arc0, answered.

Q01

Can I use Digicert with Claude, ChatGPT or Cursor?

Yes. Connect Digicert to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Digicert actions you allow.

Q02

How do users connect Digicert?

Users add their Digicert api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which Digicert actions can my agent take?

101 in total: 66 read, 29 write and 6 destructive, such as “create API Key”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Digicert?

Yes. Actions like “delete SSH Key” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Digicert too?

Yes. The same Digicert connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Digicert into your agent.

Your users connect Digicert once, under your brand. Your agent gets 101 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan