Read your certificate inventory, then submit domains and organizations for validation
Connect DigiCert and Luumen can answer questions about your CertCentral account without you opening the console: account settings, custom order fields, discovery scan templates, keys, agent ports, and alert counts. When something needs to change — a domain submitted for validation, tags added to certificates, a new organization — Luumen shows the exact call first and waits for your approval.
ReadGet Container by IDGet details about a specific container using its ID.
ReadGet Container ChildrenList all child containers for a parent container.
ReadGet Container IP RulesRetrieve a list of existing IP restriction rules in a CertCentral account.
ReadGet Container Order OrganizationsList all organizations assigned to a container.
ReadGet Container Product LimitsGet information about the limits and settings for a container's enabled products.
ReadGet Container RolesRetrieve all access roles available to a container.
ReadGet Container Template DetailsGet details about a template in a container.
ReadGet Domain DCV InformationRetrieve domain DCV (Domain Control Validation) information from DigiCert.
ReadGet Domain DCV EmailsRetrieve email addresses that receive validation emails from DigiCert for the email domain control validation (DCV) method.
ReadGet Domain Expiration CountGet the number of domains in your account with expired or expiring OV or EV domain validations.
ReadGet Domain Validation TypeList available validation types for domains.
ReadGet Finance BalanceView the current balance of your DigiCert account.
ReadGet Finance Balance HistoryList balance adjustment history for your DigiCert account.
ReadGet Remote Service InformationRetrieve remote service information from DigiCert Document Manager CSC API.
ReadGet API Key DetailsRetrieve detailed information about an API key.
ReadGet MPKI VersionQuery the TLM application version from DigiCert MPKI API.
ReadGet Order Certificate Status ChangesList orders that changed status during a given time frame.
ReadGet Organization DetailsRetrieve detailed information about an organization from DigiCert.
ReadGet Organization Contact InfoRetrieve organization and technical contact details for a specific organization.
ReadGet Recent OrganizationsRetrieve the three most recently used organizations from your CertCentral account.
ReadGet Organization ValidationGet validation details for an organization.
ReadGet Organization Validation TypeList available validation types for organizations.
ReadGet Product by NameGet information about a product by its name identifier.
ReadGet Product Platform Certificate Format MappingList the certificate format that is returned for a particular server platform.
ReadGet Product PricingRetrieve a comprehensive list of product prices available under your DigiCert account.
ReadGet Remote Service InfoRetrieve information about DigiCert's Document Manager CSC (Cloud Signature Consortium) remote service.
ReadGet Order ReportRetrieve a CSV report of all certificate orders.
ReadGet Report Order ExpiringGet the number of orders and certificates that expire within 0-30, 30-60, and 60-90 days from now.
ReadGet Report Request SummaryGet total requests and requests by type for your account.
ReadGet Scan SubdomainsRetrieve all subdomains included in a DigiCert Discovery scan.
ReadGet User DetailsRetrieve details about a specific user in CertCentral.
ReadCheck Username AvailabilityCheck if a username is available in DigiCert.
ReadList API Access RolesRetrieve a list of available API access roles.
ReadList API KeysRetrieve a list of API keys and ACME URLs.
ReadList Certificate Filter ValuesRetrieve available filter values for certificate attributes from DigiCert Discovery API.
ReadList Certificate OrdersList all certificate orders in your DigiCert account.
ReadList CertificatesList all certificates discovered by DigiCert Discovery scans.
ReadList ContainersRetrieve a list of all containers (divisions) in your DigiCert account.
ReadList Container TemplatesList all templates that can be used when creating containers.
ReadList Domain DCV MethodsRetrieve available domain control validation (DCV) methods for domains.
ReadList DomainsList all domains in your CertCentral account.
ReadList Intermediate CertificatesRetrieve a list of intermediate certificates.
ReadList LocalesRetrieve a list of available locales.
ReadList Organization Potential ApproversList all users and contacts that can be validated as verified contacts (also called EV approvers).
ReadList OrganizationsRetrieve all organizations in your DigiCert account.
ReadList PermissionsList all permissions for the authenticated user.
ReadList Available ProductsList all products available to your CertCentral account.
ReadList SensorsList all sensors used for network scanning in DigiCert Discovery.
ReadList Service UsersList all DigiCert service users (API-only users).
ReadList CertCentral UsersRetrieve a list of CertCentral account users.
ReadValidate VMC Encoded LogoValidate if an SVG file format is compatible with Verified Mark Certificate (VMC) or Common Mark Certificate (CMC) requirements.
ReadValidate VMC/CMC Logo FormatValidate SVG logo format for Verified Mark Certificates (VMC) or Common Mark Certificates (CMC).
ReadVerify TemplateVerify a certificate template structure against DigiCert's validation rules.
WriteAdd Tags to CertificateAdd custom tags to one or more certificates for categorization. Approval by default
WriteCreate API KeyCreate a new API key with specified permissions. Approval by default
WriteCreate AuthKeyCreate a new AuthKey for account authentication. Approval by default
WriteCreate Container IP RulesAdd an IP restriction rule to a CertCentral account. Approval by default
WriteCreate OrganizationCreate a new organization in your DigiCert CertCentral account. Approval by default
WriteCreate Organization ValidationSubmit an organization for validation and add verified contacts for specific product types. Approval by default
WriteDelete Account AuthKeyDelete your account's AuthKey. Approval by default
WriteDelete Certificate from DiscoveryDelete certificates from DigiCert Discovery inventory. Approval by default
WriteDelete DomainDelete a domain with the given ID. Approval by default
WriteDelete SSH KeyDelete SSH keys from DigiCert Discovery. Approval by default
WriteDelete Discovery EndpointsDelete one or more endpoints from the Discovery API. Approval by default
WriteResend User Create EmailResend the create user email to a user. Approval by default
WriteSubmit Domain for ValidationSubmit a domain for validation with specified validation types. Approval by default
WriteUpdate Account EmailsUpdate account notification and emergency email addresses. Approval by default
WriteUpdate ContainerEdit a container's details including name and description. Approval by default
WriteUpdate Container Allowed Domain NamesUpdate a container's allowed domains. Approval by default
WriteUpdate Container User AssignmentsUpdate a container's user assignments. Approval by default
WriteActivate DomainActivate a domain in DigiCert CertCentral. Approval by default
WriteResend Domain DCV EmailsResend domain control validation (DCV) emails for a domain. Approval by default
WriteUpdate API KeyEdit an API key's name or access role restrictions. Approval by default
WriteUpdate API Key StatusActivate, deactivate, or revoke a DigiCert API key. Approval by default
WriteUpdate Notification SettingsUpdate CertCentral account notification settings. Approval by default
WriteUpdate OrganizationUpdate an organization's details in your DigiCert CertCentral account. Approval by default
WriteActivate OrganizationActivate an organization in DigiCert CertCentral. Approval by default
WriteUpdate Organization ContactUpdate or replace organization contact and technical contact for an organization. Approval by default
WriteDeactivate OrganizationDeactivate an organization in DigiCert CertCentral. Approval by default
WriteUpdate Renewal Email PreferenceEnable or disable renewal notifications for SSL/TLS certificates discovered in DigiCert Discovery. Approval by default
WriteUpdate ReportUpdate an existing report’s configuration. Approval by default
WriteUpdate User ProfileUpdate a user's profile information in CertCentral. Approval by default
WriteUpdate User Container AssignmentsUpdate container (division) assignments for a user. Approval by default
WriteUpdate User RoleChange a user's access role in CertCentral. Approval by default
One prompt, start to finish
What a governed Digicert run looks like inside Luumen.
Questions
How does LuumenAI connect to Digicert?
Authorize once with API token. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.
Can LuumenAI change things in Digicert on its own?
Read actions answer immediately. Anything that writes — add tags to certificate, create api key, create authkey, create container ip rules, and more — is shown as a plan and requires approval by default, including the 7 actions classified as destructive. Administrators configure that per tool, so you decide exactly which actions can ever run unattended.
Who gets access to the integration?
You decide. Actions are granted per agent, skill, and team, and per environment — production is not staging. Read access can be broad while writes stay narrow.
Is there an audit trail?
Every call to Digicert — read or write, approved or declined — is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.