Metadata-Version: 2.5
Name: certmate-sdk
Version: 0.1.5
Summary: Thin Python client for the CertMate REST API
Project-URL: Homepage, https://github.com/fabriziosalmi/certmate
Project-URL: Source, https://github.com/fabriziosalmi/certmate/tree/main/clients/certmate-sdk
Author-email: Fabrizio Salmi <fabrizio.salmi@gmail.com>
License: MIT
Keywords: acme,certificates,certmate,letsencrypt,sdk,tls
Classifier: Development Status :: 4 - Beta
Classifier: Intended Audience :: Developers
Classifier: Intended Audience :: System Administrators
Classifier: License :: OSI Approved :: MIT License
Classifier: Operating System :: OS Independent
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.9
Classifier: Programming Language :: Python :: 3.10
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Python :: 3.13
Classifier: Topic :: Internet :: WWW/HTTP
Classifier: Topic :: Security
Classifier: Topic :: System :: Systems Administration
Requires-Python: >=3.9
Requires-Dist: httpx>=0.24
Description-Content-Type: text/markdown

# certmate-sdk

A thin, dependency-light Python client for the [CertMate](https://github.com/fabriziosalmi/certmate) REST API.

```python
from certmate import Client

with Client("https://certmate.example.com", token="...") as c:
    job = c.create_certificate("app.example.com", dns_provider="cloudflare", wait=True)
    for cert in c.list_certificates():
        print(cert.domain, cert.days_until_expiry, cert.has_expired())
    print(c.audit_verify()["ok"])
```

`base_url`/`token` fall back to `CERTMATE_URL` / `CERTMATE_TOKEN`. The only
runtime dependency is `httpx` — no server code, no certbot.

## Asking whether a certificate has expired

Use `cert.has_expired()`, not `cert.days_until_expiry <= 0`.

`days_until_expiry` is a whole number of days and rounds down, so a
certificate with 23 hours of life left reports `0`, and that comparison calls
it expired. CertMate's own dashboard did exactly that until server 2.32.2, and
on a private CA it was every certificate: step-ca issues 24-hour certificates
by default.

`has_expired()` returns the server's own answer on API contract 2.2 and later
(`cert.expired`, with `cert.seconds_left` beside it for the real remaining
life). Against an older server it returns what a day count can honestly
support: `True` below zero, `False` above it, and `None` on exactly zero,
which is the one day the number cannot tell apart. `None` also means the
server could not parse the certificate, which is neither expired nor fine.
