Know of an official OpenAPI document? Contribute it →
For Agents
Request, renew, revoke, and search digital certificates and manage the applications that own them for the Digitaal Vlaanderen DCBaaS certificate service. Authenticated with a per-environment bearer token.
Use for: I need to renew a certificate before it expires, Request a new certificate for my application, Revoke a compromised certificate, Search for certificates belonging to an application
Not supported: Does not handle TLS termination, DNS hosting, or certificate signing outside DCBaaS. Use for DCBaaS certificate lifecycle and application management only.
The DCBaaS API automates digital certificate lifecycle management for Digitaal Vlaanderen's certificate service. It requests, renews, revokes, and searches certificates, and registers, updates, delegates, and removes the applications that own them. The API exists so that shortening certificate lifecycles no longer forces manual replacement through the web portal. Calls are authenticated with a bearer token obtained from the environment-specific token endpoint.
Install Jentic One Beta
Jentic One is a self-hosted execution layer for AI agents. It lets your agent call the DCBaas API, or any other public or private API you need. You set the rules, the agent never sees your credentials, and every call is logged.
Two steps, two machines. Install the instance in a safe environment, then register your agent from wherever it runs.
Step 1: Jentic One Host machine
# On the machine that will host your Jentic One instance:
curl -fsSL "https://jentic.com/install.sh?src=apis&api=%2Fapis%2Fextapi.dcb.vlaanderen.be%2Fdcbaas" | shStep 2: Agent machine
# On the machine where your agent runs (keep this separate from the instance):
curl -fsSL "https://jentic.com/install.sh?src=apis&api=%2Fapis%2Fextapi.dcb.vlaanderen.be%2Fdcbaas" | sh
jentic register # connects your agent to your Jentic One instanceJentic One is in public beta. The setup above keeps your agent separate from the instance, which is what you want before using real credentials: an agent running as the same OS user as Jentic One can read its stored keys directly. Just evaluating? A single local install is fine to start. See the secure deployment guide for the tiers.
What an agent can do with DCBaas API.
Request new digital certificates for a registered application
Renew certificates before they expire to keep services trusted
Revoke certificates that should no longer be trusted
Search existing certificates by their attributes
Register applications that own certificates and delegate ownership to another party
Update or remove application registrations as teams change
Patterns agents use DCBaas API for, with concrete tasks.
★ Agent-Driven Certificate Renewal
An AI agent connected through Jentic can keep short-lived certificates current without a developer wiring DCBaaS auth and juggling the production, test, and development hosts. The agent searches for certificates nearing expiry, renews each one, and confirms the result, running on a schedule so manual replacement through the portal is no longer needed. Jentic injects the bearer token at call time so the credential never reaches the agent.
Search for certificates expiring soon, renew each one, and confirm the renewal succeeded
Certificate Revocation on Compromise
When a key is suspected compromised, an application can revoke the affected certificate immediately rather than waiting for a manual portal change. The agent locates the certificate by its attributes and revokes it, closing the trust window quickly. This supports incident-response runbooks that must act on certificates programmatically.
Search for the certificate tied to an application, then revoke it and verify its status
Application Onboarding
Teams bringing a new service online register it as an application in DCBaaS before requesting certificates. The agent adds the application, requests its first certificate, and can delegate ownership to the team that will operate it. This keeps certificate ownership mapped to the right application as an estate grows.
Register a new application, request a certificate for it, then delegate the application to the owning team
10 endpoints — the dcbaas api automates digital certificate lifecycle management for digitaal vlaanderen's certificate service.
METHOD
PATH
DESCRIPTION
/certificate/add
Request a new certificate
/certificate/renew
Renew an existing certificate
/certificate/revoke
Revoke a certificate
/certificate/search
Search certificates
/application/add
Register a new application
/application/delegate
Delegate an application to another party
/op/v1/token
Obtain a bearer token for the chosen environment
/certificate/add
Request a new certificate
/certificate/renew
Renew an existing certificate
/certificate/revoke
Revoke a certificate
/certificate/search
Search certificates
/application/add
Register a new application
/application/delegate
Delegate an application to another party
/op/v1/token
Obtain a bearer token for the chosen environment
This API is usable in Jentic One now. Its AI-readiness score against Jentic's framework shows where it stands today and where improvements would make it even easier for agents to use.
Base layer of spec validity and structural soundness.
Aggregated quality score from linter diagnostics, weighted by severity.
Percentage of `$ref` references that resolve successfully.
Checks whether the API description parses successfully and conforms to its declared specification (e.g., OpenAPI).
Structural correctness score based on schema issues using logarithmic dampening.
Clarity, completeness, and ingestion readiness for developers and tooling.
How richly the API is illustrated with examples.
Percentage of examples that conform to their schemas.
Percentage of operations with complete response definitions (success, client error, server error).
Health of API ingestion, bundling, and resolution within Jentic pipelines.
Semantic breadth, depth, and agent comprehension for AI systems.
Coverage of descriptions across API elements.
Coverage of RFC 9457 Problem Details for error responses.
Coverage, uniqueness, and casing consistency of operationIds for AI inference.
Coverage of summaries across operations/tags/info.
Functional utility, complexity comfort, and AI orchestration readiness.
Agent comfort level based on API operational and structural complexity.
Trust, risk posture, and security compliance.
Average quality of security schemes based on authentication method strength (weakest link for OAuth2).
Findability, semantic richness, and reasoning readiness.
Clarity and depth of descriptions across API elements.
Score it yourself
Every API in the directory is allowlisted, so you can re-score it with no key required.
npx @jentic/api-scorecard-cli score <openapi-url>What agents get from Jentic-routed access to this vendor.
Setup
Wiring DCBaaS by hand means requesting a bearer token from the correct environment's auth server, refreshing it when it expires, and choosing between the production, test, and development hosts yourself. Through Jentic you install once, import DCBaaS from the API Directory, store the credential once, and your agent calls it.
Permission scoping
You choose which DCBaaS operations the agent may call, such as searching and renewing certificates, so destructive ones like revoking a certificate or deleting an application are not included unless you add them. DCBaaS carries the application and certificate identifiers in the request body, so rules bound which operations your agent may call, not which certificate.
Credential isolation
Your DCBaaS bearer token is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
Intent-based discovery
Agents search Jentic by intent such as 'renew a certificate' or 'revoke a compromised certificate', and Jentic returns the matching DCBaaS operation with its input schema so the agent calls the right endpoint without browsing the reference docs.
Alternatives and complements available in the Jentic catalogue.
Specific to using DCBaas API through Jentic.
What authentication does the DCBaaS API use?
Per its OpenAPI spec, the DCBaaS API uses a bearer token. You request a token from the token endpoint, choosing the auth server that matches your environment, and send it as a bearer token on each call. Through Jentic the token is stored encrypted by your own instance and injected at call time, so it never reaches the agent.
Is there a DCBaaS MCP server?
You don't need an MCP server to give your agent DCBaaS. Jentic connects it directly from the API Directory: import it, store your credential once, and your agent calls operations like renewing or revoking a certificate on demand, without loading another server's tool definitions into its context.
Can I limit what my agent is allowed to do with DCBaaS?
Yes. Write a rule that allows only certificate search and renewal, so the agent can keep certificates current but cannot revoke a certificate or delete an application unless you add those operations, and every call it makes is logged. This matches a renewal bot that should maintain trust without destructive power.
Can I renew certificates automatically with the DCBaaS API?
Yes. Search for certificates nearing expiry, then call the renew operation for each one and read back its status to confirm. This replaces manual certificate replacement through the DCBaaS web portal, which is the reason the API was added.
What are the rate limits for the DCBaaS API?
The OpenAPI spec does not specify rate limits. Check the DCBaaS documentation on SwaggerHub at https://app.swaggerhub.com/apis/DCBaaS-Team/DCBaaS-API for current limits before scheduling bulk renewal jobs.
How do I renew a certificate with the DCBaaS API through Jentic?
Search Jentic for 'renew a certificate', which returns the certificate search and renew operations with their input schemas. The agent finds the certificate, renews it, and confirms the status, with your stored token injected at call time. To run it on your own infrastructure, install Jentic One from its GitHub repo.
GET STARTED