canonical: https://jentic.com/apis/extapi.dcb.vlaanderen.be/dcbaas

# Extapi Dcb Vlaanderen Be DCBaas API

The DCBaaS API automates digital certificate lifecycle management for Digitaal Vlaanderen's certificate service. It requests, renews, revokes, and searches certificates, and registers, updates, delegates, and removes the applications that own them. The API exists so that shortening certificate lifecycles no longer forces manual replacement through the web portal. Calls are authenticated with a bearer token obtained from the environment-specific token endpoint.

## For AI agents

Request, renew, revoke, and search digital certificates and manage the applications that own them for the Digitaal Vlaanderen DCBaaS certificate service. Authenticated with a per-environment bearer token.

## Scope

Does not handle TLS termination, DNS hosting, or certificate signing outside DCBaaS. Use for DCBaaS certificate lifecycle and application management only.

## Capabilities

- Request new digital certificates for a registered application
- Renew certificates before they expire to keep services trusted
- Revoke certificates that should no longer be trusted
- Search existing certificates by their attributes
- Register applications that own certificates and delegate ownership to another party
- Update or remove application registrations as teams change

## Use cases

### Agent-Driven Certificate Renewal

An AI agent connected through Jentic can keep short-lived certificates current without a developer wiring DCBaaS auth and juggling the production, test, and development hosts. The agent searches for certificates nearing expiry, renews each one, and confirms the result, running on a schedule so manual replacement through the portal is no longer needed. Jentic injects the bearer token at call time so the credential never reaches the agent.

Example prompt: Search for certificates expiring soon, renew each one, and confirm the renewal succeeded

### Certificate Revocation on Compromise

When a key is suspected compromised, an application can revoke the affected certificate immediately rather than waiting for a manual portal change. The agent locates the certificate by its attributes and revokes it, closing the trust window quickly. This supports incident-response runbooks that must act on certificates programmatically.

Example prompt: Search for the certificate tied to an application, then revoke it and verify its status

### Application Onboarding

Teams bringing a new service online register it as an application in DCBaaS before requesting certificates. The agent adds the application, requests its first certificate, and can delegate ownership to the team that will operate it. This keeps certificate ownership mapped to the right application as an estate grows.

Example prompt: Register a new application, request a certificate for it, then delegate the application to the owning team

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| POST | `/certificate/add` | Request a new certificate |
| POST | `/certificate/renew` | Renew an existing certificate |
| POST | `/certificate/revoke` | Revoke a certificate |
| POST | `/certificate/search` | Search certificates |
| POST | `/application/add` | Register a new application |
| POST | `/application/delegate` | Delegate an application to another party |
| POST | `/op/v1/token` | Obtain a bearer token for the chosen environment |

## Key resources

- **Certificaat** — Add, renew, revoke, and search digital certificates
- **Toepassing** — Add, update, delegate, and delete the applications that own certificates
- **Authenticatie** — Obtain a bearer token from the environment-specific auth server
- **Health** — Check the availability of the DCBaaS service

## AI readiness

This API is usable in Jentic One now. Its AI-readiness score against Jentic's framework shows where it stands today and where improvements would make it even easier for agents to use.

- **Score:** 58 / 100
- **Maturity:** Foundational
- **Dimensions:**
  - Foundational Compliance: 100 / 100
  - Developer Experience & Jentic Compatibility: 72 / 100
  - AI-Readiness & Agent Experience: 33 / 100
  - Agent Usability: 94 / 100
  - Security: 60 / 100
  - AI Discoverability: 58 / 100
- **View full report:** https://jentic.com/apis/extapi.dcb.vlaanderen.be/dcbaas/scorecard
- **How the score is calculated:** https://docs.jentic.com/reference/api-readiness-framework/overview/
- **More about the dimensions:** https://docs.jentic.com/reference/api-readiness-framework/specification/#dimensional-model-overview

### Score it yourself

Every API in the directory is allowlisted, so you can re-score it with no key required.

- **Score your own API:** https://jentic.com/scorecard.md
- **Scoring CLI agent skill:** https://github.com/jentic/jentic-api-scorecard/blob/main/skills/jentic-api-scorecard/SKILL.md

```sh
npx @jentic/api-scorecard-cli score <openapi-url>
```

## Why Jentic

- **Setup:** Wiring DCBaaS by hand means requesting a bearer token from the correct environment's auth server, refreshing it when it expires, and choosing between the production, test, and development hosts yourself. Through Jentic you install once, import DCBaaS from the API Directory, store the credential once, and your agent calls it.
- **Permission scoping:** You choose which DCBaaS operations the agent may call, such as searching and renewing certificates, so destructive ones like revoking a certificate or deleting an application are not included unless you add them. DCBaaS carries the application and certificate identifiers in the request body, so rules bound which operations your agent may call, not which certificate.
- **Credential handling:** Your DCBaaS bearer token is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'renew a certificate' or 'revoke a compromised certificate', and Jentic returns the matching DCBaaS operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

## Related APIs

- **Akeyless** — Secrets and certificate management platform with PKI issuance
- **CyberArk Conjur** — Secrets management and machine identity for applications
- **SSL Labs** — Assess the TLS configuration a certificate is deployed with
- **ClouDNS** — DNS hosting used for domain-control validation during issuance

## FAQ

### What authentication does the DCBaaS API use?

Per its OpenAPI spec, the DCBaaS API uses a bearer token. You request a token from the token endpoint, choosing the auth server that matches your environment, and send it as a bearer token on each call. Through Jentic the token is stored encrypted by your own instance and injected at call time, so it never reaches the agent.

### Is there a DCBaaS MCP server?

You don't need an MCP server to give your agent DCBaaS. Jentic connects it directly from the API Directory: import it, store your credential once, and your agent calls operations like renewing or revoking a certificate on demand, without loading another server's tool definitions into its context.

### Can I limit what my agent is allowed to do with DCBaaS?

Yes. Write a rule that allows only certificate search and renewal, so the agent can keep certificates current but cannot revoke a certificate or delete an application unless you add those operations, and every call it makes is logged. This matches a renewal bot that should maintain trust without destructive power.

### Can I renew certificates automatically with the DCBaaS API?

Yes. Search for certificates nearing expiry, then call the renew operation for each one and read back its status to confirm. This replaces manual certificate replacement through the DCBaaS web portal, which is the reason the API was added.

### What are the rate limits for the DCBaaS API?

The OpenAPI spec does not specify rate limits. Check the DCBaaS documentation on SwaggerHub at https://app.swaggerhub.com/apis/DCBaaS-Team/DCBaaS-API for current limits before scheduling bulk renewal jobs.

### How do I renew a certificate with the DCBaaS API through Jentic?

Search Jentic for 'renew a certificate', which returns the certificate search and renew operations with their input schemas. The agent finds the certificate, renews it, and confirms the status, with your stored token injected at call time. To run it on your own infrastructure, install Jentic One from its GitHub repo.
