> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Show the service PKI status

> This API shows the PKI status of the service.



## OpenAPI

````yaml /openapi/10.1/aviatrix-api.json get /v2.5/api/pkis/{service}
openapi: 3.1.0
info:
  title: Aviatrix Controller API
  version: '10.1'
  description: >-
    Aviatrix Controller API — version 10.1. Selected operations with Mintlify
    metadata.
servers: []
security: []
tags:
  - name: policies
    x-group: Policies
  - name: authentication
    x-group: Authentication
  - name: account-management
    x-group: Account Management
  - name: rbac
    x-group: RBAC & Permissions
  - name: gateways
    x-group: Gateways
  - name: transit
    x-group: Transit
  - name: nat
    x-group: NAT
  - name: app-domains
    x-group: SmartGroups
  - name: certificates
    x-group: Certificates
  - name: mitm
    x-group: MITM
  - name: monitoring
    x-group: Monitoring & Diagnostics
  - name: fqdn
    x-group: FQDN
  - name: logging
    x-group: Logging
  - name: vpn
    x-group: UserVPN
  - name: site-to-cloud
    x-group: Site-to-Cloud
  - name: controller
    x-group: Controller
  - name: bgp
    x-group: BGP
  - name: general
    x-group: General
  - name: firenet
    x-group: FireNet
  - name: networking
    x-group: Networking
  - name: tgw
    x-group: AWS TGW
  - name: ips
    x-group: IPS
  - name: saml
    x-group: SAML
paths:
  /v2.5/api/pkis/{service}:
    get:
      tags:
        - certificates
      summary: Show the service PKI status
      description: This API shows the PKI status of the service.
      operationId: retrieveServicePKIStatus
      parameters:
        - description: The service to retrieve PKI status for.
          in: path
          name: service
          required: true
          schema:
            $ref: '#/components/schemas/ServiceCAServiceParam'
        - name: Authorization
          in: header
          required: true
          description: 'Controller ID in the format: cid <CID>.'
          schema:
            type: string
            example: cid <CID>
            default: cid <CID>
          example: cid <CID>
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceCAPKIStatus'
          description: Successfully retrieved the service PKI status
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceCAError'
          description: Bad Request - Invalid input or CA rotation error
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceCAError'
          description: Internal Server Error
        default:
          $ref: '#/components/responses/general_response_v25'
      x-codeSamples:
        - lang: curl
          label: cURL
          source: |-
            curl -sk -X GET "https://<controller>/v2.5/api/pkis/{service}" \
              -H "Authorization: cid <CID>"
        - lang: python
          label: Python
          source: |-
            import requests

            url = "https://<controller>/v2.5/api/pkis/{service}"
            headers = {"Authorization": "cid <CID>"}

            response = requests.get(url, headers=headers)
            print(response.text)
        - lang: go
          label: Go
          source: |-
            package main

            import (
              "fmt"
              "net/http"
            )

            func main() {
              req, _ := http.NewRequest("GET", "https://<controller>/v2.5/api/pkis/{service}", nil)
              req.Header.Set("Authorization", "cid <CID>")

              client := &http.Client{}
              resp, err := client.Do(req)
              if err != nil {
                panic(err)
              }
              defer resp.Body.Close()

              fmt.Println(resp.Status)
            }
components:
  schemas:
    ServiceCAServiceParam:
      enum:
        - internal
        - uservpn
      type: string
    ServiceCAPKIStatus:
      properties:
        pki_bundle_deployment_status:
          additionalProperties:
            enum:
              - unknown
              - in_sync
              - out_of_sync
            type: string
          description: >
            Key-value mapping of node names to their PKI bundle deployment
            status.

            - unknown: The PKI bundle deployment status could not be determined
            for the node, possibly due to network issues or the node being
            offline.

            - in_sync:
              * For control-plane connection dependent services, the node PKI bundle is in sync with the source of truth on the controller.
              * For control-plane connection independent service (SPIRE), the node's SPIRE agent successfully attested to the SPIRE server, and it has the current PKI bundle.
            - out_of_sync:
              * For control-plane connection dependent services, the node PKI bundle is out of sync with the source of truth on the controller.
              * For control-plane connection independent service (SPIRE), the node's SPIRE agent has not yet attested to the SPIRE server, and it doesn't have the current PKI bundle.
            If in_sync, users can proceed to move to the next phase of CA
            rotation process. Otherwise, users should image upgrade the gateway
            as the fix.
          type: object
      required:
        - pki_bundle_deployment_status
      type: object
    ServiceCAError:
      properties:
        message:
          description: Error message
          type: string
      required:
        - message
      type: object
    general_response_v25:
      description: A generic API response container for v2.5 style APIs.
      properties:
        message:
          description: A human-readable message.
          type: string
      title: General Response v2.5
      type: object
  responses:
    general_response_v25:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/general_response_v25'
      description: General v2.5 API response schema.

````