Certificate API: How to Issue Certificates with a REST API

A certificate API turns a completed course in your LMS or CRM into an issued, blockchain-secured certificate. The TRUE API does it with five endpoints.
Certificate API: a hand touching a glowing API icon surrounded by gear, code and integration symbols, with the TRUE logo
April 17, 2024

TL;DR: A certificate API lets your own systems issue certificates automatically, with no one opening a design tool. With a REST API, your LMS, CRM or HR system sends an HTTPS request carrying the recipient's data and the name of a design template, and the certificate is issued. The TRUE API does this with five endpoints (Issue, Preview, Templates, Content and Issued), and every document it issues is secured on a public blockchain and verifiable by anyone.

What is a certificate API?

A certificate API is an application programming interface that creates and issues certificates when another system asks it to. A learning platform, CRM or HR system sends the recipient's details, and the API returns a finished certificate, diploma or licence. TRUE Original's certificate API issues documents this way, and every one of them is blockchain-secured.

Some people search for a certificate generator API. It is the same thing seen from the output: the request generates the document from a template. The phrase "API certificate" also covers a different product. An SSL/TLS certificate API manages the X.509 certificates that encrypt traffic between servers, and it has nothing to do with a diploma. The certificates here are the other kind. They prove that a named person finished a course, passed an exam or holds a licence. The wider idea of an API for documents like these is covered in What is an API for secure digital documents?

How do you issue certificates with a REST API?

You issue certificates with a REST API by sending an HTTPS POST request to the API's issue endpoint, with the recipient's data and the name of a design template in the body. The API merges the data into the template and issues the document. With the TRUE API, the same request sent to the Preview endpoint first shows what the certificate will look like, before anything is issued.

REST is the architectural style Roy Fielding described in his doctoral dissertation at the University of California, Irvine, in 2000. "The central feature that distinguishes the REST architectural style from other network-based styles is its emphasis on a uniform interface between components," Fielding wrote. For a certificate API, that uniform interface is easy to picture. A certificate is a resource like any other. You create it with POST and read it back with GET.

Issuing with the TRUE API follows five steps:

  1. Build the certificate's design template in TRUE Dashboard (Build > Design Templates) and decide which fields it shows.
  2. Read the template's structure with the Templates endpoint, so your system knows which fields to send.
  3. Send the recipient's data to Preview and check the result.
  4. Send the same request to Issue. The certificate is created, blockchain-secured, and the recipient receives it via email, all from one API call.
  5. List what you have issued with the Issued endpoint, filtered by status when you need to.

What do you need to configure before calling a certificate API?

Before the first call to the TRUE API you need two things: API credentials and a design template. The credentials authenticate every request. The design template decides which fields the certificate shows, what they are called and how many pages the document runs to.

The TRUE API authenticates with API keys sent over Basic Auth, the HTTP scheme the IETF defines in RFC 7617 (September 2015), which carries a user-id and password pair encoded in Base64. Every request carries the header Authorization: Basic base64(username:password). Every call goes over HTTPS. A call over plain HTTP fails, and so does a request without authentication. API access is included in TRUE subscriptions.

The design template is where the organisation's own work sits. It carries the brand and the fields, and a TRUE document built from it can run to several pages. Courses and other recurring items live in Document Content (TRUE Dashboard > Build > Document Content), each with a short code. A request names the course by that short code instead of repeating the full title every time.

What does a certificate API request look like?

A request to the TRUE certificate API is a JSON body with two keys: design, the name of the design template, and data, a list holding the recipient's fields. The field names come from your own template, so the example below uses only names from the illustration on the TRUE API page.

{
  "design": "true-demo-document",
  "data": [
    {
      "Contact Firstname": "Maria",
      "Contact Lastname": "Andersson",
      "E-mail address": "[email protected]",
      "Course": "course-swedish"
    }
  ]
}

The Course value is a short code from Document Content, here the "Course Swedish" item from the example on the TRUE API page. Sent to Preview, this body returns a preview. Sent to Issue, the same body issues the certificate.

Which endpoints does the TRUE API have?

The TRUE API has five endpoints: Issue, Preview, Templates, Content and Issued. Issue and Preview are POST requests that build documents. Templates, Content and Issued are GET requests that read what already sits in your TRUE account.

  • Issue (POST) issues a document with the design you choose.
  • Preview (POST) takes the same request as Issue and returns a preview without issuing anything.
  • Templates (GET) lists your design templates, or returns the structure of one template and its instructions.
  • Content (GET) returns the items in Document Content, each with a title, a short code and the date it was added.
  • Issued (GET) lists the documents you have issued. Optional parameters filter by status (all, approved or verified), choose full or simple data, and page through the results with limit and page.

Five endpoints is the whole surface. The TRUE API page says it in one line: only five endpoints in total, with "no strange filtering or complicated settings." A developer who has called a REST API before can read the entire reference in one sitting. Competitors require dozens of endpoints, complex authentication flows, and extensive configuration. TRUE's API is designed to work in hours, not weeks.

Can you test the TRUE API before you build anything?

Yes. TRUE Original publishes a Postman collection that gives access to a demo endpoint, so a developer can send real requests and read real responses before anything is set up on the organisation's side. Run the issue call from the collection and you have seen the whole flow. Most integrations go live within one to two weeks.

Documentation is a known weak spot in software. In Postman's 2025 State of the API Report, a survey of over 5,700 developers, architects and executives, 55% said they struggle with inconsistent documentation and 34% said they are unable to find existing APIs. The TRUE API keeps authentication, all five endpoints, the request format and the Postman collection on a single page.

Can you issue certificates without writing code?

Yes. TRUE Original offers two ways to issue certificates automatically without code: the email API and ready connections to platforms the organisation already runs. Both issue the same blockchain-secured TRUE documents as the REST API.

The email API works the way the name suggests. You send TRUE an email with a predetermined message and structure, and the TRUE system generates the document and issues it to the intended person. Any system that can send an email can trigger a certificate this way.

For teams without development resources, TRUE accepts CSV uploads through the dashboard. Same automation, no code required.

Which LMS and CRM systems connect to the TRUE API?

More than twenty platforms connect to TRUE Original, across learning platforms, CRM systems and business systems. Canvas, Moodle, Learnster, Salesforce, Microsoft Dynamics 365, Zapier and Shopify are among them, and every connection is listed on the TRUE integrations page.

In Moodle, automate credential issuance based on course completion, quiz scores, or custom completion criteria. The Canvas, Moodle and Learnster pages describe what each LMS connection does, and the Salesforce page covers the CRM side. With Salesforce, trigger certificate issuance when opportunities close, training completes, or certifications are earned. A platform that is not on the list can still connect through the REST API, because the pattern is the same on any system with an API. TRUE also offers webhooks for organisations that connect their own data source.

What happens after the API issues a certificate?

A certificate issued through the TRUE API is a TRUE Original document: a shareable link on the issuer's own domain, secured on a public blockchain and verifiable by anyone through TRUE Verify or a QR code. The recipient gets a link, not a file.

TRUE is blockchain-agnostic. It writes documents to several public blockchains, among them Ethereum and Polygon, and a customer who wants a specific chain can have it. Once the record is written, the document cannot be altered. A PDF certificate is a file that can be edited and forged, while a TRUE document is blockchain-locked and can be verified by anyone, at any time. Blockchain verification isn't a separate module or additional cost.

The issuer also sees what happens next. TRUE analytics show when, where and by whom a document is opened and shared. Every share puts the issuer's brand in front of new people, and TRUE documents have generated over 100 million marketing impressions worldwide. The rest of the platform around the API is on the TRUE features page.

For compliance training, the certificate includes an expiration date if applicable. Result: Audit-ready records. No manual certificate creation. Automatic reminders before expiration.

Why do organisations issue certificates through an API?

Organisations issue certificates through an API because the API does the work once per template instead of once per recipient. A course provider sending ten certificates a month can type them by hand. At ten thousand, nobody can. TRUE Original has issued over 900,000 documents for more than 200 issuers, with customers in over 15 countries.

Graduation day through the API: no manual processing. No printing delays. Graduates share their credentials on LinkedIn the same day.

The rest of the software world has moved the same way. According to Postman's 2025 State of the API Report, 82% of organisations have adopted some level of an API-first approach, and 25% operate as fully API-first organisations, a 12% increase from 2024. For an organisation that issues certificates, API-first means the system that knows a course is complete is also the system that issues the proof.

On the TRUE API, that proof is one POST request.

Frequently Asked Questions

Does TRUE have a REST API for issuing certificates?

Yes. TRUE Original has its own REST API for issuing blockchain-secured certificates, diplomas and other documents, with five endpoints in total: Issue, Preview, Templates, Content and Issued.

How do I authenticate against the TRUE API?

The TRUE API uses API keys sent over Basic Auth, with the header Authorization: Basic base64(username:password). Every request must go over HTTPS, and calls over plain HTTP or without authentication fail.

Is a certificate API the same as an SSL certificate API?

No. A certificate API like the TRUE API issues certificates that people earn, such as course certificates, diplomas and licences. An SSL/TLS certificate API manages the X.509 certificates that encrypt traffic between servers.

Can I preview a certificate before the API issues it?

Yes. The TRUE API's Preview endpoint takes the same request as the Issue endpoint and returns a preview of the document without issuing anything.

Can I issue certificates by email instead of through the API?

Yes. With TRUE's email API you send an email with a predetermined message and structure, and the TRUE system generates the document and issues it to the intended person automatically.

Talk to us to see what value TRUE would create for your organisation:

Every organisation we work with started with the same question. Give us thirty minutes and we will show you what your own documents would be worth.

Book a call

More insights

Not sure where to start? Let us help!

You have questions, we have answers. Fill out the form to speak to our experts.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Hand holding smartphone with glowing floating digital document overlay symbolizing mobile document verification against blurred background

Trusted by leading organisations worldwide