/health

get

Health check endpoint

/profiles

get

List available VPN profile names

/device-types

get

List supported device types

/{profile}/certificates

get

List all certificates issued under a profile, grouped by serial name

get

Get presigned S3 download URLs (1-hour expiry) for all artifact files for a serial + device type

/history

get

Return the last 50 certificate generation events across all profiles, most recent first

/{profile}/certificate

post

Generate a client certificate, package it for the specified device type, and upload to S3

delete

Delete all S3 artifact files for a given serial name and device type