WS-Security Certificates

<< Click to Display Table of Contents >>

Navigation:  Low-code Process Automation > Studio Cloud - Authoring environment > Bizagi Studio > Bizagi from external applications > Bizagi API > Alternative SOAP services > Requisites and concepts for SOAP web services > Enabling Bizagi API >

WS-Security Certificates

Overview

You can manage WS‑Security certificates autonomously from the Management Console. You can activate, update, and download a certificate corresponding to each environment (Development, Test, and Production). This certificate is generated automatically when the Management Console and remains valid for 10 years.  It can also be migrated during upgrades without requiring any action.

 

note_pin

Only one certificate is stored and managed per environment (Development, Production and Test) to ensure consistent WS-Security configuration.

 

Managing WS-Security Certificates

Certificate generation

A passwordless WS‑Security certificate is generated automatically when no previous certificate exists.

The Web Services options are located under the Popular tab in Management Console → Environment. At the bottom of the Web Services section, the Certificate Thumbprint indicates that the certificate exists but is disabled.

 

WS-Certificate01

 

To enable the certificate, select the Enable WS‑Security box.

 

WS-Certificate02

 

Upon enabling this option, the User Name and Password become required fields.

 

WS-Certificate03

 

Specify the User Name and Password and click Save all to finish your configuration.

 

note_pin

Auditing records each operation, including generation, activation, update, and download.

 

WS-Certificate04

 

Certificate update

To update your WS-Security certificate:

1.Click Update certificate.

 

WS-Certificate05

 

2.In the confirmation dialog click Update.

 

WS-Certificate06

 

A confirmation message box appears in the bottom-right corner of the window, verify the Certificate thumbprint has updated.

 

WS-Certificate07

 

Certificate download

To download your certificate:

1.Click Download certificate.

 

WS-Certificate08

 

2.In the pop-up window, set a password for your files by filling the text box. If left blank, no password is required to view the content of the file.

3.Click Download Certificate to confirm the action.

 

WS-Certificate09

 

4.The downloaded file is displayed in the top-right area of the browser as a listed download, double-click to open it in the download location.

 

WS-Certificate10

 

5.The certificates are downloaded as a compressed file. Right‑click the zip file.

6.Click Extract All.

 

WS-Certificate11

 

7.Type the destination folder and file name, or click Browse to define them in the file explorer.

8.Click Extract.

 

WS-Certificate12

 

The folder contains two files: the .cer file, which stores the public certificate only, and the .pfx file, which include the private key.

 

Certificate Status Monitoring (Management Console Dashboard)

GREEN: More than 90 days for expiration.

 

WS-Certificate13

 

YELLOW: Less than 90 days for expiration.

 

WS-Certificate14

 

RED: Past expiration date.

 

WS-Certificate15


Last Updated 7/15/2026 5:15:20 PM