Use an operator-supplied CSR
Cloud supports public CSR workflows on Pro and Team workspaces. A workspace manager or administrator can manage them from Certificates → CSR workflows, or use Add new CSR beside an existing certificate to rotate that certificate.
Generate the CSR with your host's existing key tooling. Keep the private key on that host. Upload only the public PEM CSR to TokenTimer; private-key material is rejected. Choose an existing target or describe the host or endpoint that will receive the signed certificate.
The workflow starts in pending_signature. Have your certificate authority sign the CSR, then import the public signed leaf certificate and any public chain. TokenTimer verifies the certificate's public-key identity against the CSR before accepting it. A certificate associated with a different managed identity cannot silently replace the certificate you selected.
After import, the workflow is signed_pending_install. Review any additions or omissions in the issued names and acknowledge them explicitly. Recording a real observation remains possible during review, but it does not promote the signed certificate until that review is complete.
Install the certificate using your host's tooling. A matching agent, controller, or endpoint observation can complete the workflow after name review. For a host TokenTimer cannot observe, Confirm installation records your manual attestation; it does not perform a network check. An existing certificate remains intact until the replacement can be promoted.
Cancellation leaves the host and its private key unchanged. Resolve an identity conflict before continuing; do not bypass it by selecting an unrelated managed certificate.
See the API reference for the /api/v1/workspaces/{id}/certops/csrs operations. These routes require an authenticated human session, workspace membership, manager-or-administrator access, and a Pro or Team plan in Cloud.