---
title: Manage certificate check monitors
source: https://docs.newrelic.com/docs/apis/nerdgraph/examples/synthetics-api/certificate-check-monitor
---

New Relic allows you use NerdGraph to create [certificate check monitors](https://docs.newrelic.com/docs/synthetics/synthetic-monitoring/using-monitors/add-edit-monitors). Certificate check monitors track SSL certificate expiration dates and notify you when certificates are about to expire. This tutorial provides examples of how to use the NerdGraph API to automate the creation of certificate check monitors.

## Create a certificate check monitor [#create-certificate-check]

You can create a certificate check monitor using the `syntheticsCreateCertCheckMonitor` mutation. This mutation allows you to set up monitoring for SSL certificate expiration on any domain.

### Input parameters

| Parameter                                   | Data Type | Is it Required? | Description                                                                                                                                                                                                                       |
| ------------------------------------------- | --------- | --------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `accountId`                                 | Integer   | Yes             | Your New Relic [account ID](https://docs.newrelic.com/docs/accounts/accounts-billing/account-structure/account-id) where the monitor will be created.                                                                             |
| `monitor.domain`                            | String    | Yes             | The domain to monitor for certificate expiration (e.g., `example.com`).                                                                                                                                                           |
| `monitor.locations.public`                  | Array     | Yes             | Array of [public location](https://docs.newrelic.com/docs/synthetics/synthetic-monitoring/using-monitors/add-edit-monitors/#setting-location) identifiers where the monitor will run checks (e.g., `["US_EAST_1", "US_WEST_1"]`). |
| `monitor.name`                              | String    | Yes             | The display name for your certificate check monitor.                                                                                                                                                                              |
| `monitor.numberDaysToFailBeforeCertExpires` | Integer   | Yes             | Number of days before certificate expiration to trigger a failure. For example, setting this to 30 means the monitor will fail when the certificate has 30 or fewer days until expiration.                                        |
| `monitor.period`                            | Enum      | Yes             | How often the monitor runs. Options: `EVERY_MINUTE`, `EVERY_5_MINUTES`, `EVERY_10_MINUTES`, `EVERY_15_MINUTES`, `EVERY_30_MINUTES`, `EVERY_HOUR`, `EVERY_6_HOURS`, `EVERY_12_HOURS`, `EVERY_DAY`.                                 |
| `monitor.status`                            | Enum      | Yes             | The monitor status. Options: `ENABLED` (monitor is active and performing checks), `DISABLED` (monitor is inactive).                                                                                                               |
| `monitor.apdexTarget`                       | Float     | No              | The monitor's Apdex target in seconds, used to populate SLA reports. Defaults to 7.0 seconds.                                                                                                                                     |

### Sample request

```graphql
mutation {
  syntheticsCreateCertCheckMonitor(
    accountId: ACCOUNT_ID
    monitor: {
      domain: "DOMAIN"
      locations: { public: ["LOCATION_1", "LOCATION_2"] }
      name: "YOUR_MONITOR_NAME"
      numberDaysToFailBeforeCertExpires: DAYS_UNTIL_EXPIRATION
      period: PERIOD
      status: STATUS
      apdexTarget: APDEX_TARGET
    }
  ) {
    errors {
      description
      type
    }
  }
}
```

### Sample response

A successful response returns `null` for errors:

```json
{
  "data": {
    "syntheticsCreateCertCheckMonitor": {
      "errors": null
    }
  }
}
```

If there are any issues creating the monitor, the `errors` array will contain objects with `description` and `type` fields explaining what went wrong.

## Update a certificate check monitor [#update-certificate-check]

You can update an existing certificate check monitor using the `syntheticsUpdateCertCheckMonitor` mutation. This allows you to modify the configuration of a certificate check monitor that has already been created.

### Input parameters

| Parameter                                   | Data Type | Is it Required? | Description                                                                                                                                                                                                                       |
| ------------------------------------------- | --------- | --------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `guid`                                      | String    | Yes             | The unique entity [GUID](https://docs.newrelic.com/docs/apis/nerdgraph/examples/synthetics-api/query-synthetics-data#query-monitors) of the monitor you want to update.                                                           |
| `monitor.domain`                            | String    | No              | The domain to monitor for certificate expiration (e.g., `example.com`).                                                                                                                                                           |
| `monitor.locations.public`                  | Array     | No              | Array of [public location](https://docs.newrelic.com/docs/synthetics/synthetic-monitoring/using-monitors/add-edit-monitors/#setting-location) identifiers where the monitor will run checks (e.g., `["US_EAST_1", "US_WEST_1"]`). |
| `monitor.name`                              | String    | No              | The updated display name for your certificate check monitor.                                                                                                                                                                      |
| `monitor.numberDaysToFailBeforeCertExpires` | Integer   | No              | Number of days before certificate expiration to trigger a failure.                                                                                                                                                                |
| `monitor.period`                            | Enum      | No              | How often the monitor runs. Options: `EVERY_MINUTE`, `EVERY_5_MINUTES`, `EVERY_10_MINUTES`, `EVERY_15_MINUTES`, `EVERY_30_MINUTES`, `EVERY_HOUR`, `EVERY_6_HOURS`, `EVERY_12_HOURS`, `EVERY_DAY`.                                 |
| `monitor.status`                            | Enum      | No              | The monitor status. Options: `ENABLED` (monitor is active and performing checks), `DISABLED` (monitor is inactive).                                                                                                               |
| `monitor.apdexTarget`                       | Float     | No              | The monitor's Apdex target in seconds, used to populate SLA reports. Defaults to 7.0 seconds.                                                                                                                                     |

### Sample request

```graphql
mutation {
  syntheticsUpdateCertCheckMonitor(
    guid: ENTITY_GUID
    monitor: {
      domain: "DOMAIN"
      locations: { public: ["LOCATION_1", "LOCATION_2"] }
      name: "YOUR_MONITOR_NAME"
      numberDaysToFailBeforeCertExpires: DAYS_UNTIL_EXPIRATION
      period: PERIOD
      status: STATUS
      apdexTarget: APDEX_TARGET
    }
  ) {
    errors {
      description
      type
    }
  }
}
```

### Sample response

A successful response returns `null` for errors:

```json
{
  "data": {
    "syntheticsUpdateCertCheckMonitor": {
      "errors": null
    }
  }
}
```

If there are any issues updating the monitor, the `errors` array will contain objects with `description` and `type` fields explaining what went wrong.

## Delete a certificate check monitor [#delete-monitor]

When a certificate check monitor is no longer needed, you can permanently remove it using the `syntheticsDeleteMonitor` mutation.

To delete a monitor, refer to the [Delete Synthetic monitor](https://docs.newrelic.com/docs/apis/nerdgraph/examples/synthetics-api/ping-monitor/#delete-monitor) section.

## Query certificate check monitors [#query-certificate-check-monitors]

Use NerdGraph to retrieve metadata, map IDs, or check the status of your certificate check monitors.

For more information, refer to:

-   [Query all monitors](https://docs.newrelic.com/docs/apis/nerdgraph/examples/synthetics-api/query-synthetics-data#query-monitors): To list all synthetic monitors and their configurations.
-   [Map monitor ID to entity GUID](https://docs.newrelic.com/docs/apis/nerdgraph/examples/synthetics-api/query-synthetics-data#query-guid-mapping): To migrate legacy monitor IDs to entity GUIDs.
-   [Runtime upgrade status](https://docs.newrelic.com/docs/apis/nerdgraph/examples/synthetics-api/query-synthetics-data#query-runtime-upgrade-all): To check if your monitors are ready for the latest runtime upgrades.

To view complete list of query examples, refer to the [Query synthetics data](https://docs.newrelic.com/docs/apis/nerdgraph/examples/synthetics-api/query-synthetics-data) document.
