Starter
$199/month
- Certificates included
- 100
- Overage rate
- $2.25
- Audit retention
- 30 days
- Support
- Email, business hours
- Best for
- Fintechs starting with B2B partner integrations
CA Manager
Available nowIssue, renew, and revoke mTLS certificates via REST API. CRL and OCSP responder hosted on a dedicated CDN. Audit log included. Built for Brazilian fintechs that authenticate dozens to hundreds of B2B partners in private integrations, without operating PKI internally.
The use case
Brazilian fintechs that integrate with partner ecosystems, payment processors, sub-acquirers, BaaS clients, financial service consumers, face the same operational problem: dozens to hundreds of certificate-authenticated mTLS connections to manage.
Every partner needs a certificate. Every certificate has a lifecycle. And every event of that lifecycle is operational work that doesn't differentiate your product: issuance, renewal, revocation, OCSP query.
The traditional path is to set up your own private CA: pick a PKI stack, write scripts, configure CRL distribution, custody the root key in dedicated hardware, build a presigned download mechanism, write audit logs, and maintain all of it as your partner base grows.
CA Manager replaces that entire stack with a REST API. Your fintech keeps full control over which partners get certificates and which ones get revoked. Swepay handles everything that doesn't add value to your product.
Where CA Manager fits in your stack
What's in the box
Issue, renew, revoke, and query certificates via a single API surface. JWT bearer authentication. No portal forms, no manual approval steps.
Each Swepay tenant gets a dedicated private CA, isolated from other tenants. Your root key is generated in managed cryptographic custody and not extractable. Your intermediate hierarchy is yours.
Certificate Revocation List is published automatically as certificates are revoked, served from ca-cdn.swepay.com.br with edge caching. OCSP responder supports both POST (RFC 6960) and GET (RFC 6960 §A.1) variants. CRL Distribution Points and Authority Information Access extensions embedded in every certificate. Your partners' mTLS clients validate revocation status without coupling to the administrative API.
Each issued certificate is returned in four formats on the same API response: PEM inline, presigned PEM download URL, base64-encoded PFX with generated password, or presigned PFX download URL. Pick the format that fits your partner's runtime, no conversion scripts needed.
Every API call leaves an immutable audit record. Retention is configurable per plan (30 days to 1 year). Queryable when an auditor asks for evidence, internal, regulatory, or partner-driven.
Pay on your AWS bill. Subscribe in five minutes. Upgrade between tiers without procurement cycles. Cancel anytime.
Built from day one for fintechs that need tenant isolation. Customers, environments, and key pairs are scoped by tenant from API to storage layer.
From zero to production
A complete certificate lifecycle, demonstrated. Authenticate with a JWT bearer token delivered after subscribing on AWS Marketplace. Administrative API at https://ca.swepay.com.br; PKI infrastructure (CRL, OCSP) at https://ca-cdn.swepay.com.br.
Before issuing certificates, initialize your tenant's private Certificate Authority. The root key is generated and stored in managed cryptographic custody within Swepay's infrastructure, not accessible externally, not extractable.
Provide identity attributes. CA Manager generates the key pair and returns the certificate in four delivery formats, choose what fits your runtime.
Get full certificate details by ID, status, validity, expiration countdown.
Revoke with RFC 5280 reason code. Certificate is added to the CRL within minutes.
Query certificates expiring within a window. Useful for proactive renewal automation.
Your partner's mTLS client queries the OCSP responder on the CDN during handshake. RFC 6960 standard.
Full API reference, OpenAPI spec, and architecture details on the developers page. For technical questions, email [email protected].
Pricing
Plans differ by certificate volume included. All plans get the same API, same audit log, same OCSP responder, same support response time. Subscribe and upgrade via AWS Marketplace.
$199/month
$449/month
$799/month
$1,999/month
Request a guided demonstration before subscribing. Email [email protected] with your name, company, and a brief description of your B2B integration scenario. We schedule a 30-minute technical walkthrough.
Request a demo→Talk to engineering for an AWS Marketplace Private Offer with custom volume, dedicated support, contractual SLA, and negotiated overage rates.
Talk to engineering→Request a 15-day sandbox with 5 certificates to run issuance, OCSP, and revocation against your own integration before subscribing. No AWS Marketplace contract required.
Request sandbox access→Be honest about scope
Brazilian financial infrastructure is full of overlapping standards. We want you to know exactly when CA Manager is not the right tool.
No. CA Manager is a private CA. The certificates it issues are not trusted by the Open Finance Brasil directory. For Open Finance Brasil, obtain certificates from established Brazilian providers like Soluti, Serpro, Certisign, or Valid Certificadora.
No. Pix DICT and SPB integrations require certificates that CA Manager does not issue. For those scenarios, follow the same path as Open Finance: obtain certificates from Soluti, Serpro, Certisign, or Valid Certificadora.
No. CA Manager certificates are signed by your private CA, which is not in browser or OS trust stores. They are designed for mTLS between your fintech and partners you explicitly trust. For public-internet TLS certificates, use Let's Encrypt, AWS Certificate Manager, or DigiCert.
CA Manager generates the key pair server-side at issuance and delivers it to you in one of four formats on the same API response: inline PEM, presigned PEM download URL, base64-encoded PFX with a generated password, or presigned PFX download URL. The presigned URLs expire shortly. Swepay does not retain the issued certificate's private key after delivery. The only key that stays in Swepay's infrastructure is your tenant's root CA key, held in managed cryptographic custody and not externally accessible, including not accessible to Swepay operators in normal operations.
CA Manager is designed for mTLS authentication of B2B partners in private integrations, where your fintech defines the trust relationship contractually, manages partner onboarding, and operates the truststore on both sides. Typical scenarios: payment processors authenticating sub-acquirers, BaaS providers authenticating tenants, fintechs authenticating financial service consumers. CA Manager is not designed for public-internet TLS or for scenarios requiring certificates valid in browser/OS trust stores.
CA Manager is mTLS only. It does not issue OAuth2 tokens, validate JWTs, or implement OIDC. For that layer, see Native Guard, currently in technical validation.
CA Manager is used in production by Brazilian payment processors authenticating B2B partner integrations.
Subscribe in five minutes. JWT credentials in your inbox. Issue your first certificate today.
Subscribe to CA ManagerRequest a 30-minute guided demonstration. We walk through your B2B integration scenario, show the API in action, answer questions.
Request a demoFor PSPs, BaaS providers, and large fintechs with custom volume needs, integration assistance, or contractual SLAs.
Talk to engineeringA 15-day sandbox with 5 certificates. Run issuance, OCSP, and revocation against your integration before you subscribe.
Request sandbox access