---
editLink: false
lastUpdated: false
---

[@salesforce/b2c-tooling-sdk](../../../modules.md) / [operations/mtls](../index.md) / issueClientCertificate

# Function: issueClientCertificate()

> **issueClientCertificate**(`options`): [`IssuedClientCertificate`](../interfaces/IssuedClientCertificate.md)

Defined in: [packages/b2c-tooling-sdk/src/operations/mtls/index.ts:264](https://github.com/SalesforceCommerceCloud/b2c-developer-tooling/blob/bceb8da43dd8bc63d57932bbd905d36a1b40c949/packages/b2c-tooling-sdk/src/operations/mtls/index.ts#L264)

Issues a client certificate signed by the given CA and bundles it as PKCS12.

The resulting `.p12` is what the CLI, IDE extension, and other WebDAV clients
use for two-factor code upload (`certificate` / `certificate-passphrase` in
dw.json). This runs entirely locally; no API call is made.

## Parameters

### options

[`IssueClientCertificateOptions`](../interfaces/IssueClientCertificateOptions.md)

CA, subject, validity, and passphrase options

## Returns

[`IssuedClientCertificate`](../interfaces/IssuedClientCertificate.md)

The client certificate, private key, and PKCS12 bundle

## Throws

Error if the CA certificate/key are invalid, don't match, or the CA has expired
