Renew a Workato On-Prem Agent (OPA) Certificate

  • Updated

Renew a Workato On-Prem Agent (OPA) certificate before it expires. To maintain uninterrupted connectivity between Workato and your on-premise environment.

To help prevent certificate expiration issues, Unimarket automatically displays a notification in the customer's Workato workspace and creates a support ticket with the Unimarket Support team 30 days before the certificate expires.

 

Prerequisites

Before starting, ensure that:

  • You have administrator access to the Workato workspace.
  • You have access to the existing OPA host server.
  • The existing OPA is operational.
  • You can create a new agent within the same Workato On-Prem Group.
  • You have saved the activation code for the new agent.
  • You have appropriate permissions to access the OPA installation directory.

 

Optional: Request Access to the Workato Workspace

If you do not already have access:

  1. Create a free Workato account at Workato Sign Up.
  2. Email Unimarket Support and request the Collaborator role for your organization's Workato workspace.
  3. Once access is granted, you can manage the certificate renewal process directly.

 

Step 1: Create a New On-Prem Agent

  • In Workato, create a new On-Prem Agent in the same On-Prem Group as the existing agent.
  • Name the new agent using the format:

     

    {Customer Name} PROD OPA 2026

     

  • Complete the agent creation process.
  • Copy and save the Activation Code displayed during setup.

Note: You do not need to download or install a new agent unless you are also performing an agent upgrade.

 

Step 2: Backup the Existing Certificate Files

  • Navigate to the conf folder within the existing OPA installation directory.

    Windows Default Location

     

    C:\Program Files\Workato Agent\conf

     

  • Move the following files to a secure backup location:

     

    cert.pem
    cert.key

     

Step 3: Generate a New Certificate

  • Open a command prompt or terminal.
  • Change to the Workato Agent bin directory.

    Example Windows location:

    C:\Program Files\Workato Agent\bin

     

  • Run the activation script using the activation code from Step 1:

     

    activate.cmd --code=ACTIVATION_CODE

     

  • Confirm that new versions of the following files are generated:

     

    cert.pem
    cert.key

 

Step 4: Validate the New Agent

  • Return to the Workato workspace.
  • Open the newly created agent.
  • Select Test.
  • Verify that the agent status displays as Active.
  • Select Done.

The existing OPA installation is now associated with the new agent and certificate.

 

Step 5: Remove the Old Agent

  • Locate the original agent in the Workato agent list.
  • In the Version column, select the ellipsis (...).
  • Select Delete Agent.
  • Confirm the deletion.

 

Results

You have successfully renewed the Workato OPA certificate.

Verify the renewal by confirming that:

  • The new agent status is Active.
  • Connections and recipes using the OPA function normally.
  • A new certificate has been generated.
  • The certificate expiration date is approximately one year from the generation date.

 

Limits and Notes

  • OPA certificates are valid for one year from the generation date.
  • Unimarket generates renewal notifications and support tickets 30 days before certificate expiration.
  • Certificate renewal can be completed by:
    • Customer IT staff with appropriate Workato access or
    • Unimarket Integration team, on behalf of the customer.
  • Renewing the certificate does not require an agent upgrade.

 

What's Next/Related