Renew a Workato On-Prem Agent (OPA) certificate before it expires. To maintain uninterrupted connectivity between Workato and your on-premise environment.
To help prevent certificate expiration issues, Unimarket automatically displays a notification in the customer's Workato workspace and creates a support ticket with the Unimarket Support team 30 days before the certificate expires.
Prerequisites
Before starting, ensure that:
- You have administrator access to the Workato workspace.
- You have access to the existing OPA host server.
- The existing OPA is operational.
- You can create a new agent within the same Workato On-Prem Group.
- You have saved the activation code for the new agent.
- You have appropriate permissions to access the OPA installation directory.
Optional: Request Access to the Workato Workspace
If you do not already have access:
- Create a free Workato account at Workato Sign Up.
- Email Unimarket Support and request the Collaborator role for your organization's Workato workspace.
- Once access is granted, you can manage the certificate renewal process directly.
Step 1: Create a New On-Prem Agent
- In Workato, create a new On-Prem Agent in the same On-Prem Group as the existing agent.
-
Name the new agent using the format:
{Customer Name} PROD OPA 2026 - Complete the agent creation process.
- Copy and save the Activation Code displayed during setup.
Note: You do not need to download or install a new agent unless you are also performing an agent upgrade.
Step 2: Backup the Existing Certificate Files
-
Navigate to the
conffolder within the existing OPA installation directory.Windows Default Location
C:\Program Files\Workato Agent\conf -
Move the following files to a secure backup location:
cert.pemcert.key
Step 3: Generate a New Certificate
- Open a command prompt or terminal.
-
Change to the Workato Agent
bindirectory.Example Windows location:
C:\Program Files\Workato Agent\bin -
Run the activation script using the activation code from Step 1:
activate.cmd --code=ACTIVATION_CODE -
Confirm that new versions of the following files are generated:
cert.pemcert.key
Step 4: Validate the New Agent
- Return to the Workato workspace.
- Open the newly created agent.
- Select Test.
- Verify that the agent status displays as Active.
- Select Done.
The existing OPA installation is now associated with the new agent and certificate.
Step 5: Remove the Old Agent
- Locate the original agent in the Workato agent list.
- In the Version column, select the ellipsis (...).
- Select Delete Agent.
- Confirm the deletion.
Results
You have successfully renewed the Workato OPA certificate.
Verify the renewal by confirming that:
- The new agent status is Active.
- Connections and recipes using the OPA function normally.
- A new certificate has been generated.
- The certificate expiration date is approximately one year from the generation date.
Limits and Notes
- OPA certificates are valid for one year from the generation date.
- Unimarket generates renewal notifications and support tickets 30 days before certificate expiration.
- Certificate renewal can be completed by:
- Customer IT staff with appropriate Workato access or
- Unimarket Integration team, on behalf of the customer.
- Renewing the certificate does not require an agent upgrade.