When an API uses HTTPS, certificates help establish trust before any request data is exchanged. A CA certificate helps Bruno verify that the server is genuine. A client certificate works in the other direction: it lets the server verify the identity of Bruno or the application making the request.