Skip to main content

ACME HTTP Connector

Publish ACME challenges and deploy certificates through your HTTP APIs.

PyPI Python License

Documentation · Source code · Issues · Certbot adapter

What it does

ACME HTTP Connector connects your certificate automation to an existing HTTP API. Use it to publish an HTTP-01 challenge, remove it after validation, and send issued certificates to the service that needs them.

Operation What your API receives
Publish a challenge The challenge path and key authorization text
Clean up a challenge The challenge path to remove
Deploy a certificate The domain, certificate, private key and optional chain

The library works independently of Certbot. Your ACME client remains responsible for requesting certificates and completing validation; your HTTP service exposes the challenge to the certificate authority.

Installation

Requires Python 3.10 or newer.

python -m pip install acme-http-connector

Using Certbot? Install certbot-httpreq instead. It includes this library and provides the Certbot plugins.

Dehydrated hook

The package installs acme-http-dehydrated, a Dehydrated 0.7.2 HTTP-01 hook that publishes and cleans single or chained challenges and deploys issued certificates. No Certbot installation is required. The hook is included starting with core 0.2.0.

Set Dehydrated HOOK to the command's absolute path and CHALLENGETYPE="http-01". Configure API endpoints in /etc/acme-http-connector.yml, or set ACME_HTTP_CONNECTOR_CONFIG to another YAML path. See Dehydrated setup for directory setup, issuance and renewal.

Unknown lifecycle hooks succeed without action. Action hooks return nonzero on argument, configuration, file or HTTP errors; messages omit sensitive exception details. Failed batches stop at the first HTTP error without automatic retry or rollback. DNS-01 and TLS-ALPN-01 are not supported.

Quick start

1. Connect your API

from acme_http_connector import HTTPConnector

connector = HTTPConnector({
    "perform": {
        "uri": "https://api.example.com",
        "path": "/challenges",
        "param_validation": "value",
    },
    "cleanup": {
        "uri": "https://api.example.com",
        "path": "/challenges",
    },
    "deploy": {
        "uri": "https://api.example.com",
        "path": "/certificates",
    },
})

Replace the example endpoints with your own API. By default, publication uses PUT, cleanup uses DELETE, and deployment uses POST with JSON payloads.

2. Publish and remove a challenge

Pass the full challenge path and key authorization supplied by your ACME client:

challenge_path = "/.well-known/acme-challenge/TOKEN"
connector.publish(challenge_path, "TOKEN.ACCOUNT_THUMBPRINT")

# Run your ACME client's validation here, then remove the challenge.
connector.cleanup(challenge_path)

With the configuration above, the API receives a request at /challenges/.well-known/acme-challenge/TOKEN with {"value": "TOKEN.ACCOUNT_THUMBPRINT"}. Your service must make that value available at the domain's public HTTP-01 URL.

3. Deploy the issued certificate

connector.deploy_files(
    domain="example.com",
    cert_path="cert.pem",
    key_path="privkey.pem",
    chain_path="chain.pem",
)

Already have the PEM contents in memory? Use connector.deploy(domain, cert, key, chain="") instead. The chain is optional in both methods.

Configuration at a glance

Each operation has its own settings, so challenge publication and certificate deployment can use different endpoints and credentials.

Setting Purpose Default
uri, path API origin and request path http://localhost; phase-specific path
method HTTP method PUT / DELETE / POST
format JSON or form body json
headers Authentication and custom HTTP headers None
timeout Positive socket timeout in seconds 30
verify TLS verification or CA bundle path true
param_challenge Send the full challenge path in a query parameter Append to API path
param_validation Wrap key authorization in a named body field Send the text directly
body_params Rename certificate deployment fields domain, cert, key, chain

See the complete configuration reference for allowed methods, environment variables and payload formats.

Integration notes

  • No Certbot dependency. Import HTTPConnector directly from Python or use the Dehydrated HTTP-01 hook. Other client adapters remain on the roadmap.
  • Explicit errors. Invalid settings raise ConfigurationError. HTTP, network and file errors propagate to your application. Successful operations return None.
  • Configuration stays yours. The library copies the supplied mapping. Use the phases argument to initialize only the operations your integration needs.
  • Protected transport by default. TLS verification is enabled and requests have a 30-second socket timeout. Use HTTPS for remote deployment: it sends the private key.

Project

Report an issue · Release history · Roadmap

Copyright © 2019–2026 Adrien Delle Cave. Licensed under GPL-3.0-or-later.

HTTP redirects are refused for publish, cleanup and deployment. Configure the final API URL directly; redirects do not trigger another request or count as success.

Metadata

Release files for acme-http-connector 0.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for acme-http-connector 0.2.1
File Size Uploaded
acme_http_connector-0.2.1.tar.gz 22.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for acme-http-connector 0.2.1
File Interpreter ABI Platform
acme_http_connector-0.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 44.2 kB

Release files / acme_http_connector-0.2.1.tar.gz

Download URL acme_http_connector-0.2.1.tar.gz
Size 22.2 kB
Tags Source
SHA-256 checksum
How to use checksums
f1c55f1f78161173b4d41ba4ea815ed9bcb5f8cbec5366ebd84d57403bfaa9d2
BLAKE2b-256 checksum
How to use checksums
2b3f7b3457cd69199ce98ae1633e65cda418119b6382c8eff4ad1e9a7d111b40
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log

Release files / acme_http_connector-0.2.1-py3-none-any.whl

Download URL acme_http_connector-0.2.1-py3-none-any.whl
Size 21.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
2701f70536b69333b4c87e1d24ea5a2a3da7ae1ff2b860600516f02779ae7107
BLAKE2b-256 checksum
How to use checksums
87c503ba9bad58b088c539af3b1017f1a2343ec4f5bac91393643de8d8b4f72c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.1 This release

2 release files

0.2.0

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page