ACME HTTP Connector
Publish ACME challenges and deploy certificates through your HTTP APIs.
Documentation · Source code · Issues · Certbot adapter
What it does
ACME HTTP Connector connects your certificate automation to an existing HTTP API. Use it to publish an HTTP-01 challenge, remove it after validation, and send issued certificates to the service that needs them.
| Operation | What your API receives |
|---|---|
| Publish a challenge | The challenge path and key authorization text |
| Clean up a challenge | The challenge path to remove |
| Deploy a certificate | The domain, certificate, private key and optional chain |
The library works independently of Certbot. Your ACME client remains responsible for requesting certificates and completing validation; your HTTP service exposes the challenge to the certificate authority.
Installation
Requires Python 3.10 or newer.
python -m pip install acme-http-connector
Using Certbot? Install certbot-httpreq
instead. It includes this library and provides the Certbot plugins.
Dehydrated hook
The package installs acme-http-dehydrated, a Dehydrated 0.7.2 HTTP-01 hook
that publishes and cleans single or chained challenges and deploys issued
certificates. No Certbot installation is required. The hook is included starting with
core 0.2.0.
Set Dehydrated HOOK to the command's absolute path and
CHALLENGETYPE="http-01". Configure API endpoints in
/etc/acme-http-connector.yml, or set ACME_HTTP_CONNECTOR_CONFIG to another YAML
path. See Dehydrated setup
for directory setup, issuance and renewal.
Unknown lifecycle hooks succeed without action. Action hooks return nonzero on argument, configuration, file or HTTP errors; messages omit sensitive exception details. Failed batches stop at the first HTTP error without automatic retry or rollback. DNS-01 and TLS-ALPN-01 are not supported.
Quick start
1. Connect your API
from acme_http_connector import HTTPConnector
connector = HTTPConnector({
"perform": {
"uri": "https://api.example.com",
"path": "/challenges",
"param_validation": "value",
},
"cleanup": {
"uri": "https://api.example.com",
"path": "/challenges",
},
"deploy": {
"uri": "https://api.example.com",
"path": "/certificates",
},
})
Replace the example endpoints with your own API. By default, publication uses
PUT, cleanup uses DELETE, and deployment uses POST with JSON payloads.
2. Publish and remove a challenge
Pass the full challenge path and key authorization supplied by your ACME client:
challenge_path = "/.well-known/acme-challenge/TOKEN"
connector.publish(challenge_path, "TOKEN.ACCOUNT_THUMBPRINT")
# Run your ACME client's validation here, then remove the challenge.
connector.cleanup(challenge_path)
With the configuration above, the API receives a request at
/challenges/.well-known/acme-challenge/TOKEN with {"value": "TOKEN.ACCOUNT_THUMBPRINT"}.
Your service must make that value available at the domain's public HTTP-01 URL.
3. Deploy the issued certificate
connector.deploy_files(
domain="example.com",
cert_path="cert.pem",
key_path="privkey.pem",
chain_path="chain.pem",
)
Already have the PEM contents in memory? Use
connector.deploy(domain, cert, key, chain="") instead. The chain is optional
in both methods.
Configuration at a glance
Each operation has its own settings, so challenge publication and certificate deployment can use different endpoints and credentials.
| Setting | Purpose | Default |
|---|---|---|
uri, path |
API origin and request path | http://localhost; phase-specific path |
method |
HTTP method | PUT / DELETE / POST |
format |
JSON or form body | json |
headers |
Authentication and custom HTTP headers | None |
timeout |
Positive socket timeout in seconds | 30 |
verify |
TLS verification or CA bundle path | true |
param_challenge |
Send the full challenge path in a query parameter | Append to API path |
param_validation |
Wrap key authorization in a named body field | Send the text directly |
body_params |
Rename certificate deployment fields | domain, cert, key, chain |
See the complete configuration reference for allowed methods, environment variables and payload formats.
Integration notes
- No Certbot dependency. Import
HTTPConnectordirectly from Python or use the Dehydrated HTTP-01 hook. Other client adapters remain on the roadmap. - Explicit errors. Invalid settings raise
ConfigurationError. HTTP, network and file errors propagate to your application. Successful operations returnNone. - Configuration stays yours. The library copies the supplied mapping. Use the
phasesargument to initialize only the operations your integration needs. - Protected transport by default. TLS verification is enabled and requests have a 30-second socket timeout. Use HTTPS for remote deployment: it sends the private key.
Project
Report an issue · Release history · Roadmap
Copyright © 2019–2026 Adrien Delle Cave. Licensed under GPL-3.0-or-later.
HTTP redirects are refused for publish, cleanup and deployment. Configure the final API URL directly; redirects do not trigger another request or count as success.
Metadata
Release files for acme-http-connector 0.2.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| acme_http_connector-0.2.1.tar.gz | 22.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| acme_http_connector-0.2.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 44.2 kB
Release files / acme_http_connector-0.2.1.tar.gz
| Download URL | acme_http_connector-0.2.1.tar.gz |
|---|---|
| Size | 22.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f1c55f1f78161173b4d41ba4ea815ed9bcb5f8cbec5366ebd84d57403bfaa9d2
|
|
BLAKE2b-256 checksum How to use checksums |
2b3f7b3457cd69199ce98ae1633e65cda418119b6382c8eff4ad1e9a7d111b40
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / acme_http_connector-0.2.1-py3-none-any.whl
| Download URL | acme_http_connector-0.2.1-py3-none-any.whl |
|---|---|
| Size | 21.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
2701f70536b69333b4c87e1d24ea5a2a3da7ae1ff2b860600516f02779ae7107
|
|
BLAKE2b-256 checksum How to use checksums |
87c503ba9bad58b088c539af3b1017f1a2343ec4f5bac91393643de8d8b4f72c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency log