Skip to main content

ACME HTTP Connector

Connect ACME clients to your HTTP APIs.

Current adapter: Certbot. Version: 0.0.20. Previously named certbot-httpreq. The Python distribution and Certbot plugin names remain certbot-httpreq for compatibility. Other clients are planned, not implemented; see ROADMAP.md.

The authenticator publishes and removes HTTP-01 challenges through a custom HTTP endpoint. The installer sends a certificate, private key and chain to an API on issuance and renewal. Certbot performs ACME issuance; this plugin does not run an ACME server or HTTP challenge server.

Installation

Python 3.10+ and Certbot 2.11–5.x are the supported target range. CI checks Certbot 2.11 and the latest available 5.x. Install the plugin in the same Python environment as Certbot; a separate pip environment does not extend a snap.

python -m pip install certbot-httpreq
certbot plugins

PyPI installation uses the last published release. To install from a source checkout:

python -m pip install -e .

Usage

Copy certbot-httpreq.yml to /etc/letsencrypt/certbot-httpreq.yml and configure your API endpoints.

certbot run \
  --agree-tos --text --email admin@example.com \
  -a certbot-httpreq:auth \
  -i certbot-httpreq:installer \
  -d example.com

A different config file can be selected with --certbot-httpreq:auth-config and --certbot-httpreq:installer-config, or CBT_HTTPREQ_AUTH_CONFIG and CBT_HTTPREQ_INST_CONFIG.

The receiving service must expose the published challenge at http://example.com/.well-known/acme-challenge/<token> for ACME validation. The plugin also checks the challenge against the configured perform.uri host and its explicit port (otherwise Certbot's HTTP-01 port), so that route must serve the challenge too. The API write route and challenge read route need not be the same.

Configuration

Each phase (perform, cleanup, deploy) has its own uri, path, method, headers, format, timeout and verify options.

Phase Methods Payload
perform PUT, POST Challenge validation, optionally under param_validation
cleanup DELETE, PUT, POST Challenge path in URL; no request body
deploy POST, PUT, PATCH domain, cert, key, chain
  • format: json or form-urlencoded.
  • param_challenge: optional query parameter name receiving the full challenge path, including /.well-known/acme-challenge/. Otherwise that path is appended to the configured API path.
  • param_validation: optional body field name; without it JSON sends a string and form mode sends raw validation text.
  • body_params in deploy: overrides the four deployment field names.
  • headers: custom headers, including API authentication headers if needed.
  • timeout: positive finite seconds, default 30. This is Requests' socket timeout, not a total operation deadline.
  • verify: default true; a CA bundle path is also supported. Explicit false disables TLS certificate verification.

Scalar settings can be supplied using CBT_HTTPREQ_<PHASE>_<OPTION>, for example CBT_HTTPREQ_DEPLOY_TIMEOUT=15. Explicit nonempty YAML values take precedence; missing/null values use environment values, then defaults. Environment timeout values are parsed as numbers; verification accepts true/false, yes/no, on/off, 1/0 or a CA bundle path. Headers and body mappings are configured in YAML.

Use HTTPS for remote APIs, particularly deployment: the payload contains the private key. Protect the YAML file if it contains authentication headers.

Renewal

certbot renew --dry-run
certbot renew

Run dry runs against a test API first: challenge publication and cleanup are real API calls. Deployment uses the first certificate name as domain, with the complete certificate (including any SANs). HTTP errors propagate to Certbot.

Compatibility changes in 0.0.20

Existing package/plugin names, paths, environment variables and deployment fields are retained. Python 2 and old Certbot interfaces are retired. Unset HTTP timeouts now default to 30 seconds; cleanup honors its own settings; invalid HTTP methods raise an error. See CHANGELOG.

Development

python -m pip install -e . pytest build
python -m pytest
python -m build
certbot plugins

Copyright © 2019–2026 Adrien Delle Cave. GPL-3.0-or-later.

Publishing (maintainers)

GitHub Actions publishes the existing certbot-httpreq distribution using PyPI Trusted Publishing, without a long-lived API token. Configure the publisher on that PyPI project with these exact values:

Setting Value
Owner decryptus
Repository acme-http-connector
Workflow publish.yml
Environment pypi

For a release, first synchronize VERSION, RELEASE and setup.yml, finalize the top CHANGELOG entry (replace UNRELEASED with unstable) and update the README's development status. Merge those changes, then publish a non-prerelease GitHub Release tagged v<version> at that commit. The workflow checks version consistency, runs tests, builds and validates distributions, then uploads the same artifacts in a separate OIDC-enabled job.

A manual Run workflow only builds and validates; it never publishes. Pull requests changing the publishing workflow also validate without uploading to PyPI.

Metadata

Release files for certbot-httpreq 0.0.20

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for certbot-httpreq 0.0.20
File Size Uploaded
certbot_httpreq-0.0.20.tar.gz 26.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for certbot-httpreq 0.0.20
File Interpreter ABI Platform
certbot_httpreq-0.0.20-py3-none-any.whl Python 3 none any Details

Total release size: 48.3 kB

Release files / certbot_httpreq-0.0.20.tar.gz

Download URL certbot_httpreq-0.0.20.tar.gz
Size 26.2 kB
Tags Source
SHA-256 checksum
How to use checksums
357b96b2db99b72d3106a567b1edaa36c61012cbb08d6ae29c12c6a1137eb469
BLAKE2b-256 checksum
How to use checksums
207af9a565b1bf0f21539a724ebec779278b4c89f94d6e606b394df789d8f704
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / certbot_httpreq-0.0.20-py3-none-any.whl

Download URL certbot_httpreq-0.0.20-py3-none-any.whl
Size 22.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
db8aed31223303e8e76d92bf62c422deb6ad3e8ffa7aadbac50b93c0a0d8fe9d
BLAKE2b-256 checksum
How to use checksums
b6a9d96f38e421f15b454bb003191bb01345ffb798657bb661ac8ddab121f272
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.0.20 This release

2 release files

0.0.17

2 release files

0.0.16

2 release files

0.0.15

2 release files

0.0.14

2 release files

0.0.12

2 release files

0.0.11

2 release files

0.0.10

2 release files

0.0.9

2 release files

0.0.8

2 release files

0.0.7

2 release files

0.0.6

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page