Skip to main content

ACME HTTP Connector · Certbot adapter

Publish HTTP-01 challenges and deploy your Certbot certificates through an HTTP API.

PyPI Python License

Documentation · Source code · Issues · Independent core

What it does

certbot-httpreq adds two plugins to Certbot. Together they connect certificate issuance and renewal to your existing HTTP services.

Plugin Role
certbot-httpreq:auth Publish and clean up HTTP-01 challenges through your API
certbot-httpreq:installer Send the certificate, private key and chain to your deployment API

The project is now called ACME HTTP Connector. The package name, plugin names and configuration options are preserved for existing Certbot installations.

Installation

Requires Python 3.10+ and Certbot 2.11–5.x. Install in the same Python environment as Certbot; a separate pip environment does not extend a snap installation.

python -m pip install certbot-httpreq
certbot plugins

The independent acme-http-connector core is installed automatically.

Quick start

1. Configure your endpoints

Save the following as /etc/letsencrypt/certbot-httpreq.yml, replacing the example URLs with your own services:

perform:
  uri: https://api.example.com
  path: /challenges
  method: PUT
  format: json
  param_validation: value

cleanup:
  uri: https://api.example.com
  path: /challenges
  method: DELETE

deploy:
  uri: https://api.example.com
  path: /certificates
  method: POST
  format: json

TLS verification is enabled and the socket timeout is 30 seconds by default. Each section can override headers, timeout and verify independently.

2. Request a certificate

certbot run \
  --agree-tos --text --email admin@example.com \
  -a certbot-httpreq:auth \
  -i certbot-httpreq:installer \
  -d example.com

Your API must publish the challenge at http://example.com/.well-known/acme-challenge/<token>. The adapter also verifies it against the host in perform.uri and its explicit port, or Certbot's HTTP-01 port. That host must serve the challenge too.

3. Renew

certbot renew

Certbot invokes the configured plugins for challenge handling and certificate deployment. Deployment sends the first certificate name as domain and includes the complete certificate, including its additional names.

Use certbot renew --dry-run with a test API first: challenge publication and cleanup still make real HTTP requests.

Configuration

Need Setting
Custom config file --certbot-httpreq:auth-config and --certbot-httpreq:installer-config
API authentication headers in each phase
Challenge path as a query parameter param_challenge
Named key authorization field param_validation
Custom deployment field names body_params under deploy
Custom TLS trust store CA bundle path in verify
Environment overrides CBT_HTTPREQ_<PHASE>_<OPTION>

See the full configuration reference and complete example file. Use HTTPS for remote deployment and protect API credentials: certificate payloads include the private key.

Compatibility

Existing commands, plugin names, YAML settings and environment variables continue to work. Since version 0.0.21, the shared HTTP transport lives in the independent core package. Certbot handles ACME issuance; the connector handles your HTTP APIs.

Project

Report an issue · Release history · Roadmap

Copyright © 2019–2026 Adrien Delle Cave. Licensed under GPL-3.0-or-later.

Metadata

Release files for certbot-httpreq 0.0.22

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for certbot-httpreq 0.0.22
File Size Uploaded
certbot_httpreq-0.0.22.tar.gz 26.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for certbot-httpreq 0.0.22
File Interpreter ABI Platform
certbot_httpreq-0.0.22-py3-none-any.whl Python 3 none any Details

Total release size: 46.4 kB

Release files / certbot_httpreq-0.0.22.tar.gz

Download URL certbot_httpreq-0.0.22.tar.gz
Size 26.6 kB
Tags Source
SHA-256 checksum
How to use checksums
5d81bce2efd3faafac790f4b99eb2a20b30bb5d2e3a96ec84104a438b3832524
BLAKE2b-256 checksum
How to use checksums
e212df80c17c5919a62b8d55ad34d2be344be05c19f3bef1b2eed33d5a877304
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / certbot_httpreq-0.0.22-py3-none-any.whl

Download URL certbot_httpreq-0.0.22-py3-none-any.whl
Size 19.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
2ac12f24f42db4f0bebfb889c5bee652d7599b9c571c4d251f489d428c5cb260
BLAKE2b-256 checksum
How to use checksums
526a71873cca169b6cf2dbeaddfa6da10e87384dc52cd2316ddad0e5c97ccfcb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.0.22 This release

2 release files

0.0.20

2 release files

0.0.17

2 release files

0.0.16

2 release files

0.0.15

2 release files

0.0.14

2 release files

0.0.12

2 release files

0.0.11

2 release files

0.0.10

2 release files

0.0.9

2 release files

0.0.8

2 release files

0.0.7

2 release files

0.0.6

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page