ACME HTTP Connector · Certbot adapter
Publish HTTP-01 challenges and deploy your Certbot certificates through an HTTP API.
Documentation · Source code · Issues · Independent core
What it does
certbot-httpreq adds two plugins to Certbot. Together they connect certificate
issuance and renewal to your existing HTTP services.
| Plugin | Role |
|---|---|
certbot-httpreq:auth |
Publish and clean up HTTP-01 challenges through your API |
certbot-httpreq:installer |
Send the certificate, private key and chain to your deployment API |
The project is now called ACME HTTP Connector. The package name, plugin names and configuration options are preserved for existing Certbot installations.
Installation
Requires Python 3.10+ and Certbot 2.11–5.x. Install in the same Python environment as Certbot; a separate pip environment does not extend a snap installation.
python -m pip install certbot-httpreq
certbot plugins
The independent acme-http-connector
core is installed automatically. Adapter 0.0.23 uses core 0.2.x.
Using Dehydrated? Install only acme-http-connector and use its
acme-http-dehydrated HTTP-01 hook; Certbot is not required. See the
Dehydrated guide.
Quick start
1. Configure your endpoints
Save the following as /etc/letsencrypt/certbot-httpreq.yml, replacing the
example URLs with your own services:
perform:
uri: https://api.example.com
path: /challenges
method: PUT
format: json
param_validation: value
cleanup:
uri: https://api.example.com
path: /challenges
method: DELETE
deploy:
uri: https://api.example.com
path: /certificates
method: POST
format: json
TLS verification is enabled and the socket timeout is 30 seconds by default.
Each section can override headers, timeout and verify independently.
2. Request a certificate
certbot run \
--agree-tos --text --email admin@example.com \
-a certbot-httpreq:auth \
-i certbot-httpreq:installer \
-d example.com
Your API must publish the challenge at
http://example.com/.well-known/acme-challenge/<token>.
The adapter also verifies it against the host in perform.uri and its explicit
port, or Certbot's HTTP-01 port. That host must serve the challenge too.
3. Renew
certbot renew
Certbot invokes the configured plugins for challenge handling and certificate
deployment. Deployment sends the first certificate name as domain and includes
the complete certificate, including its additional names.
Use certbot renew --dry-run with a test API first: challenge publication and
cleanup still make real HTTP requests.
Configuration
| Need | Setting |
|---|---|
| Custom config file | --certbot-httpreq:auth-config and --certbot-httpreq:installer-config |
| API authentication | headers in each phase |
| Challenge path as a query parameter | param_challenge |
| Named key authorization field | param_validation |
| Custom deployment field names | body_params under deploy |
| Custom TLS trust store | CA bundle path in verify |
| Environment overrides | CBT_HTTPREQ_<PHASE>_<OPTION> |
See the full configuration reference and complete example file. Use HTTPS for remote deployment and protect API credentials: certificate payloads include the private key.
Compatibility
Existing commands, plugin names, YAML settings and environment variables continue to work. Since version 0.0.21, the shared HTTP transport lives in the independent core package. Certbot handles ACME issuance; the connector handles your HTTP APIs.
Project
Report an issue · Release history · Roadmap
Copyright © 2019–2026 Adrien Delle Cave. Licensed under GPL-3.0-or-later.
Metadata
Release files for certbot-httpreq 0.0.23
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| certbot_httpreq-0.0.23.tar.gz | 25.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| certbot_httpreq-0.0.23-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 45.6 kB
Release files / certbot_httpreq-0.0.23.tar.gz
| Download URL | certbot_httpreq-0.0.23.tar.gz |
|---|---|
| Size | 25.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
e2a6157e37cc52918553c4ed12caad82e473de97666a1f24056ec5cc9607208b
|
|
BLAKE2b-256 checksum How to use checksums |
49e6b2578f5849e6a3d2f602ba40f1bd43fff98a4a9e589df98d1e059cd3bc40
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.
Transparency logRelease files / certbot_httpreq-0.0.23-py3-none-any.whl
| Download URL | certbot_httpreq-0.0.23-py3-none-any.whl |
|---|---|
| Size | 19.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
b4bb7fdc2e17de3eb7390243ac4fc6c86ab9e1d16af08b0f414d80cf170d28e4
|
|
BLAKE2b-256 checksum How to use checksums |
7ff92c27aa339f3c39f20dc605783dfd7fd0db9a42660ad8dc40f96d8aa987f0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.
Transparency log