Skip to main content

ACME HTTP Connector · Certbot adapter

Publish HTTP-01 challenges and deploy your Certbot certificates through an HTTP API.

PyPI Python License

Documentation · Source code · Issues · Independent core

What it does

certbot-httpreq adds two plugins to Certbot. Together they connect certificate issuance and renewal to your existing HTTP services.

Plugin Role
certbot-httpreq:auth Publish and clean up HTTP-01 challenges through your API
certbot-httpreq:installer Send the certificate, private key and chain to your deployment API

The project is now called ACME HTTP Connector. The package name, plugin names and configuration options are preserved for existing Certbot installations.

Installation

Requires Python 3.10+ and Certbot 2.11–5.x. Install in the same Python environment as Certbot; a separate pip environment does not extend a snap installation.

python -m pip install certbot-httpreq
certbot plugins

The independent acme-http-connector core is installed automatically. Adapter 0.0.24 uses core 0.2.x.

Using Dehydrated? Install only acme-http-connector and use its acme-http-dehydrated HTTP-01 hook; Certbot is not required. See the Dehydrated guide.

Quick start

1. Configure your endpoints

Save the following as /etc/letsencrypt/certbot-httpreq.yml, replacing the example URLs with your own services:

perform:
  uri: https://api.example.com
  path: /challenges
  method: PUT
  format: json
  param_validation: value

cleanup:
  uri: https://api.example.com
  path: /challenges
  method: DELETE

deploy:
  uri: https://api.example.com
  path: /certificates
  method: POST
  format: json

TLS verification is enabled and the socket timeout is 30 seconds by default. Each section can override headers, timeout and verify independently.

2. Request a certificate

certbot run \
  --agree-tos --text --email admin@example.com \
  -a certbot-httpreq:auth \
  -i certbot-httpreq:installer \
  -d example.com

Your API must publish the challenge at http://example.com/.well-known/acme-challenge/<token>. The adapter also verifies it against the host in perform.uri and its explicit port, or Certbot's HTTP-01 port. That host must serve the challenge too.

3. Renew

certbot renew

Certbot invokes the configured plugins for challenge handling and certificate deployment. Deployment sends the first certificate name as domain and includes the complete certificate, including its additional names.

Use certbot renew --dry-run with a test API first: challenge publication and cleanup still make real HTTP requests.

Configuration

Need Setting
Custom config file --certbot-httpreq:auth-config and --certbot-httpreq:installer-config
API authentication headers in each phase
Challenge path as a query parameter param_challenge
Named key authorization field param_validation
Custom deployment field names body_params under deploy
Custom TLS trust store CA bundle path in verify
Environment overrides CBT_HTTPREQ_<PHASE>_<OPTION>

See the full configuration reference and complete example file. Use HTTPS for remote deployment and protect API credentials: certificate payloads include the private key.

Compatibility

Existing commands, plugin names, YAML settings and environment variables continue to work. Since version 0.0.21, the shared HTTP transport lives in the independent core package. Certbot handles ACME issuance; the connector handles your HTTP APIs.

Project

Report an issue · Release history · Roadmap

Copyright © 2019–2026 Adrien Delle Cave. Licensed under GPL-3.0-or-later.

HTTP redirects are refused for publish, cleanup and deployment. Configure the final API URL directly; redirects do not trigger another request or count as success.

Metadata

Release files for certbot-httpreq 0.0.24

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for certbot-httpreq 0.0.24
File Size Uploaded
certbot_httpreq-0.0.24.tar.gz 25.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for certbot-httpreq 0.0.24
File Interpreter ABI Platform
certbot_httpreq-0.0.24-py3-none-any.whl Python 3 none any Details

Total release size: 45.9 kB

Release files / certbot_httpreq-0.0.24.tar.gz

Download URL certbot_httpreq-0.0.24.tar.gz
Size 25.9 kB
Tags Source
SHA-256 checksum
How to use checksums
5d7cabd67db11059996ff1a95ae22da5002b19b4fde035b82abb884105191180
BLAKE2b-256 checksum
How to use checksums
518666ab1fd23e00e8d6e470878ae9e88975c990de58d8af35c0a4d6381eb922
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log

Release files / certbot_httpreq-0.0.24-py3-none-any.whl

Download URL certbot_httpreq-0.0.24-py3-none-any.whl
Size 20.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
1c8351973937fc1d0289bc6ccdd69a974964df70e4beeae6dc984048b5c6cd27
BLAKE2b-256 checksum
How to use checksums
19dd4b28caf03ca0d16d43fd94ce4cdd3b1672125ac97a49b4f277f43faefa88
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.0.24 This release

2 release files

0.0.20

2 release files

0.0.17

2 release files

0.0.16

2 release files

0.0.15

2 release files

0.0.14

2 release files

0.0.12

2 release files

0.0.11

2 release files

0.0.10

2 release files

0.0.9

2 release files

0.0.8

2 release files

0.0.7

2 release files

0.0.6

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page