Let's Encrypt

You should not use this if you are also using the DuckDNS add-on. The DuckDNS add-on has integrated Let’s Encrypt support.

Setup and manage a Let’s Encrypt certificate. This add-on will create a certificate on the first run and will auto-renew if the certificate is within 30 days of expiration. This add-on uses port 80 to verify the certificate request. You will need to stop all other add-ons that also use this port.

  "email": "example@example.com",
  "domains": ["example.com", "mqtt.example.com", "hass.example.com"],
  "certfile": "fullchain.pem",
  "keyfile": "privkey.pem"

Configuration Variables


(string)(Required)Your email address for registration on Let’s Encrypt.


(list)(Required)A list of domains to create/renew the certificate.


(string)(Required)Name of the certfile that is created. Leave as default value.

Default value: fullchain.pem


(string)(Required)Name of the keyfile that is created. Leave as default value.

Default value: privkey.pem

Home Assistant configuration

Use the following configuration in Home Assistant to use the generated certificate:

  base_url: https://my-domain.tld:8123
  ssl_certificate: /ssl/fullchain.pem
  ssl_key: /ssl/privkey.pem

If you use another port such as 8123 or an SSL proxy, change the port number.

Enabling auto-renewals

Out of the box, the add-on will not automatically renew your certificate. In fact, it only starts, tries to get/renew your certificate, and then stops. It’s up to you to manually start it again whenever your certificate comes close to expiry.

However, you can automate this process using Home Assistant.

Use this in your automations.yaml to attempt certificate renewal each day at midnight:

- id: letsencrypt-renewal
  alias: "Let's Encrypt Renewal"
  - platform: time
    at: '00:00:00'
  - service: hassio.addon_restart
      addon: core_letsencrypt