Start by securing a single domain in minutes with a guided flow. Enter your host name, generate or upload a CSR, and pick how you want to prove control: place a small file on your site, add a DNS TXT record, or confirm via email. ZeroSSL walks you through each step with copy‑ready values and live status checks so you always know what’s next. Once verified, choose the format your server expects (PEM, PFX, etc.), include the intermediate chain, and follow the install notes for Apache, NGINX, IIS, or your CDN. Finish with the built‑in checker to confirm the chain, hostname coverage (including SANs), and expiration date before you flip traffic.
Running infrastructure at scale? Point your ACME client to the ZeroSSL directory and let your existing tooling do the heavy lifting. Certbot, acme.sh, and other ACME agents can request new certs, handle HTTP or DNS challenges, and renew on a schedule without manual touch. Use DNS validation for wildcard hosts and automation‑friendly flows; store credentials securely, and script record creation through your DNS provider. For containers and clusters, attach ACME to your ingress controller so every new service endpoint gets protection on deployment. Keep staging and production separate with different accounts or labels and roll out updates with zero downtime.
For deadlines and teams, switch on certificate health checks and expiry alerts. ZeroSSL can watch your endpoints and notify you by email or webhook well before a cert is due. If you prefer a fully hands‑off approach, enable the managed automation bot to re‑validate and rotate certs for supported environments. Track everything in one place: see which domains are covered, filter by status, and export details for audits. When rotating keys, use overlapping validity to avoid gaps, and schedule renewals during low‑traffic windows. If a check fails, follow the diagnostic hints to fix DNS propagation, firewall blocks, or misconfigured virtual hosts.
Developers can integrate issuance into build and release pipelines via the REST API. Create an order, upload a CSR, select a challenge type, then poll for status until it’s ready to download. Attach tags for project names, push results to secrets stores, and reload services with a post‑deploy hook. Content creators launching a blog on a custom domain can use the web UI: request a multi‑domain cert covering www and apex, add the single TXT record, and publish. Agencies managing dozens of client sites can template the process—standardize CSR fields, automate DNS challenges through a provider API, and enforce a uniform renewal window so every property stays green without calendar juggling.
Free
Free
90-Day Certificates
ACME Certificates
Basic
$8.00 per month
90-Day Certificates
3 1-Year Certificates
Multi-Domain Certs
ACME Certificates
REST API Access
Technical Support
Premium
$40.00 per month
90-Day Certificates
10 1-Year Certificates
Multi-Domain Certs
90-Day Wildcard
1 1-Year Wildcards
ACME Certificates
REST API Access
Technical Support
Business
$80.00 per month
90-Day Certificates
25 1-Year Certificates
Multi-Domain Certs
90-Day Wildcards
3 1-Year Wildcards
ACME Certificates
REST API Access
Technical Support
Enterprise
Custom
90-Day Certificates
1-Year Certificates
Multi-Domain Certs
90-Day Wildcards
1-Year Wildcards
ACME Certificates
REST API Access
Technical Support
Custom Solutions
Comments