acme.sh
A lightweight ACME client written purely in Unix shell that issues, renews and installs SSL/TLS certificates without depending on Python.
- GitHub stars
- 48k
- Last commit
- 5 days ago
- Latest release
- 3.1.6
- Licence
- GPL-3.0
- Self-hosted
- Yes

acme.sh is an ACME protocol client written entirely in Unix shell. It implements the full ACME protocol and uses a single script to issue, renew and install SSL/TLS certificates automatically. It is released under the GPL-3.0 license and works with Bash, dash and sh, with no dependency on Python.
It supports ECDSA certificates as well as SAN and wildcard certificates, and its topics reference certificate authorities such as Let's Encrypt, ZeroSSL and Buypass. The project is described as simple to learn, and it does not need root access.
Since 2021 acme.sh has been sponsored and maintained by ZeroSSL, and it now has a dedicated website. As certificate lifetimes shorten, automated renewal becomes more important, which is the problem the tool addresses. It suits system administrators and developers who want a minimal, scriptable alternative to Certbot for web servers, appliances and containers.
Key features
- ACME client written purely in shell
- Issue, renew and install certificates
- ECDSA, SAN and wildcard certificate support
- Works with Bash, dash and sh
- No Python dependency
- Works with Let's Encrypt and ZeroSSL
Pricing: Free tier with 3 90-day SSL certificates. Basic $14.99/month (billed yearly) for unlimited 90-day certificates. Premium $68.99/month through Platinum $219.99/month with increasing annual certificate allowances.

