7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

acme.sh

Open source

A lightweight ACME client written purely in Unix shell that issues, renews and installs SSL/TLS certificates without depending on Python.

Open-source alternative to

acme.sh
acme.sh homepage screenshot
GitHub stars
48k
Last commit
5 days ago
Repository age
10 years
Version
3.1.6
Licence
GPL-3.0
Self-hosted
Yes

About acme.sh

acme.sh is an ACME protocol client written entirely in Unix shell. It implements the full ACME protocol and uses a single script to issue, renew and install SSL/TLS certificates automatically. It is released under the GPL-3.0 license and works with Bash, dash and sh, with no dependency on Python.

It supports ECDSA certificates as well as SAN and wildcard certificates, and its topics reference certificate authorities such as Let's Encrypt, ZeroSSL and Buypass. The project is described as simple to learn, and it does not need root access.

Since 2021 acme.sh has been sponsored and maintained by ZeroSSL, and it now has a dedicated website. As certificate lifetimes shorten, automated renewal becomes more important, which is the problem the tool addresses. It suits system administrators and developers who want a minimal, scriptable alternative to Certbot for web servers, appliances and containers.

Key features

  • ACME client written purely in shell
  • Issue, renew and install certificates
  • ECDSA, SAN and wildcard certificate support
  • Works with Bash, dash and sh
  • No Python dependency
  • Works with Let's Encrypt and ZeroSSL

Good fit for

  • →Automating TLS certificates on servers
  • →Wildcard certificates for many subdomains
  • →Lightweight alternative to Certbot
Built with
Shell
Tags
acme
ssl
tls
lets-encrypt
certificates
shell
zerossl
automation

acme.sh: questions and answers

What is acme.sh used for?
acme.sh is a lightweight ACME client written purely in Unix shell that issues, renews and installs SSL/TLS certificates without depending on Python. It is a good fit for automating TLS certificates on servers and wildcard certificates for many subdomains.
Is acme.sh open source?
Yes. acme.sh is open source under the GPL-3.0 licence. Its source code is on GitHub at acmesh-official/acme.sh and is written mainly in Shell.
Is acme.sh free?
Yes. acme.sh is open source, so the software itself is free to use. Paid plans are also available, starting at $14.99 per month.
What is acme.sh an alternative to?
acme.sh is an open-source alternative to DigiCert, Sectigo and GlobalSign. Other open-source alternatives to DigiCert include Certbot, Lego and step-ca.
Is acme.sh actively maintained?
Yes. The most recent commit to acme.sh was on 27 September 2026, and the latest release is 3.1.6, published on 20 September 2026. The project has 48k stars on GitHub.

Open-source alternatives to acme.sh

See all

SaaS alternatives to acme.sh

See all