About acme.sh
acme.sh is an ACME protocol client written entirely in Unix shell. It implements the full ACME protocol and uses a single script to issue, renew and install SSL/TLS certificates automatically. It is released under the GPL-3.0 license and works with Bash, dash and sh, with no dependency on Python.
It supports ECDSA certificates as well as SAN and wildcard certificates, and its topics reference certificate authorities such as Let's Encrypt, ZeroSSL and Buypass. The project is described as simple to learn, and it does not need root access.
Since 2021 acme.sh has been sponsored and maintained by ZeroSSL, and it now has a dedicated website. As certificate lifetimes shorten, automated renewal becomes more important, which is the problem the tool addresses. It suits system administrators and developers who want a minimal, scriptable alternative to Certbot for web servers, appliances and containers.
Key features
- ACME client written purely in shell
- Issue, renew and install certificates
- ECDSA, SAN and wildcard certificate support
- Works with Bash, dash and sh
- No Python dependency
- Works with Let's Encrypt and ZeroSSL
Good fit for
- →Automating TLS certificates on servers
- →Wildcard certificates for many subdomains
- →Lightweight alternative to Certbot
- Built with
- Shell
- Tags
- acme
- ssl
- tls
- lets-encrypt
- certificates
- shell
- zerossl
- automation
acme.sh: questions and answers
- What is acme.sh used for?
- acme.sh is a lightweight ACME client written purely in Unix shell that issues, renews and installs SSL/TLS certificates without depending on Python. It is a good fit for automating TLS certificates on servers and wildcard certificates for many subdomains.
- Is acme.sh open source?
- Yes. acme.sh is open source under the GPL-3.0 licence. Its source code is on GitHub at acmesh-official/acme.sh and is written mainly in Shell.
- Is acme.sh free?
- Yes. acme.sh is open source, so the software itself is free to use. Paid plans are also available, starting at $14.99 per month.
- What is acme.sh an alternative to?
- acme.sh is an open-source alternative to DigiCert, Sectigo and GlobalSign. Other open-source alternatives to DigiCert include Certbot, Lego and step-ca.
- Is acme.sh actively maintained?
- Yes. The most recent commit to acme.sh was on 27 September 2026, and the latest release is 3.1.6, published on 20 September 2026. The project has 48k stars on GitHub.
Open-source alternatives to acme.sh
See all
Certbot
Security
Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTP
OSSvs DigiCert★ 33k
Lego
Security
Let's Encrypt/ACME client and library written in Go
MITvs DigiCert★ 9.9k
step-ca
Security
🛡️ A private certificate authority (X.509 & SSH) & ACME server for secure automated certi
Apache-2.0vs Entrust★ 8.9k
Certimate
Security
ssl tls https ssl-certificate ssl-certificates ssl-cert https-certificate https-certificat
MITvs Sectigo★ 9.3k
Certd
Security
开源SSL证书管理工具;全自动证书申请、更新、续期;通配符证书,泛域名证书申请;证书自动化部署到阿里云、腾讯云、主机、群晖、宝塔;https证书,pfx证书,der证书,TLS证书
AGPL-3.0vs Sectigo★ 5k
AllinSSL
Security
AllinSSL 是一个集证书申请、管理、部署和监控于一体的SSL证书全生命周期管理工具。AllinSSL is an all-in-one SSL certificate lif
AGPL-3.0★ 3.6k
SaaS alternatives to acme.sh
See all
DigiCert
Security
Certificate authority and digital trust provider for TLS and PKI
SaaS
Sectigo
Security
Certificate authority offering TLS certificates and certificate lifecycle management
SaaS
GlobalSign
Security
Certificate authority and digital identity provider
SaaS
Entrust
Security
Identity security provider with MFA, PKI, identity verification and payments security
SaaS
Keyfactor
Security
Machine identity and PKI management platform
SaaS
Akeyless
Security
SaaS secrets management and machine identity platform for apps and pipelines
SaaS

