About Lego
Lego is an ACME client and library written in Go, built to obtain and renew certificates from Let's Encrypt and other ACME certificate authorities. It can be used as a command-line tool or embedded in other Go software, which makes HTTPS certificates easy to automate.
It implements ACME v2 as defined in RFC 8555 and supports related standards, including the TLS-ALPN challenge extension, certificates for IP addresses, Renewal Information and several draft extensions. Its challenge support covers HTTP-01, DNS-01 and TLS-ALPN-01, and it ships with integrations for more than 200 DNS providers. It can register with a CA, obtain certificates from scratch or from an existing CSR, renew and revoke them, and handle SAN certificates and custom challenge solvers.
Lego is released under the MIT license. It is described as an independent, free project that relies on donations, and its documentation is hosted online. If a DNS provider is missing, users are encouraged to open an issue to request support.
Key features
- ACME v2 client per RFC 8555
- HTTP-01, DNS-01 and TLS-ALPN-01 challenges
- More than 200 DNS provider integrations
- Obtain, renew and revoke certificates
- SAN certificates and custom solvers
- Usable as a CLI or Go library
Good fit for
- →Automating Let's Encrypt renewals
- →Embedding certificate management in Go apps
- Built with
- Go
- Tags
- acme
- letsencrypt
- tls
- certificates
- dns
- https
- go
- cli
Lego: questions and answers
- What is Lego used for?
- Lego is an ACME client and Go library for obtaining and renewing TLS certificates from Let's Encrypt and other certificate authorities. It is a good fit for automating Let's Encrypt renewals and embedding certificate management in Go apps.
- Is Lego open source?
- Yes. Lego is open source under the MIT licence. Its source code is on GitHub at go-acme/lego and is written mainly in Go.
- Is Lego free?
- Yes. Lego is open source, so the software itself is free to use.
- What is Lego an alternative to?
- Lego is an open-source alternative to DigiCert, Sectigo and GlobalSign. Other open-source alternatives to DigiCert include Certbot, acme.sh and step-ca.
- Is Lego actively maintained?
- Yes. The most recent commit to Lego was on 27 September 2026, and the latest release is v5.5.2, published on 23 September 2026. The project has 9.9k stars on GitHub.
Open-source alternatives to Lego
See all
Certbot
Security
Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTP
OSSvs DigiCert★ 33k
acme.sh
Security
A pure Unix shell script ACME client for SSL / TLS certificate automation
GPL-3.0vs DigiCert★ 48k
step-ca
Security
🛡️ A private certificate authority (X.509 & SSH) & ACME server for secure automated certi
Apache-2.0vs Entrust★ 8.9k
Certimate
Security
ssl tls https ssl-certificate ssl-certificates ssl-cert https-certificate https-certificat
MITvs Sectigo★ 9.3k
Certd
Security
开源SSL证书管理工具;全自动证书申请、更新、续期;通配符证书,泛域名证书申请;证书自动化部署到阿里云、腾讯云、主机、群晖、宝塔;https证书,pfx证书,der证书,TLS证书
AGPL-3.0vs Sectigo★ 5k
Grype
Security
A vulnerability scanner for container images and filesystems
Apache-2.0vs Snyk★ 13k
SaaS alternatives to Lego
See all
DigiCert
Security
Certificate authority and digital trust provider for TLS and PKI
SaaS
Sectigo
Security
Certificate authority offering TLS certificates and certificate lifecycle management
SaaS
GlobalSign
Security
Certificate authority and digital identity provider
SaaS
Entrust
Security
Identity security provider with MFA, PKI, identity verification and payments security
SaaS
Keyfactor
Security
Machine identity and PKI management platform
SaaS
AgentScan
Security
Scans AI coding agent skills for security issues and distributes reviewed workflows for Claude Code and others
SaaS

