7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

Lego

Open source

ACME client and Go library for obtaining and renewing TLS certificates from Let's Encrypt and other certificate authorities.

Open-source alternative to

go-acme.github.io
Lego homepage screenshot
GitHub stars
9.9k
Last commit
5 days ago
Repository age
11 years
Version
v5.5.2
Licence
MIT
Self-hosted
Yes

About Lego

Lego is an ACME client and library written in Go, built to obtain and renew certificates from Let's Encrypt and other ACME certificate authorities. It can be used as a command-line tool or embedded in other Go software, which makes HTTPS certificates easy to automate.

It implements ACME v2 as defined in RFC 8555 and supports related standards, including the TLS-ALPN challenge extension, certificates for IP addresses, Renewal Information and several draft extensions. Its challenge support covers HTTP-01, DNS-01 and TLS-ALPN-01, and it ships with integrations for more than 200 DNS providers. It can register with a CA, obtain certificates from scratch or from an existing CSR, renew and revoke them, and handle SAN certificates and custom challenge solvers.

Lego is released under the MIT license. It is described as an independent, free project that relies on donations, and its documentation is hosted online. If a DNS provider is missing, users are encouraged to open an issue to request support.

Key features

  • ACME v2 client per RFC 8555
  • HTTP-01, DNS-01 and TLS-ALPN-01 challenges
  • More than 200 DNS provider integrations
  • Obtain, renew and revoke certificates
  • SAN certificates and custom solvers
  • Usable as a CLI or Go library

Good fit for

  • →Automating Let's Encrypt renewals
  • →Embedding certificate management in Go apps
Built with
Go
Tags
acme
letsencrypt
tls
certificates
dns
https
go
cli

Lego: questions and answers

What is Lego used for?
Lego is an ACME client and Go library for obtaining and renewing TLS certificates from Let's Encrypt and other certificate authorities. It is a good fit for automating Let's Encrypt renewals and embedding certificate management in Go apps.
Is Lego open source?
Yes. Lego is open source under the MIT licence. Its source code is on GitHub at go-acme/lego and is written mainly in Go.
Is Lego free?
Yes. Lego is open source, so the software itself is free to use.
What is Lego an alternative to?
Lego is an open-source alternative to DigiCert, Sectigo and GlobalSign. Other open-source alternatives to DigiCert include Certbot, acme.sh and step-ca.
Is Lego actively maintained?
Yes. The most recent commit to Lego was on 27 September 2026, and the latest release is v5.5.2, published on 23 September 2026. The project has 9.9k stars on GitHub.

Open-source alternatives to Lego

See all

SaaS alternatives to Lego

See all