On this page
Overview
mkcert is a CLI for local-development TLS certificates. It can create a local CA, install trust into supported system and browser stores, and issue certificates for localhost, IP addresses, development domains, and wildcard names with minimal configuration.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Create a local CA and install trust into development stores
mkcert -install creates a local CA and can add it to supported system, Firefox, Chrome/Chromium, and Java trust stores, avoiding self-signed-certificate warnings in local HTTPS development.
Sources: [1]
Put multiple domains, IP addresses, and wildcards in one certificate
A single certificate can include localhost, IPv4 or IPv6 addresses, test domains, wildcard names, and other Subject Alternative Names supplied on the command line.
Sources: [1]
Support client certificates, ECDSA, PKCS#12, and CSRs
Beyond normal server certificates, mkcert supports client authentication, ECDSA keys, PKCS#12 output, and certificate generation from an existing CSR.
Sources: [1]
Best fit
Fits local HTTPS development without public CAs or manual OpenSSL setup
It is useful for web applications and APIs that need trusted https://localhost or development-domain testing without obtaining public certificates or manually maintaining OpenSSL CA commands.
Sources: [1]
Before adoption
Protect the root CA private key and never share it
The README warns that rootCA-key.pem has enough authority to intercept secure requests from the machine. It must not be committed to repositories or shared with others.
Sources: [1]
Use it for development, not production certificate management
mkcert generates certificates but does not configure servers automatically, and the README explicitly positions it for development rather than end-user or production certificate deployment.
Sources: [1]
Official sources
- [1]mkcert v1.4.4 README(2026-10-04)
- [2]mkcert v1.4.4 release(2026-10-04)
- [3]mkcert BSD-3-Clause license(2026-10-04)
Supplemental curator note
mkcert is convenient because it removes trust errors from local HTTPS, but that convenience comes from owning a powerful CA private key. Protect rootCA-key.pem and keep this workflow separate from production certificate management.
Try it in 3 steps
- 1
Fetch the mkcert v1.4.4 source
Pin the checkout to the latest GitHub release tag.
git clone --depth 1 --branch v1.4.4 https://github.com/FiloSottile/mkcert.git mkcert-v1.4.4 - 2
Build the mkcert binary locally
Build inside the repository without a system install. The README documents Go 1.13+ for source builds.
cd mkcert-v1.4.4 && go build -ldflags "-X main.Version=$(git describe --tags)" - 3
Generate a development certificate without changing trust stores
This intentionally omits
-install, so system trust stores are unchanged. Keep the generated CA in this demo directory and never share_demo-ca/rootCA-key.pem.cd mkcert-v1.4.4 && mkdir -p _demo-ca _demo-certs && cd _demo-certs && CAROOT="$PWD/../_demo-ca" ../mkcert localhost 127.0.0.1 ::1 && ls -1
Growth
Growth trends · Last 30 days
59,717 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 0
- Open PRs
- 61
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- https
- tls
- certificates
- local-development
- localhost
- root-ca
- macos
- linux
- windows
- ios
- firefox
- chrome
- Stars
- 59,717
- Forks
- 3,139
- Watchers
- 509
- Open issues
- 116
- Contributors
- 37
- Owner type
- User
- Primary language
- Go
- License
- BSD-3-Clause
- Repository last updated
- Aug 13, 2024
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- OSV-Scanner11,135 Stars
2 shared tag(s) · 1 shared category(s) · Same language
scan lockfiles, source trees, containers, and SBOMs for dependency vulnerabilities using OSV data
Go - Kyverno8,213 Stars
2 shared tag(s) · 1 shared category(s) · Same language
Continuously apply policy as code through Kubernetes admission and background scans
Go - Tailscale37,129 Stars
2 shared tag(s) · Same language
Join devices to a WireGuard mesh with tailscaled/CLI while coordinating identity, NAT traversal, and policy through a managed control plane
Go - Consul30,091 Stars
2 shared tag(s) · Same language
combine service discovery, health checks, service mesh, and API gateway capabilities for distributed infrastructure
Go - Cilium25,598 Stars
2 shared tag(s) · Same language
unify Kubernetes networking, security, and observability on an eBPF dataplane
Go - cert-manager14,104 Stars
2 shared tag(s) · Same language
automate TLS certificate issuance and renewal inside Kubernetes while using ACME, Vault, and other issuers through shared resources
Go
Report incorrect information
Tell us if any listing information is incorrect or outdated.