Configure a Custom SSL Certificate


An SSL certificate enables secure HTTPS connections. When you add a custom domain to your app, App Platform automatically issues a free Let's Encrypt certificate for it and renews it before it expires.

If you've purchased a certificate separately, you can use it instead of Let's Encrypt.

Limitations
Copy link

  • You can replace the certificate only for a custom domain assigned to your app. App Platform manages the certificate for the technical domain.
  • You can't change the certificate while the app is unpaid or blocked.
  • Installation fails if the certificate has expired, was issued for a different domain, or doesn't match the private key.
  • A wildcard certificate for *.example.com doesn't cover example.com itself. To use it for the root domain, make sure example.com is also listed in the certificate.
  • Any certificate change triggers a redeploy. The new certificate takes effect only after the deployment completes.

Install a Custom Certificate
Copy link

Before you start, add your custom domain to the app.

  1. Go to App Platform and select your app.
  2. Open the Settings tab.
  3. Next to SSL certificates, click Configure.
  4. Select a domain from the drop-down list.
  5. On the Custom tab:
    • Paste the certificate text into the Certificate field, or click Upload from file and select a .crt file. You can provide the full certificate chain.
    • Paste the key text into the Private key field, or upload a .key file.
  6. Click Reinstall.
  7. Confirm the action.

Wait for the deployment to finish. Once it completes, the domain will use the new certificate.

Remove a Custom Certificate
Copy link

  1. Go to App Platform and select your app.
  2. Open the Settings tab.
  3. Next to SSL certificates, click Configure.
  4. Select a domain from the drop-down list.
  5. Open the Custom tab and click Delete.
  6. Confirm the action.

A domain can't be left without a certificate, so App Platform automatically issues a Let's Encrypt certificate for it again and renews it as usual. This triggers a redeploy, and the Let's Encrypt certificate takes effect once the deploy completes.