Configure a Custom SSL Certificate
An SSL certificate enables secure HTTPS connections. When you add a custom domain to your app, App Platform automatically issues a free Let's Encrypt certificate for it and renews it before it expires.
If you've purchased a certificate separately, you can use it instead of Let's Encrypt.
Limitations Copy link
- You can replace the certificate only for a custom domain assigned to your app. App Platform manages the certificate for the technical domain.
- You can't change the certificate while the app is unpaid or blocked.
- Installation fails if the certificate has expired, was issued for a different domain, or doesn't match the private key.
- A wildcard certificate for
*.example.comdoesn't coverexample.comitself. To use it for the root domain, make sureexample.comis also listed in the certificate. - Any certificate change triggers a redeploy. The new certificate takes effect only after the deployment completes.
Install a Custom Certificate Copy link
Before you start, add your custom domain to the app.
- Go to App Platform and select your app.
- Open the Settings tab.
- Next to SSL certificates, click Configure.
- Select a domain from the drop-down list.
- On the Custom tab:
- Paste the certificate text into the Certificate field, or click Upload from file and select a
.crtfile. You can provide the full certificate chain. - Paste the key text into the Private key field, or upload a
.keyfile.
- Paste the certificate text into the Certificate field, or click Upload from file and select a
- Click Reinstall.
- Confirm the action.
Wait for the deployment to finish. Once it completes, the domain will use the new certificate.
Remove a Custom Certificate Copy link
- Go to App Platform and select your app.
- Open the Settings tab.
- Next to SSL certificates, click Configure.
- Select a domain from the drop-down list.
- Open the Custom tab and click Delete.
- Confirm the action.
A domain can't be left without a certificate, so App Platform automatically issues a Let's Encrypt certificate for it again and renews it as usual. This triggers a redeploy, and the Let's Encrypt certificate takes effect once the deploy completes.