Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
World desk4 min

How to Handle SSL Certificate Errors in Selenium WebDriver

Set WebDriver’s acceptInsecureCerts capability before creating a session to proceed past an invalid test certificate—or leave it off when the test must verify TLS validation.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To let a Selenium browser navigate past an invalid or self-signed certificate, set the WebDriver capability acceptInsecureCerts to true in the browser options before creating the session. It applies for the whole session. Leave it disabled when the test is supposed to detect certificate problems: accepting an invalid certificate bypasses browser validation; it does not fix the certificate.

What the SSL certificate setting does

“SSL certificate error” is common search wording; current Selenium documentation describes the setting in terms of TLS certificates. The WebDriver capability is acceptInsecureCerts. When enabled, it tells the browser to trust invalid certificates during the session, including self-signed certificates. When disabled, navigation to a domain with certificate problems returns an insecure-certificate error.

This is a test-environment choice, not a certificate repair. It does not make an expired certificate valid, correct a hostname mismatch, or show that a production site has valid TLS. MDN describes insecure-certificate errors as occurring when the controlled browser encounters a certificate warning, commonly because a certificate is expired or invalid, and cautions that bypassing checks weakens the test environment.

Choose whether to bypass validation

  • Test certificate handling: Keep acceptInsecureCerts false (the default unless your setup changes it). Fix the test endpoint, certificate chain, hostname, or trust configuration so the browser receives the certificate the test expects.
  • Test application behavior behind a known-invalid test certificate: Set the capability to true for that session, and keep the bypass limited to tests that need it.

Do not suppress validation just to make an unexplained browser error disappear. A run that succeeds with certificate checks bypassed does not establish that certificate validation works.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set the capability before creating the WebDriver session

Configure it through the browser Options or capabilities object and pass that object when creating the driver. It is a session capability, not a per-navigation switch.

Python with a remote WebDriver

This pattern uses Selenium’s Python binding and a remote endpoint such as a Grid. Set grid_url to the command-executor URL for your environment.

from selenium import webdriver
from selenium.webdriver.chrome.options import Options

# Replace with your Grid or hosted-browser command-executor URL.
grid_url = "http://localhost:4444"

options = Options()
options.set_capability("acceptInsecureCerts", True)

driver = webdriver.Remote(command_executor=grid_url, options=options)
try:
    driver.get("https://your-test-host.example")
    print(driver.title)
finally:
    driver.quit()

For local Chrome, use Chrome Options when constructing the local driver:

from selenium import webdriver
from selenium.webdriver.chrome.options import Options

options = Options()
options.set_capability("acceptInsecureCerts", True)

driver = webdriver.Chrome(options=options)
try:
    driver.get("https://your-test-host.example")
    print(driver.title)
finally:
    driver.quit()

JavaScript API

The Selenium JavaScript API exposes setAcceptInsecureCerts(accept) on the options object. Set it before building the driver:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
const { Builder } = require('selenium-webdriver');
const chrome = require('selenium-webdriver/chrome');

const options = new chrome.Options();
options.setAcceptInsecureCerts(true);

(async () => {
  const driver = await new Builder()
    .forBrowser('chrome')
    .setChromeOptions(options)
    .build();
  try {
    await driver.get('https://your-test-host.example');
    console.log(await driver.getTitle());
  } finally {
    await driver.quit();
  }
})();

Use the syntax supported by the Selenium binding and version installed in your project. ChromeDriver documentation also lists acceptInsecureCerts as a capability. Prefer this standard WebDriver capability over browser command-line flags such as ignore-certificate-errors when this is the behavior you need.

Remote Grid or hosted browser

Pass the option in the session request, as in the Python remote example, then verify that the remote end accepts and applies it. Behavior can depend on the browser, driver, Grid, or hosted provider; the documented capability does not establish a complete compatibility matrix for every combination.

Troubleshoot a certificate failure

  1. Identify the certificate problem. Determine whether the certificate is expired, issued by an untrusted authority (including a self-signed certificate), or associated with a hostname/domain problem. Do not bypass validation before deciding what the test is meant to prove.
  2. If validation is the test, keep the capability false. Correct the endpoint, certificate chain, hostname, or trust setup so the browser receives the expected valid certificate. The exact repair depends on the test environment.
  3. If proceeding past the invalid certificate is intentional, set the capability to true before creating the driver. Changing a setting after the session starts will not configure that existing session.
  4. If navigation still fails, inspect the negotiated capabilities and browser, driver, Grid, or provider logs. Confirm the capability reached the remote end and check that the specific browser/provider combination applies it. Provider-specific behavior is not established by the general Selenium capability documentation.
  5. Keep the bypass scoped. Separate tests that exercise application behavior behind a test certificate from tests that verify normal certificate validation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your goal is a website screenshot rather than Selenium-driven interaction or certificate testing, ScreenshotNeo is a screenshot API and MCP server for developers. A single GET request returns an image or PDF; it is not a replacement for Selenium tests of TLS validation. Its clean-shot options remove cookie/consent banners, newsletter popups, and chat widgets before capture. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and the response identifies the page verdict and billing status. Its MCP server lets AI agents use screenshot tools. The free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots.

Example request (replace the target URL as needed):

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo documentation for setup and options. Sign up for 1,000 free screenshots a month, with no card required.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.