To let a Selenium browser navigate past an invalid or self-signed certificate, set the WebDriver capability acceptInsecureCerts to true in the browser options before creating the session. It applies for the whole session. Leave it disabled when the test is supposed to detect certificate problems: accepting an invalid certificate bypasses browser validation; it does not fix the certificate.
What the SSL certificate setting does
“SSL certificate error” is common search wording; current Selenium documentation describes the setting in terms of TLS certificates. The WebDriver capability is acceptInsecureCerts. When enabled, it tells the browser to trust invalid certificates during the session, including self-signed certificates. When disabled, navigation to a domain with certificate problems returns an insecure-certificate error.
This is a test-environment choice, not a certificate repair. It does not make an expired certificate valid, correct a hostname mismatch, or show that a production site has valid TLS. MDN describes insecure-certificate errors as occurring when the controlled browser encounters a certificate warning, commonly because a certificate is expired or invalid, and cautions that bypassing checks weakens the test environment.
Choose whether to bypass validation
- Test certificate handling: Keep
acceptInsecureCertsfalse (the default unless your setup changes it). Fix the test endpoint, certificate chain, hostname, or trust configuration so the browser receives the certificate the test expects. - Test application behavior behind a known-invalid test certificate: Set the capability to true for that session, and keep the bypass limited to tests that need it.
Do not suppress validation just to make an unexplained browser error disappear. A run that succeeds with certificate checks bypassed does not establish that certificate validation works.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Set the capability before creating the WebDriver session
Configure it through the browser Options or capabilities object and pass that object when creating the driver. It is a session capability, not a per-navigation switch.
Python with a remote WebDriver
This pattern uses Selenium’s Python binding and a remote endpoint such as a Grid. Set grid_url to the command-executor URL for your environment.
Rank #2
from selenium import webdriver
from selenium.webdriver.chrome.options import Options
# Replace with your Grid or hosted-browser command-executor URL.
grid_url = "http://localhost:4444"
options = Options()
options.set_capability("acceptInsecureCerts", True)
driver = webdriver.Remote(command_executor=grid_url, options=options)
try:
driver.get("https://your-test-host.example")
print(driver.title)
finally:
driver.quit()
For local Chrome, use Chrome Options when constructing the local driver:
from selenium import webdriver
from selenium.webdriver.chrome.options import Options
options = Options()
options.set_capability("acceptInsecureCerts", True)
driver = webdriver.Chrome(options=options)
try:
driver.get("https://your-test-host.example")
print(driver.title)
finally:
driver.quit()
JavaScript API
The Selenium JavaScript API exposes setAcceptInsecureCerts(accept) on the options object. Set it before building the driver:
Recommended Free Tools
Rank #3
const { Builder } = require('selenium-webdriver');
const chrome = require('selenium-webdriver/chrome');
const options = new chrome.Options();
options.setAcceptInsecureCerts(true);
(async () => {
const driver = await new Builder()
.forBrowser('chrome')
.setChromeOptions(options)
.build();
try {
await driver.get('https://your-test-host.example');
console.log(await driver.getTitle());
} finally {
await driver.quit();
}
})();
Use the syntax supported by the Selenium binding and version installed in your project. ChromeDriver documentation also lists acceptInsecureCerts as a capability. Prefer this standard WebDriver capability over browser command-line flags such as ignore-certificate-errors when this is the behavior you need.
Remote Grid or hosted browser
Pass the option in the session request, as in the Python remote example, then verify that the remote end accepts and applies it. Behavior can depend on the browser, driver, Grid, or hosted provider; the documented capability does not establish a complete compatibility matrix for every combination.
Rank #4
Troubleshoot a certificate failure
- Identify the certificate problem. Determine whether the certificate is expired, issued by an untrusted authority (including a self-signed certificate), or associated with a hostname/domain problem. Do not bypass validation before deciding what the test is meant to prove.
- If validation is the test, keep the capability false. Correct the endpoint, certificate chain, hostname, or trust setup so the browser receives the expected valid certificate. The exact repair depends on the test environment.
- If proceeding past the invalid certificate is intentional, set the capability to true before creating the driver. Changing a setting after the session starts will not configure that existing session.
- If navigation still fails, inspect the negotiated capabilities and browser, driver, Grid, or provider logs. Confirm the capability reached the remote end and check that the specific browser/provider combination applies it. Provider-specific behavior is not established by the general Selenium capability documentation.
- Keep the bypass scoped. Separate tests that exercise application behavior behind a test certificate from tests that verify normal certificate validation.
Or skip the browser setup
If your goal is a website screenshot rather than Selenium-driven interaction or certificate testing, ScreenshotNeo is a screenshot API and MCP server for developers. A single GET request returns an image or PDF; it is not a replacement for Selenium tests of TLS validation. Its clean-shot options remove cookie/consent banners, newsletter popups, and chat widgets before capture. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and the response identifies the page verdict and billing status. Its MCP server lets AI agents use screenshot tools. The free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots.
Example request (replace the target URL as needed):
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo documentation for setup and options. Sign up for 1,000 free screenshots a month, with no card required.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




