Pricing
Pick a one-time certificate or a subscription that reissues automatically. You'll confirm exact hostnames later in the order flow.
Duration
Additional hostnames
Beyond your primary domain (SANs).
Included
- ✓Domain validation (DNS or HTTP)
- ✓Wildcard certificates supported (DNS validation required)
- ✓Automatic issuance via Let's Encrypt / ZeroSSL (ACME)
- ✓Order status tracking with a live timeline
- ✓Certificate download the moment it's issued
- ✓No tracking, no data resale, minimal retention
All public CAs are capped by the CA/Browser Forum schedule (200 days in 2026, 100 in 2027, 47 in 2029) regardless of provider. Short 7/14/30-day terms here are a product policy layered on top via rotation, not a special deal from any one CA.
Estimated total
Select a duration to see pricing.
FAQ
- Are these prices per certificate or per year?
- For one-time orders, per certificate, for the validity period you choose. For subscriptions, one payment covers the whole term — see "Do you offer multi-year certificates?" below.
- Do you offer multi-year certificates?
- Not a single multi-year certificate — no public CA can issue one; validity is capped industry-wide (200 days now, dropping to 100 in 2027 and 47 in 2029). Our subscription plan is the multi-year equivalent: pay once, and we reissue a fresh short-lived certificate automatically on your chosen cadence for 12 or 24 months.
- Why not just run my own renewal automation instead?
- If you're already running certbot, acme.sh, or cert-manager, you probably don't need this — that's a completely reasonable, free way to solve the same problem, and we're not going to pretend otherwise. The subscription is for the opposite case: you want certificates that rotate automatically without standing up and maintaining that tooling yourself, or you're on a platform where running an ACME client directly isn't practical.
- What counts as an additional hostname?
- Any Subject Alternative Name beyond your primary domain — e.g. www.example.com alongside example.com, or a second subdomain.
- Do you support wildcard certificates?
- Yes — enter *.example.com as your primary domain or an additional hostname. Wildcards require DNS validation (adding a TXT record) since there's no way to prove control of every possible subdomain over HTTP; we'll select DNS validation for you automatically once a wildcard is in the order.
- Can I change my duration after ordering?
- Not on an issued certificate — you'd place a new order. You can change duration freely while you're still in the order flow, before Review.