mkcert Web UI

Web interface for mkcert CLI to manage development TLS certificates

222 stars 12 forks last commit first released GPL-3.0

Actively maintained

Last commit 23 Aug 2026.

mkcert Web UI provides a browser-based interface for the mkcert CLI to create and manage locally-trusted development TLS/SSL certificates. It exposes certificate generation, downloads, monitoring, and a built-in SCEP enrollment service while enforcing input validation and rate limits for security.

Key Features

  • Certificate generation for multiple domains and IPs with PEM, CRT and password-protected PFX (PKCS#12) output
  • Built-in SCEP server supporting GetCACert and GetCACaps for automated device enrollment and challenge-based authentication
  • Enterprise-grade protections: allowlist command validation, path traversal prevention, filename validation, input sanitization, and multi-tier rate limiting
  • Flexible authentication: basic auth and OpenID Connect SSO support; session secret configuration
  • Certificate monitoring with configurable warning/critical thresholds and automated email notifications for expiring certificates
  • Docker and docker-compose deployment support and a simple HTTP API for generate, list, download, and monitoring endpoints

Use Cases

  • Centralize generation and distribution of development TLS certificates for local networks and developer teams
  • Automate certificate provisioning on devices using the SCEP service for managed device enrollment
  • Monitor certificate expiry across development assets and send email alerts to administrators

Limitations and Considerations

  • Requires the mkcert CLI and local trust of the mkcert root CA; initial root CA installation is a prerequisite
  • No built-in hardware security module (HSM) or remote CA integration; keys and certificates are stored on local filesystem by default
  • Exposing SCEP or the management UI publicly requires careful network and authentication configuration to avoid security risks

mkcert Web UI is suited for teams and developers who need an accessible UI to run mkcert at scale in development environments. It simplifies certificate workflows while retaining the underlying mkcert trust model and operational constraints.

Categories:

Tags:

Tech Stack:

Share:

Similar to mkcert Web UI

nextExplorer

Self-hosted web file explorer with access control and previews

1k
27
Last commit

Modern, Docker-first self-hosted web file explorer with local users/groups, optional OIDC SSO, fast previews, built-in editor, sharing links, and search.

GPL-3.0Actively maintained
Alternative to:
Dropbox logo
Dropbox
+19

UniFi Voucher Site

Generate and manage UniFi guest WiFi vouchers

301
35
Last commit

Web app to create, print, email, and manage UniFi guest vouchers with OIDC support, kiosk mode, PDF/thermal printing, and a REST API. Deployable via Docker.

MITActively maintained
Alternative to:
Proxyclick logo
Proxyclick
+1
Teikei logo

Teikei

Maps community-supported agriculture across Germany, Switzerland and Austria

66
13
Last commit

Web application and API that crowdsources and maps community-supported agriculture (CSA) locations in Germany, Switzerland and Austria; includes admin UI and REST API.

AGPL-3.0Actively maintained
LibreChat logo

LibreChat

Self-hosted multi-provider AI chat UI with agents and tools

42.5k
8.8k
Last commit

LibreChat is a self-hosted AI chat platform that supports multiple LLM providers, custom endpoints, agents/tools, file and image chat, conversation search, and presets.

MITActively maintained
Alternative to:
ChatGPT logo
ChatGPT
+11
Wiki.js logo

Wiki.js

Modern, extensible wiki software built on Node.js

28.8k
3.3k
Last commit

A modern, extensible Node.js wiki with Markdown editing, powerful admin tools, multiple auth options, and support for popular SQL databases.

AGPL-3.0Actively maintained
Alternative to:
Atlassian Confluence logo
Atlassian Confluence
+19
Dashy logo

Dashy

Self-hosted personal dashboard for links, widgets, and status checks

26.3k
1.9k
Last commit

Dashy is a self-hosted personal dashboard for organizing services in one place, with widgets, themes, live status checks, search, and optional authentication.

MITActively maintained
Alternative to:
Start.me logo
Start.me
+9