ScreenshotNeo

BlogHow-to

How to Handle SSL Certificates in Selenium WebDriver

Use Selenium’s acceptInsecureCerts capability to handle invalid TLS certificates for a test session, and learn when to fix the certificate instead.

By the ScreenshotNeo team4 October 20267 min read

Selenium WebDriver handles invalid SSL/TLS certificates with the standard acceptInsecureCerts session capability. Set it to true in the browser options before creating the driver when a test must proceed through a known-invalid certificate, such as a self-signed certificate on a test server. The setting applies to the whole WebDriver session. Leave it disabled when the test needs to verify that certificate validation works.

Despite the familiar search term “SSL,” current Selenium documentation describes this behavior in terms of TLS certificates. Accepting an insecure certificate bypasses browser validation; it does not repair the certificate or show that a production site has valid TLS. Selenium’s Browser Options documentation describes the session capability and the insecure certificate error returned when it is false.

Choose between fixing the certificate and accepting it

First decide what the test is supposed to prove:

Test goal What to do Why
Verify normal certificate validation or test an invalid-certificate warning Keep acceptInsecureCerts false, or omit it so the browser uses its default. The browser must perform its usual validation for the test to detect certificate problems.
Exercise application behavior behind a known-invalid test certificate Set acceptInsecureCerts to true when creating the WebDriver session. The browser can navigate past certificate problems for that session.
A test endpoint is expected to have a valid certificate Fix the endpoint’s certificate, chain, hostname, or trust configuration. A bypass would hide the defect the test should catch.

A browser’s insecure-certificate error can arise from an expired or otherwise invalid certificate, an untrusted issuer such as a self-signed certificate, or a hostname/domain mismatch. Identify the actual issue before suppressing validation. MDN explains the browser error and the risks of bypassing certificate checks in its WebDriver capability reference.

Python: set the capability before starting the driver

Install Selenium in the environment running this example with python -m pip install selenium. For a local Chrome session:

from selenium import webdriver
from selenium.webdriver.chrome.options import Options

options = Options()
options.set_capability("acceptInsecureCerts", True)

driver = webdriver.Chrome(options=options)
try:
    driver.get("https://your-test-host.example")
    print(driver.title)
finally:
    driver.quit()

Replace the example host with the test endpoint. To retain certificate validation, set the capability to False or omit the line that sets it. Pass the options object at driver creation: this is a session capability, not a per-navigation switch.

Remote WebDriver and Selenium Grid

Configure the same browser options for a remote session. The remote endpoint must accept and apply the requested capability:

from selenium import webdriver
from selenium.webdriver.chrome.options import Options

options = Options()
options.set_capability("acceptInsecureCerts", True)

grid_url = "http://localhost:4444"
driver = webdriver.Remote(
    command_executor=grid_url,
    options=options,
)
try:
    driver.get("https://your-test-host.example")
    print(driver.title)
    print("Session capabilities:", driver.capabilities)
finally:
    driver.quit()

Use the actual Grid or hosted-browser command URL for grid_url. Check the returned capabilities and the browser, driver, and Grid logs if the remote browser still shows an interstitial. Remote-provider support and behavior can depend on that provider’s configuration, so confirm it in the environment used by the project. Selenium’s current Python documentation shows the Options pattern for Remote WebDriver sessions.

Other language bindings

JavaScript

The Selenium JavaScript API exposes setAcceptInsecureCerts on browser options. This Node.js example uses Chrome and quits the session even if navigation fails:

const { Builder } = require('selenium-webdriver');
const chrome = require('selenium-webdriver/chrome');

(async function run() {
  const options = new chrome.Options();
  options.setAcceptInsecureCerts(true);

  const driver = await new Builder()
    .forBrowser('chrome')
    .setChromeOptions(options)
    .build();

  try {
    await driver.get('https://your-test-host.example');
    console.log(await driver.getTitle());
  } finally {
    await driver.quit();
  }
})();

For remote execution, configure the browser options before building the remote session, using the remote connection settings required by your Grid or provider. The Selenium JavaScript Options API documents setAcceptInsecureCerts(accept).

Java

In Java, set the capability on the browser options passed to the driver constructor:

import org.openqa.selenium.WebDriver;
import org.openqa.selenium.chrome.ChromeDriver;
import org.openqa.selenium.chrome.ChromeOptions;

public class InsecureCertSession {
    public static void main(String[] args) {
        ChromeOptions options = new ChromeOptions();
        options.setAcceptInsecureCerts(true);

        WebDriver driver = new ChromeDriver(options);
        try {
            driver.get("https://your-test-host.example");
            System.out.println(driver.getTitle());
        } finally {
            driver.quit();
        }
    }
}

For a remote session, pass the options to RemoteWebDriver with the Grid URL. The capability name is standardized as acceptInsecureCerts; use the matching options API for your Selenium binding and version.

Browser and remote-session configuration details

  • Set it at session creation. The capability affects navigation throughout the session. To use different validation behavior, create a separate session with different options.
  • Prefer the WebDriver capability. ChromeDriver documents acceptInsecureCerts as a capability. Use the standard option instead of starting with browser command-line flags such as ignore-certificate-errors.
  • Keep it scoped. Enable it only for sessions whose test purpose requires passing a known-invalid test certificate.
  • Check the actual browser stack. The standard capability is documented by Selenium and ChromeDriver, but there is no single compatibility matrix covering every browser version, driver, Grid, and hosted provider. Validate it in the browser and execution environment your project uses.
  • Do not use legacy guidance as current setup instructions. Selenium’s Selenium 2 SSL page describes older, browser-specific behavior. Use current WebDriver options documentation for the standard session capability.

cURL, Python, and Node.js alternatives for screenshot capture

If the goal is to save a page image rather than interact with the page through WebDriver, an HTTP screenshot API can avoid maintaining a browser session yourself. These examples use ScreenshotNeo’s documented screenshot endpoint; they do not configure Selenium or change certificate-validation behavior for your WebDriver tests. See the ScreenshotNeo API documentation for request options.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

Or skip the browser setup

For a page screenshot, ScreenshotNeo returns an image or PDF from one GET request, without you setting up a Selenium browser session. Cookie banners are accepted like a visitor and removed along with 60+ known consent platforms, newsletter popups, and chat widgets; each cleanup step can be turned off. Bot checks and CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, and response headers report the page verdict and billing status. An MCP server lets AI agents use take_screenshot, get_page_info, and capture_pdf. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000 screenshots.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the API documentation for format and capture options, or create a free account to get 1,000 screenshots a month with no card.

Troubleshooting SSL certificate errors

Symptom Likely cause What to check or change
Navigation returns an insecure certificate error The browser encountered an expired, untrusted, hostname-mismatched, or otherwise invalid certificate, and the session does not accept insecure certificates. Decide whether the test should validate TLS. If yes, fix the certificate, chain, hostname, or trust configuration. If the test intentionally proceeds through a known-invalid test certificate, set acceptInsecureCerts to true before creating the session.
The browser still shows a certificate warning after enabling the capability The option may not have been passed into session creation, or a remote end may not have applied it. Inspect the requested and returned capabilities, confirm the options object was passed to the driver constructor, and review browser, driver, Grid, or provider logs.
Changing the option before a later navigation has no effect The capability is session-wide; it is not a per-navigation toggle. Quit the session and create a new one with the intended capability value.
A passing test gives false confidence about production TLS Certificate checks were bypassed. Run a separate validation test with the capability false or omitted, and verify the production endpoint’s certificate through the appropriate TLS checks.
Options method or constructor does not match an example The sample may target another language binding or API version. Use the current Options API for the installed Selenium binding. The Python, JavaScript, and Java examples show the binding-specific configuration shape.

Do not suppress certificate validation until you know whether the certificate problem is expected by the test. Bypassing it makes the browser proceed; it does not resolve the certificate defect.

Performance, reliability, and cost considerations

acceptInsecureCerts is a session configuration choice, not a certificate repair or a performance feature. It can let navigation continue past certificate errors in tests designed for that behavior. It cannot make an expired certificate valid, correct a hostname mismatch, install a trusted issuer, or establish that a production endpoint is secure.

For reliability, keep certificate-validation tests distinct from tests that exercise application behavior behind a test certificate. That way, a session that intentionally bypasses validation cannot conceal a certificate regression. In remote runs, verify the capability reaches the remote end and check the exact browser, driver, Grid, or provider used by the run.

The capability itself has no separate Selenium usage charge described in the cited documentation. Costs for a remote browser depend on the Grid or browser provider; consult that environment’s terms. If screenshot capture is the task, ScreenshotNeo’s free tier includes 1,000 screenshots per month without a card, and paid plans start at $5 for 3,000.

FAQ

Does acceptInsecureCerts accept self-signed certificates?

Yes. When enabled for the WebDriver session, the browser trusts invalid certificates during navigation, including self-signed certificates.

Can I turn certificate acceptance on for just one page?

No. It is a session capability. Create a separate session with the desired setting when different tests need different certificate behavior.

Should I enable it in production tests?

Only if the test explicitly needs to exercise application behavior behind a known-invalid test certificate. Leave it disabled when checking normal TLS validation or certificate errors.

Is this setting specific to Chrome?

acceptInsecureCerts is a standard WebDriver capability, and Selenium documents it in its options and APIs. Confirm support in the precise browser, driver, and remote environment you run.

Does enabling it fix the certificate?

No. It bypasses browser validation for the session. Fix the endpoint or trust configuration if the test expects a valid certificate.